MALICIOUS — virussign.com_a2247d58f551e14339516c2782bf0db0.vir
MALICIOUS — virussign.com_a2247d58f551e14339516c2782bf0db0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 13 of 51 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
3e3e347e74f84b757de8f8c63e7c9684cf87e88a01feb55320123e0347bdfb10 - SHA-1:
889e7483a63ab973e0f370319a31ed5a035e2a1e - MD5:
a2247d58f551e14339516c2782bf0db0 - imphash:
b5115849209844616759b800db5d003e - ssdeep:
98304:rXsRXg62ZKUgTH2M2m9UMpu1QfLczqssnKS2fkZcG:Kg62PgTH2qBpu1QfLIqsufgPG - TLSH:
T1866A06568F833156D2F7BD009460D9DC820FB45DA77F868DD702C03991ABABB8EE1096 - Submitted as: virussign.com_a2247d58f551e14339516c2782bf0db0.vir
- File type: pe · Size: 9265046 bytes
- Verdict: malicious (100/100) · Family: Delf
Source: VirusSign · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (13 of 51 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:collection/keylog
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Delf-6980489-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): P2P-Worm.Win32.Delf.aj
- Microsoft Defender: Worm:Win32/Xolxo.A
- Emsisoft (Emergency Kit): Gen:Variant.Ransom.Amnesia.1
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Worm.Delf-6980489-0 (rule
Win.Worm.Delf-6980489-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - query domain / anti-analysis (rule
query domain / anti-analysis) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://rna-pdf-resource.acrobat.com/, https://crbug.com/820996, https://msmip.reader.com/authorize - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/appx/2010/manifest
- http://schemas.microsoft.com/appv/2010/manifest
- http://www.w3.org/2000/09/xmldsig#
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2000/09/xmldsig#sha1
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com/0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.microsoft.com/pki/certs/tspca.crt0
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://office.microsoft.com
- https://oobe.adobe.com/
- https://rna-pdf-resource.acrobat.com/
- http://www.w3.org/TR/REC-html40
- https://oobe.adobe.com/federation_start
- https://oobe.adobe.com
- https://oobe.adobe.com/delegation_start
- https://oobe.adobe.com/delegation_end
- https://oobe.adobe.com/delegation_error
- https://oobe.adobe.com/federation_end
- https://oobe.adobe.com/federation_error
Embedded domains
- schemas.microsoft.com
- www.w3.org
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
- ug.mi.oc.co
- oobe.adobe.com
- rna-pdf-resource.acrobat.com
- dc-api-stage.adobe.io
- crbug.com
- ns.adobe.com
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- clients2.google.com
- helpx.adobe.com
- help.adobe.com
- adobehelp.corp.adobe.com
- adobe.com
- dc.acrobat.com
- documentcloud.adobe.com
- dc.stage.acrobat.com
- acrobat.adobe.com
- stage.acrobat.adobe.com
Embedded IP addresses
- 4.6.0.111
Registry keys
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
- HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
- HKCU\Software
- HKCU\Software\Policies
- HKLM\Software
- HKLM\Software\Policies
- HKEY_CURRENT_USER\%s\*
- HKEY_CURRENT_USER\Software\Adobe\Acrobat
- HKEY_CURRENT_USER\Software\Adobe\Adobe
- HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage
- HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes\Installer*
- HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes*
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech*
- HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties*
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
- HKEY_CURRENT_USER\SOFTWARE\Adobe\CommonFiles*
File paths
- C:\My
- C:\WINNT\system32\actmovie.exe
- C:\WINDOWS\system32\dllhost.exe
- C:\WINDOWS\pchealth\helpctr\binaries\notiflag.exe
- C:\WINDOWS\system32\login.cmd
- C:\WINDOWS\system32\fastopen.exe
- C:\Program
- p:\Target\x86\ship\setuptools\x-none\Flattener.pdb
- F:\Office\Target\x86\ship\postc2r\x-none\csisyncclient.pdb
- D:\T\Acrobat\Viewer\win\EXEs\ViewerExe\ChromeSandboxLaunch.cpp
- D:\T\BuildResults\bin\Release_x64\AcrobatExe.pdb
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report