MALICIOUS — virussign.com_78fd5a2b3f74eeb11afd73adb8f760b0.vir
MALICIOUS — virussign.com_78fd5a2b3f74eeb11afd73adb8f760b0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the MPRESS family. 8 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3c2396696c89dcfc23c7000ec33c89f7aa3648c8c9dd4ff863e90d63cb344dc3 - SHA-1:
a25f21008ef6df1d9a87c4c02e1a174d2b0d79aa - MD5:
78fd5a2b3f74eeb11afd73adb8f760b0 - imphash:
504411fa583b3c54342e6878c01d9e81 - ssdeep:
768:RzG9lCapIyMsDlfjQelqYreP23SUx94NMyKZNi4bUBOwZSoWPay:g9lDpI4zFSUFXZNr7J - TLSH:
T16F37BDCD41A81B67C33B14E51632DA6E9296F0E20EEC35194D5DA03D80C78E3ED62E76 - Submitted as: virussign.com_78fd5a2b3f74eeb11afd73adb8f760b0.vir
- File type: pe · Size: 70487 bytes
- Verdict: malicious (100/100) · Family: MPRESS
Source: VirusSign · first seen 2026-07-08T00:00:00.000Z · SHA-256 verified
Detections (8 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Downloader.Upatre-5744087-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: PWS:Win32/Zbot.FD!MTB
- Emsisoft (Emergency Kit): Trojan.Downloader.JQCL
- Kaspersky (KVRT): Trojan.Win32.Bublik.bhmj
- Trellix Stinger (McAfee): PWSZbot-FIT!78FD5A2B3F74
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Upatre-5744087-0 (rule
Win.Downloader.Upatre-5744087-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 8 finding(s), e.g. process hollowing in hots.exe (pid 4452) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged PWS:Win32/Zbot.FD!MTB (rule
PWS:Win32/Zbot.FD!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Downloader.JQCL (rule
Trojan.Downloader.JQCL) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
9663 behavior events · 2 ATT&CK techniques · 6 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- hot-buys.org
- www.bing.com
- config.edge.skype.com
- desktop-hsgcbep
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- watson.events.data.microsoft.com
- aps.prod.windows.com
- msedge.api.cdp.microsoft.com
- ecs.office.com
- g.live.com
- www.msftncsi.com
Dropped files
- /opt/CAPEv2/storage/analyses/3812/files/0b49acd7f52b93db308a52f70655235316762e0089b5a18791059341b4daeb07 -
0b49acd7f52b93db308a52f70655235316762e0089b5a18791059341b4daeb07 - 2e06ae1bfd7a37eefa41b14c61266a57d7412cb7bde76390bc90646f1b60fdf6 -
2e06ae1bfd7a37eefa41b14c61266a57d7412cb7bde76390bc90646f1b60fdf6 - c0078061be968b48221127faca2f45066c1cd1ec6196a11e7d995c27e0986e05 -
c0078061be968b48221127faca2f45066c1cd1ec6196a11e7d995c27e0986e05 - ebbd000631c557eea9977418389a9ac83fc34d63ff90c6d313b523a2204757b6 -
ebbd000631c557eea9977418389a9ac83fc34d63ff90c6d313b523a2204757b6 - 7cc9839a8da2f509e1e6911c8f440e4ff03f7aa74f2d77c1e53e73b0d49839a1 -
7cc9839a8da2f509e1e6911c8f440e4ff03f7aa74f2d77c1e53e73b0d49839a1 - 4a67542acae80157932886552f13b0f356ccdad5cd3709e4652ee57539ee4fab -
4a67542acae80157932886552f13b0f356ccdad5cd3709e4652ee57539ee4fab
Embedded domains
- staging.to-do.officeppe.com
- hot-buys.org
File paths
- C:\vKO7gbgO.exe
- C:\XDWLLVEK.exe
- C:\XnS7aRzt.exe
- C:\GpiL0WiY.exe
- C:\Users\Lisa\Desktop\poRP6FBj.exe
- C:\eee451bba9cc94b9ce8f0d6a39e12e3d002fb8093365e85a144e4f5537b9c46c
- C:\4ae420ac2f44aae2b79597fa09b990590984dc7712ff1dc4518f8d2a4ad4bbf0
- C:\Documents
- C:\TBvCfkBi.exe
- C:\ab1498ec7898f7e794b964185d501e366c61ad3bad2d525a9c3a603f33e9d01f
- C:\dbda811af8100c19bb81483f4f6c6e43e7bd20183dd5a9fe42cdcdd4f4d6a054
- C:\Users\Virtual\AppData\Local\Temp\cd075e0b279cf667994ebe1bc435ce106c586cd4ec575685b878e1a9e9756ff7.exe
- C:\0dfbb923d5df6f791c308345841313b725f0af4fcfcc262db089f093f1ed3f83
- C:\7eb74600221cd1864826da882fda858b8ff0f40375b608cff02fc4dc699dab5b
- C:\Users\Virtual\AppData\Local\Temp\1159b7d7ada248af465e433389baf1371c1d78cd7351bf1ffa160f545cb28cd1.exe
- C:\43846fde43ccbde920a038cf944a47f507c7387e21bddb28dc8e2094132ab87c
- C:\oRMgFRRo.exe
- C:\z4reNBU7.exe
- C:\ofOEU96T.exe
- C:\82059a1f774b0d1d1d9a3de2271395fefa9e69e3d5b1c287bd9d5ce363653988
- C:\fdee43cbe0b1b1f71e8840f221e550d16b9cd57657c56e12d1142e521d62af2e
- C:\88d13ec2450826e10cde66d090f2c822a2efc002ceaa6676c4ba9688ff4be3c3
- c:\task\F5B1F6967C7268AF2564E3554A69AEB5.exe
- c:\task\36CDF6559B02F754C720EA5747A71840.exe
- c:\task\E865E82ECC7229B2F673C92EB1780857.exe
More MPRESS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report