MALICIOUS — virussign.com_25f707697b9dcc7b09c5fa8bafa84bf0.vir
MALICIOUS — virussign.com_25f707697b9dcc7b09c5fa8bafa84bf0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Copak family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
52f28883510e8934381289b1e59fced2a43d8d128e411d04390fc250b9965e64 - SHA-1:
52d03421dc0e111b935984e3003c4eed9fc4b48a - MD5:
25f707697b9dcc7b09c5fa8bafa84bf0 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
1536:PUMTvcJsNcfZML+KcAsFbo/kimvnLkT0nAr0CmuJd4BXKikc6C:PUMTcJXfgsRbrT60ArBbd4M5C - TLSH:
T1B03A027DA2180481DCC6A049A16CB5FD7C03650A53AADE8131C6D25D5E3DFEB2182FAF - Submitted as: virussign.com_25f707697b9dcc7b09c5fa8bafa84bf0.vir
- File type: pe · Size: 94208 bytes
- Verdict: malicious (99/100) · Family: Copak
Source: VirusSign · first seen 2026-07-15T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Packed.Copak-9853643-0
- Microsoft Defender: Ransom:Win32/Tescrypt!pz
- Emsisoft (Emergency Kit): Gen:Variant.babar.69948
- Kaspersky (KVRT): HEUR:Trojan.Win32.Copak.vho
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Packed.Copak-9853643-0 (rule
Win.Packed.Copak-9853643-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 8 finding(s), e.g. process hollowing in tsk_b0d3da74c4 (pid 8868) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged Ransom:Win32/Tescrypt!pz (rule
Ransom:Win32/Tescrypt!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.babar.69948 (rule
Gen:Variant.babar.69948) - engine signal, weight 0.55, confidence 0.85 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
110 behavior events · 1 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- config.edge.skype.com
- www.bing.com
- fd.api.iris.microsoft.com
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/3415/files/0d6f8e5ae0d8159caf4be963503909851ca208ded454a938ee7abc54ecc2f0c2 -
0d6f8e5ae0d8159caf4be963503909851ca208ded454a938ee7abc54ecc2f0c2 - 308fd3633bc69349c60f71ce3231fcfb9c508d39fd48a6ff617d9ac4054f5ab1 -
308fd3633bc69349c60f71ce3231fcfb9c508d39fd48a6ff617d9ac4054f5ab1 - 619e8b80592052331b06ba19febfe301087792c0eee9e575a4f8ff3345c21a80 -
619e8b80592052331b06ba19febfe301087792c0eee9e575a4f8ff3345c21a80 - 114e34b241a086fc9239d3546303d35fd1c35e834ca5b8285595598e67d33504 -
114e34b241a086fc9239d3546303d35fd1c35e834ca5b8285595598e67d33504 - 23ca5ad02df1aca1195a07eac57cede292e428c85ad8618b348456c6af129074 -
23ca5ad02df1aca1195a07eac57cede292e428c85ad8618b348456c6af129074 - 3ed1820b8e525614939f30e0fcd3898661b17c1f276628cbadd02a8694f59292 -
3ed1820b8e525614939f30e0fcd3898661b17c1f276628cbadd02a8694f59292
Embedded domains
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
- www.msftconnecttest.com
- searchapp.bundleassets.example
- outlook.office.com
- outlook.office365.com
- config.edge.skype.com
- www.bing.com
- fd.api.iris.microsoft.com
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- msedge.api.cdp.microsoft.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
More Copak samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report