MALICIOUS — virussign.com_18c26ef0987ad3b4864d1be0a40d6410.vir
MALICIOUS — virussign.com_18c26ef0987ad3b4864d1be0a40d6410.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Small family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
3b1685bc69f21cd613f194e555e555f7b518ff8bfc7a058dc5a435f349424d0a - SHA-1:
52d6a51e2e4408f9d3bbeb53a54724cd8efe5b1f - MD5:
18c26ef0987ad3b4864d1be0a40d6410 - imphash:
46646950e38cdd1519d35c0c539d2b12 - ssdeep:
1536:FllY/BITjmVY5RGKgKJ44Af2P9TcTmEbVN5ISBpBcis00t66+/NTS6WnNr:FwyjmVYDZHJACOTlN5IuBcr4NrWNr - TLSH:
T1F53A1228181F1BCFE0DD3F5EB11A181C5E4115B3BA2069E2E969A87533E01939973F83 - Submitted as: virussign.com_18c26ef0987ad3b4864d1be0a40d6410.vir
- File type: pe · Size: 99328 bytes
- Verdict: malicious (87/100) · Family: Small
Source: VirusSign · first seen 2026-08-07T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Trojan.Small-5420
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.SalityStub.F
- Kaspersky (KVRT): Virus.Win32.Sality.sil
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Small-5420 (rule
Win.Trojan.Small-5420) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Small samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report