MALICIOUS — virussign.com_c86e68380edd318506496ec9913f4110.vir
MALICIOUS — virussign.com_c86e68380edd318506496ec9913f4110.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Neshta family. 6 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4e811b8a43ecec3b1d5c4d8deccd1fe65d2c570019bce1ed403662e040abd1f7 - SHA-1:
8744059d03f859b4fa2ddc74e62bd5206739018a - MD5:
c86e68380edd318506496ec9913f4110 - imphash:
9f4693fc0c511135129493f2161d1e86 - ssdeep:
6144:k9xCYLOdB50KJXv/s8YBvfGLoVVmrgaZkfIDz5Z0/vfp5:uCTB50Cv/sQLhmyn0/vx5 - TLSH:
T187474B9F45091700EA34C7686954AEED3452F0A214BA340E6A9BC53E23C6DDBFDF12B4 - Submitted as: virussign.com_c86e68380edd318506496ec9913f4110.vir
- File type: pe · Size: 321640 bytes
- Verdict: malicious (100/100) · Family: Neshta
Source: VirusSign · first seen 2026-07-17T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- ClamAV (daily): Win.Trojan.Neshuta-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Neshta.A
- Emsisoft (Emergency Kit): Win32.Neshta.A
- Kaspersky (KVRT): Virus.Win32.Neshta.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Neshuta-1 (rule
Win.Trojan.Neshuta-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 6 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 8052) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Virus:Win32/Neshta.A (rule
Virus:Win32/Neshta.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Neshta.A (rule
Win32.Neshta.A) - engine signal, weight 0.55, confidence 0.85 - Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://res.ldmnq.com/ld/leidian, https://res.ldmnq.com/ldmnq_file/location_web/location.html, https://res.ldmnq.com/ldmnq_file/location_web/location_2.html - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
37929 behavior events · 1 ATT&CK techniques · 10 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- edge.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- watson.events.data.microsoft.com
- www.msftncsi.com
- fs.microsoft.com
- self.events.data.microsoft.com
- 192.168.122.108
- 192.168.122.255
- 192.168.122.1
- 224.0.0.252
- 169.254.110.32
- 192.168.122.106
Dropped files
- /opt/CAPEv2/storage/analyses/3557/files/ca214b1eb79affecbc8243e3623adf24a71e997b16645b7f6f75f7d3bc73eea3 -
ca214b1eb79affecbc8243e3623adf24a71e997b16645b7f6f75f7d3bc73eea3 - /opt/CAPEv2/storage/analyses/3557/files/1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce -
1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce - /opt/CAPEv2/storage/analyses/3557/files/8be4d3fe6d043736cc43ff142e5777f8031061b59a3bfb759cc412d4f3aa27e4 -
8be4d3fe6d043736cc43ff142e5777f8031061b59a3bfb759cc412d4f3aa27e4 - /opt/CAPEv2/storage/analyses/3557/files/12ec8da0f30159bca5aaed39c899e3eac32a708433c5dd608522f2ec366617a3 -
12ec8da0f30159bca5aaed39c899e3eac32a708433c5dd608522f2ec366617a3 - /opt/CAPEv2/storage/analyses/3557/files/3d58d7225b724a7c2a79765cf3037518b25516152780065fbd20592f797caafa -
3d58d7225b724a7c2a79765cf3037518b25516152780065fbd20592f797caafa - /opt/CAPEv2/storage/analyses/3557/files/22b8dbf3767619f32910c03c67ed7ca63d5dc5216cb9fc945d8bae13c97b73d1 -
22b8dbf3767619f32910c03c67ed7ca63d5dc5216cb9fc945d8bae13c97b73d1 - /opt/CAPEv2/storage/analyses/3557/files/e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad -
e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad - /opt/CAPEv2/storage/analyses/3557/files/78c3f8b5d01455d4329ef380f1558833f90fa41782089178157b69b6e677ea71 -
78c3f8b5d01455d4329ef380f1558833f90fa41782089178157b69b6e677ea71 - /opt/CAPEv2/storage/analyses/3557/files/1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 -
1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 - /opt/CAPEv2/storage/analyses/3557/files/485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4 -
485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/CPS0
- https://res.ldmnq.com/ld/leidian
- https://res.ldmnq.com/ldmnq_file/location_web/location.html
- https://res.ldmnq.com/ldmnq_file/location_web/location_2.html
- https://res.ldmnq.com/mnqfile/
- http://api.ldmnq.com/checkVersion2
- https://inf.ldmnq.com/checkMnqVersion
- https://res.ldmnq.com/ld/ad_fullscreen.data
- https://res.ldmnq.com/ld/apps_must_config.data
- https://res.ldmnq.com/ld/ad_bg.data
- http://api.ldmnq.com/buglog?bugdesc=1®ion=cn&filemd5=
- https://apicn.ldmnq.com/report_uninstall
- https://res.ldmnq.com/ld/vtlink.txt
- https://storetw.ldmnq.com/store/v2/get_game_by_package?packageName=
- https://apitw.ldmnq.com/getScreenUrl?gameName=
- https://ldbbs.ldmnq.com/ld/leidian
- https://ldbbs.ldmnq.com/ldmnq_file/location_web/location.html
- https://ldbbs.ldmnq.com/ldmnq_file/location_web/location_2.html
- https://ldbbs.ldmnq.com/mnqfile/
- https://ldbbs.ldmnq.com/ld/ad_fullscreen.data
- https://ldbbs.ldmnq.com/ld/apps_must_config.data
- https://ldbbs.ldmnq.com/ld/ad_bg.data
- https://ldbbs.ldmnq.com/ld/vtlink.txt
- https://encdn.ldmnq.com/player_files/tw/leidian
Embedded domains
- schemas.microsoft.com
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- res.ldmnq.com
- api.ldmnq.com
- inf.ldmnq.com
- apicn.ldmnq.com
- storetw.ldmnq.com
- apitw.ldmnq.com
- ldbbs.ldmnq.com
- encdn.ldmnq.com
- apikr2.ldmnq.com
- apikr.ldmnq.com
- storekr.ldmnq.com
- apien.ldmnq.com
- storeen.ldmnq.com
- apijp.ldmnq.com
- storejp.ldmnq.com
- apiru.ldmnq.com
- storeru.ldmnq.com
- apivn.ldmnq.com
- storevn.ldmnq.com
- apith.ldmnq.com
Embedded IP addresses
- 255.255.255.0
- 223.5.5.5
- 114.114.114.114
- 8.8.8.8
- 8.8.4.4
File paths
- I:\build\trunk9_en_build\simulator\bin\ldrecord\ldrecord.pdb
- D:\:o:
- X:\:`:d:h:l:p:t:x:
- P:\:
More Neshta samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report