SUSPICIOUS — virussign.com_b43d2be594f8b18d52138d6bc4b5ac70.vir
SUSPICIOUS — virussign.com_b43d2be594f8b18d52138d6bc4b5ac70.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the Note family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
43af96a2b7a583a0f84e536cc2cf45f08a7f0a0930c57add0132dea436dc2767 - SHA-1:
9f801529fb46a47c77131e02f34a2085214926cd - MD5:
b43d2be594f8b18d52138d6bc4b5ac70 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
3072:jBbkCyAqYviHeRvn00000000000eCAqYWTVABVMyk/ZJaCpnKGj/WJx57au+4GA:lbTqpYvFq/YnkH/CGm4onLaqcvNxUq - TLSH:
T1E74818BD8526720FCAD37B7D141AE0CD7A5729CB980F93D9E119C62F99E13B701A0890 - Submitted as: virussign.com_b43d2be594f8b18d52138d6bc4b5ac70.vir
- File type: pe · Size: 359936 bytes
- Verdict: suspicious (40/100) · Family: Note
Source: VirusSign · first seen 2026-08-15T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- YARA: MalwareAnalyser community pack: TL_Ransomware_Note_Markers
- Microsoft Defender: Trojan:MSIL/FileCoder.ARA!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Ransom.REntS.Gen.1
- Kaspersky (KVRT): HEUR:Trojan-Ransom.MSIL.Encoder.gen
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: MalwareAnalyser community pack flagged TL_Ransomware_Note_Markers (rule
TL_Ransomware_Note_Markers) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://en.wikipedia.org/wiki/Bitcoin - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://en.wikipedia.org/wiki/Bitcoin
Embedded domains
- schemas.microsoft.com
- en.wikipedia.org
File paths
- C:\Users\Worm\source\repos\BSOD\BSOD\obj\Debug\BSOD.pdb
- C:\Users\Dolka\Downloads\RANSOMWARE3.0-SOURCE-CODE-main\RANSOMWARE3.0-SOURCE-CODE-main\RANSOMWARE3.0\RANSOMWARE3.0\obj\Release\JournalTrace.pdb
- C:\Program
- C:\Users
- C:\Windows
- C:\Windows\System32
- C:\Windows\
- C:\Windows\BSOD.exe
More Note samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report