MALICIOUS — virussign.com_626b5734cc1d9c12beff8379af25ca30.vir
MALICIOUS — virussign.com_626b5734cc1d9c12beff8379af25ca30.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Padodor family. 5 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
50990900c94290ff3b1279e2c74f6582bd937cf232a11f61d01ed7cf408820c9 - SHA-1:
2ad631fbd36d0cf9e557d3992b7d089d7d249f82 - MD5:
626b5734cc1d9c12beff8379af25ca30 - imphash:
26babd76bbb7f9c516a338b0601b4c9f - ssdeep:
1536:Bwzl2fXA2KVYY+MvalFD37YmAYG9da6eUjeDlHnouy8x:qY1Mval6eyeUjehHoutx - TLSH:
T19439490982A96EE8FBD02D85B929EECC6DCB0136EB6845D68320C87047F514F5646F7C - Submitted as: virussign.com_626b5734cc1d9c12beff8379af25ca30.vir
- File type: pe · Size: 90141 bytes
- Verdict: malicious (99/100) · Family: Padodor
Source: VirusSign · first seen 2026-08-25T00:00:00.000Z · SHA-256 verified
Detections (5 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-31
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Backdoor:Win32/Padodor.SK!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKDZ.119632
- Kaspersky (KVRT): Backdoor.Win32.Padodor.gen
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-31 (rule
Win.Trojan.Crypted-31) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Padodor.SK!MTB (rule
Backdoor:Win32/Padodor.SK!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKDZ.119632 (rule
Trojan.GenericKDZ.119632) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Backdoor.Win32.Padodor.gen (rule
Backdoor.Win32.Padodor.gen) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - Contacted 3 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Dropped 6 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Memory forensics: 4 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5804) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
230 behavior events · 1 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- slscr.update.microsoft.com
Dropped files
- C:\Windows\System32\Ejjpalcn.exe -
92c031a8d176ab59be458623fa6e7c50e93ed5211d80f7984c0cdccb41cadf80 - C:\Windows\System32\Bbomlf32.dll -
e7059cb3b444972b2d714b9234a85082d69b102acb00804bea7caf26f6ce0bba - C:\Windows\System32\Hnfnof32.exe -
a1d3237ee36818e0aa7b672f9ea670e1f8b1a7a3355d11f93f4d27dbc8354c52 - C:\Windows\System32\Jmjlphne.dll -
a32d37ebf203092c099a89b54287925e78734957f52637e272029c540da2007c - C:\Windows\System32\Jigiabjd.dll -
b0e92f487d28737ad3c8ac7817b5421fa7e0d5f3ef781001ba300b0b6bc2b8b2 - C:\Windows\System32\Dcdhhcfo.exe -
13d8224132d2a1c6e391230c8ac90ac6667342a6c6206dd42c05ccd2587bd7b4
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 104.208.16.94
- 20.247.184.142
- 4.230.171.124
- 52.230.59.222
- 104.18.33.89
- 135.233.95.135
- 57.155.104.224
- 74.179.77.204
- 20.184.175.1
- 172.178.240.161
- 52.110.12.48
- 52.110.12.20
More Padodor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report