MALICIOUS — virussign.com_b5d1c83d9e201315c39e7df05e16fd20.vir
MALICIOUS — virussign.com_b5d1c83d9e201315c39e7df05e16fd20.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the MPRESS family. 8 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4b701597adf961f4cc77cad71b4f6906860fc18384a4e84e190ee7d154e9f2c2 - SHA-1:
a9341400e5aa58933165ce91a346b7731f2ebbb3 - MD5:
b5d1c83d9e201315c39e7df05e16fd20 - imphash:
9dacd5fc505421be83fd9ef325d44b59 - ssdeep:
1536:mAocdpeVoBDulhzHMb7xNAa04Mcg5bx7DUQeDac7AkT7w:0cdpeeBSHHMHLf9Rybx7DYec7Fw - TLSH:
T1053BFA6396A7F885C93070AB3F8F3351B040B9F00653798665ACE29F7D6758B46838C6 - Submitted as: virussign.com_b5d1c83d9e201315c39e7df05e16fd20.vir
- File type: pe · Size: 103475 bytes
- Verdict: malicious (99/100) · Family: MPRESS
Source: VirusSign · first seen 2026-07-20T00:00:00.000Z · SHA-256 verified
Detections (8 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.BlackMoon-4255490-1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Microsoft Defender: TrojanDropper:Win32/Dinwod!pz
- Emsisoft (Emergency Kit): Trojan.GenericKD.80176773
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
- Trellix Stinger (McAfee): Trojan-FPCQ!BA60F51D4D97
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.BlackMoon-4255490-1 (rule
Win.Trojan.BlackMoon-4255490-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 5 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7788) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged TrojanDropper:Win32/Dinwod!pz (rule
TrojanDropper:Win32/Dinwod!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80176773 (rule
Trojan.GenericKD.80176773) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
31 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- www.bing.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- 192.168.122.107
- 224.0.0.252
- 192.168.122.255
- 192.168.122.1
- 192.168.122.105
- 192.168.122.108
- 224.0.0.22
Embedded domains
- www.msftconnecttest.com
- config.edge.skype.com
- dns.msftncsi.com
- www.bing.com
- watson.events.data.microsoft.com
- edge.microsoft.com
More MPRESS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report