MALICIOUS — virussign.com_f2123efd44321b38e35c235eff837040.vir
MALICIOUS — virussign.com_f2123efd44321b38e35c235eff837040.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Razy family. 4 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
3fe2643c26ba51b2daa4cda28cc0dba39ac0f946cb7f309ae5f86c024fac25ea - SHA-1:
80b1aef4b1394dd108de06f2d1576fdc9b08909c - MD5:
f2123efd44321b38e35c235eff837040 - imphash:
3c2e1c95b87b1cf3c33906bf62025007 - ssdeep:
768:y8eRH+9lFh0ul16sh7iQroCHrf+RjFBSuB2XZAdOE7Q6cnqh5wCoN:y9l+Z16sh7iQroCqRB0uMfKcqoCoN - TLSH:
T1C635B8CD80682A57C23745B95A3EDA5ED196B0D229AC770D0D8DB13E40C38E3EC62D76 - Submitted as: virussign.com_f2123efd44321b38e35c235eff837040.vir
- File type: pe · Size: 59570 bytes
- Verdict: malicious (98/100) · Family: Razy
Source: VirusSign · first seen 2026-08-19T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- ClamAV (daily): Win.Downloader.Razy-9935848-0
- Microsoft Defender: Trojan:Win32/Zbot.HBAI!MTB
- Trellix Stinger (McAfee): Trojan-FXIX!F2123EFD4432
- Kaspersky (KVRT): Trojan-PSW.Win32.LdPinch.hij
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Downloader.Razy-9935848-0 (rule
Win.Downloader.Razy-9935848-0) - engine signal, weight 0.90, confidence 0.95 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 32 external host(s) at runtime (30 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
10687 behavior events · 2 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- gwentcarsales.co.uk
- yr.c.lencr.org
- yr1.c.lencr.org
- lanoguard.co.uk
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\bkgrnd.exe -
92bfc94912cad1d0348c55fe8eeaecdd59a92f9d999f8497e73797ed54bf3511 - 2d314ea7a5039b12879fe4deb03287afd544d17a65f59a9aaa1816147f924948 -
2d314ea7a5039b12879fe4deb03287afd544d17a65f59a9aaa1816147f924948 - e329b622d856b6e1d7dc74ddb34404a3a5330960564ce74d2b330891bdda366c -
e329b622d856b6e1d7dc74ddb34404a3a5330960564ce74d2b330891bdda366c - 9b8fd69b310ab950619013495e947361b5a05194ff3dc59b768684a44594f5b8 -
9b8fd69b310ab950619013495e947361b5a05194ff3dc59b768684a44594f5b8 - a706fe700b169972466a84eefe99e9a40f4ab05adb9a6f041731a116c3e49415 -
a706fe700b169972466a84eefe99e9a40f4ab05adb9a6f041731a116c3e49415
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787782130&P2=404&P3=2&P4=QET2oEi55AcZRyvoVU9MlOEyR%2foSamq%2bBAt8f1EX5u2T7Fjz8keyjcRzd50UkRwxKkc8ay1ahHhWyKIrPNVwNg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://yr.c.lencr.org/
- http://yr1.c.lencr.org/68.crl
- http://c.pki.goog/r/r1.crl
- http://c.pki.goog/wr1/fXwYrqsj_io.crl
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787782208&P2=404&P3=2&P4=F3LYW5tKmw7khHzgupmJkQYONc6tp2iR4Uf4HjO5BLCfpFQnYuFMJQ071939AzxgubPrLc5yEkgRcFa2ej6lbg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- tern32.de
- gwentcarsales.co.uk
- x1.c.lencr.org
- yr.c.lencr.org
- yr1.c.lencr.org
- lanoguard.co.uk
Embedded IP addresses
- 20.42.65.94
- 52.123.252.227
- 57.154.63.210
- 4.230.171.124
- 40.84.85.40
- 4.144.132.223
- 135.233.95.144
- 74.178.240.51
- 51.11.192.50
- 52.123.252.239
- 20.76.201.171
- 52.123.129.14
- 52.123.128.14
- 40.99.133.226
- 4.150.223.104
- 52.168.117.168
- 203.26.79.13
- 135.233.45.222
- 52.110.12.52
- 162.159.142.9
- 52.110.12.22
- 74.178.232.29
- 23.227.38.64
- 52.148.114.188
- 172.178.240.162
File paths
- C:\Users\VAIO\AppData\Local\Temp\Rar$EXa0.052\report_11212013.exe
- C:\uB7DQLYF.exe
- C:\pOS7zq_A.exe
- C:\x3y8acAN.exe
- C:\9C_72AbF.exe
- C:\e7TJodaF.exe
- C:\senEv5qv.exe
- C:\AwILxdJk.exe
- C:\jNPPvREu.exe
- C:\E3QARmhl.exe
- C:\Soq1U0DH.exe
- C:\7EU90hz0.exe
- C:\Cl57wga8.exe
- C:\yW4KRDD0.exe
- C:\UGC3NV2U.exe
- C:\cHv7g_EC.exe
- C:\Idnw6Qmc.exe
- C:\Ur5N9901.exe
- C:\hVVOtFF7.exe
- C:\jYrsBSpg.exe
- C:\0MP4_6_I.exe
- C:\8EGkL9Ba.exe
- C:\Je3iyrvd.exe
- C:\r0g_XveS.exe
- C:\0fHiuF_1.exe
More Razy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report