MALICIOUS — virussign.com_467c7786673b5f5f40b3c94c1aa10c30.vir
MALICIOUS — virussign.com_467c7786673b5f5f40b3c94c1aa10c30.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the MPRESS family. 8 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4e5a08f1083f21bf52b16c2ea45bdd99bbef2bfefeaee42e96fb2be5b8a1a152 - SHA-1:
014ea0c22ad04dc4c2726ace209fa595ac22286a - MD5:
467c7786673b5f5f40b3c94c1aa10c30 - imphash:
9dacd5fc505421be83fd9ef325d44b59 - ssdeep:
1536:mAocdpeVoBDulhzHMb7xNAa04Mcg5IKvlNJiRXDKFjI+pZm5W:0cdpeeBSHHMHLf9RyIEQ5KXZB - TLSH:
T1923A4CA796A3B4C9C93470AF3F4F73A57400BDF00653798625ACE28EBD6618B46834C5 - Submitted as: virussign.com_467c7786673b5f5f40b3c94c1aa10c30.vir
- File type: pe · Size: 100568 bytes
- Verdict: malicious (99/100) · Family: MPRESS
Source: VirusSign · first seen 2026-07-20T00:00:00.000Z · SHA-256 verified
Detections (8 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.BlackMoon-4255490-1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.GenericKD.80803832
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
- Trellix Stinger (McAfee): Trojan-FPCQ!BA60F51D4D97
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.BlackMoon-4255490-1 (rule
Win.Trojan.BlackMoon-4255490-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 6 finding(s), e.g. RWX/private injected region in powershell.exe (pid 2488) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80803832 (rule
Trojan.GenericKD.80803832) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
29 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- desktop-hsgcbep
- dns.msftncsi.com
- www.bing.com
- config.edge.skype.com
- edge.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- 224.0.0.252
- 192.168.122.255
- 169.254.59.211
- 192.168.122.105
- 192.168.122.1
- 192.168.122.107
- 192.168.122.108
- 224.0.0.22
Embedded domains
- www.msftconnecttest.com
- dns.msftncsi.com
- www.bing.com
- config.edge.skype.com
- edge.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
More MPRESS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report