MALICIOUS — virussign.com_5e3b87eb268d47bb77ba5a319f6445f0.vir
MALICIOUS — virussign.com_5e3b87eb268d47bb77ba5a319f6445f0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Neshuta family. 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
526cc9c5971a4851a6c1218ff689a11909518507d0bb799bfc101e7866767119 - SHA-1:
541d10eb11b1c116ae4eef41ab4199aa1b750958 - MD5:
5e3b87eb268d47bb77ba5a319f6445f0 - imphash:
9f4693fc0c511135129493f2161d1e86 - ssdeep:
1536:JxqjQ+P04wsmJCUuOn89n8d58CZfVyv4HGFM:sr85CUui8V8T8CZw4mi - TLSH:
T12E41192C4F177666D4E481ABB8416F2E14366868F41E7C98E363C03DA7E2C7365E019B - Submitted as: virussign.com_5e3b87eb268d47bb77ba5a319f6445f0.vir
- File type: pe · Size: 180844 bytes
- Verdict: malicious (99/100) · Family: Neshuta
Source: VirusSign · first seen 2026-07-14T00:00:00.000Z · SHA-256 verified
Detections (4 of 53 engines)
- ClamAV (daily): Win.Trojan.Neshuta-1
- Microsoft Defender: Virus:Win32/Neshta.A
- Emsisoft (Emergency Kit): Win32.Neshta.A
- Kaspersky (KVRT): Virus.Win32.Neshta.a
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Neshuta-1 (rule
Win.Trojan.Neshuta-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 6 finding(s), e.g. RWX/private injected region in powershell.exe (pid 2592) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 36 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- Contacted 36 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
37372 behavior events · 1 ATT&CK techniques · 9 dropped files.
Runtime network
- www.msftconnecttest.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep
- msedge.api.cdp.microsoft.com
- www.bing.com
- officeclient.microsoft.com
- v10.events.data.microsoft.com
- ctldl.windowsupdate.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- v20.events.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
- aps.prod.windows.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/2382/files/0d2154522224270ce1c3faeb18badc14c579e888f8095c37df2b175b2fe5b64b -
0d2154522224270ce1c3faeb18badc14c579e888f8095c37df2b175b2fe5b64b - /opt/CAPEv2/storage/analyses/2382/files/56d2c68b9152d4230361be5e6a9c55c3d69f1b951e746a8ee9773aec26ea95f5 -
56d2c68b9152d4230361be5e6a9c55c3d69f1b951e746a8ee9773aec26ea95f5 - /opt/CAPEv2/storage/analyses/2382/files/4f97faf091b62f5388d1a1a47a6bc01e4fe043b097e7a5058c8c5113d07338e4 -
4f97faf091b62f5388d1a1a47a6bc01e4fe043b097e7a5058c8c5113d07338e4 - /opt/CAPEv2/storage/analyses/2382/files/1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce -
1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce - /opt/CAPEv2/storage/analyses/2382/files/c6906999be24eb179a7d10da68e30225afd714df64cd7a61b5c3ed86b11821df -
c6906999be24eb179a7d10da68e30225afd714df64cd7a61b5c3ed86b11821df - /opt/CAPEv2/storage/analyses/2382/files/e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad -
e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad - /opt/CAPEv2/storage/analyses/2382/files/1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 -
1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 - /opt/CAPEv2/storage/analyses/2382/files/485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4 -
485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4 - /opt/CAPEv2/storage/analyses/2382/files/0cbd2e0569b8bd047bc5a764d5858025914e41bfcc17d76a4361a1f1a6ea50f8 -
0cbd2e0569b8bd047bc5a764d5858025914e41bfcc17d76a4361a1f1a6ea50f8
Embedded URLs
- http://203.26.79.13/filestreamingservice//files/92621512-d997-4742-9ae0-db0593ed93c6/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/92621512-d997-4742-9ae0-db0593ed93c6?P1=1785706635&P2=404&P3=2&P4=f4xQ9vTNmyNMwF5GIrH1riVouUcZk5cdn9ojBihAwo4HHyHORKRZbfCatJmnPcsT14G9tEMjZPWwGNZTiXB0%2bQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://www.msftconnecttest.com/connecttest.txt
Embedded domains
- oneclient.sfx.ms
- www.msftconnecttest.com
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- msedge.api.cdp.microsoft.com
- www.bing.com
- officeclient.microsoft.com
- v10.events.data.microsoft.com
- ctldl.windowsupdate.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- v20.events.data.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
- aps.prod.windows.com
- cp801.prod.do.dsp.mp.microsoft.com
- msedge.b.tlu.dl.delivery.mp.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- _dosvc._tcp.local
- dns.msftncsi.com
Embedded IP addresses
- 10.10.0.180
- 203.26.79.13
- 52.110.12.32
- 52.110.12.31
- 20.184.175.3
- 52.168.117.171
- 23.33.238.102
- 20.42.179.192
- 52.182.143.212
- 172.178.240.161
- 150.171.28.11
- 23.40.52.209
- 40.126.14.163
- 135.233.95.144
- 20.165.94.54
- 20.42.73.30
- 199.232.138.172
- 20.184.175.16
- 150.171.22.17
- 74.178.232.29
- 150.171.109.19
- 151.101.30.172
- 23.11.37.157
- 92.223.78.30
- 204.79.197.203
File paths
- D:\JHCTest\PLU.TXT
- E:\MyProject\Commdll_old\FileTransSample\FileTrans_V2\FileTransDemo\FileTransDemo.cpp
- E:\MyProject\Commdll_old\FileTransSample\FileTrans_V2\FileTransDemo\FileTransDemoDlg.cpp
- E:\MyProject\Commdll_old\FileTransSample\FileTrans_V2\FileTransDemo\Debug\FileTransDemo.pdb
More Neshuta samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report