MALICIOUS — virussign.com_7767ae80b8bf2d7edeab7672c1814190.vir
MALICIOUS — virussign.com_7767ae80b8bf2d7edeab7672c1814190.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Socks family. 7 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
54130bd84fff5e709a76976e875e52bcd8c955c6ebc6f4f94e3a1ed4c055e3ca - SHA-1:
6d799e657ae4c94b61d89ab797fd836d5348af31 - MD5:
7767ae80b8bf2d7edeab7672c1814190 - imphash:
178689c38c1294cbf87aafcafb2357ed - ssdeep:
12288:ACCs5xOKx2Nht6igCF+WrAouDidUVwpsL5akDEGmQ:AU5xOuiPX4CPUKp80Q - TLSH:
T1064F23A516F70929D6329E0414647EBF27718B08F2A47700E2E26530ED8DD931B9F93B - Submitted as: virussign.com_7767ae80b8bf2d7edeab7672c1814190.vir
- File type: pe · Size: 710705 bytes
- Verdict: malicious (100/100) · Family: Socks
Source: VirusSign · first seen 2026-07-18T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Socks-10058896-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.02
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.Stealer.557
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Worm.Socks-10058896-0 (rule
Win.Worm.Socks-10058896-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 5384) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Stealer.557 (rule
Trojan.Stealer.557) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.02 (rule
DIE:UPX 3.02) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, UPX 3.02 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
9390 behavior events · 2 ATT&CK techniques · 18 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- bublikiadministrator.com
- bublikimanager.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- www.bing.com
- config.edge.skype.com
- dns.msftncsi.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- tas02.sls.update.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/3644/files/0f72bc664e121dfd2888771aa3f06a0b638d161d72337b918e2aa717b96e66fb -
0f72bc664e121dfd2888771aa3f06a0b638d161d72337b918e2aa717b96e66fb - /opt/CAPEv2/storage/analyses/3644/files/e9362f2a36795aaa096fcc5b69c98fabc6eaf62185cc6e6ac29b7949a6511f78 -
e9362f2a36795aaa096fcc5b69c98fabc6eaf62185cc6e6ac29b7949a6511f78 - /opt/CAPEv2/storage/analyses/3644/files/7a117a76ef1d0d5f2210b458ae5b578e5891bdf3bc84942d488cd3395ef16beb -
7a117a76ef1d0d5f2210b458ae5b578e5891bdf3bc84942d488cd3395ef16beb - /opt/CAPEv2/storage/analyses/3644/files/948c01346aa9a8655d4b2c3c2319615ae836a255df82ea9182643bd80b62ccce -
948c01346aa9a8655d4b2c3c2319615ae836a255df82ea9182643bd80b62ccce - /opt/CAPEv2/storage/analyses/3644/files/5017e332c9cdf4949e00313fdae133f82b4766f9d0e3fc9095a9e253a593534f -
5017e332c9cdf4949e00313fdae133f82b4766f9d0e3fc9095a9e253a593534f - /opt/CAPEv2/storage/analyses/3644/files/2a282397d1d96874a2769b18b8e5ca685ad9704675577c6525d7405d0402f7f9 -
2a282397d1d96874a2769b18b8e5ca685ad9704675577c6525d7405d0402f7f9 - /opt/CAPEv2/storage/analyses/3644/files/76baf95fcbfe0e36d92e9eafaae3723bade2d6017aca3ca60d67384b72980818 -
76baf95fcbfe0e36d92e9eafaae3723bade2d6017aca3ca60d67384b72980818 - /opt/CAPEv2/storage/analyses/3644/files/497876227b692eab5a29681e1399f2197e797bbd88b4d17bb7cdc64c928dc9a3 -
497876227b692eab5a29681e1399f2197e797bbd88b4d17bb7cdc64c928dc9a3 - /opt/CAPEv2/storage/analyses/3644/files/c533cbd21ee614fab3fa471fc3d5c9ada1afd46e8c0f270f9eeab29b528c070d -
c533cbd21ee614fab3fa471fc3d5c9ada1afd46e8c0f270f9eeab29b528c070d - /opt/CAPEv2/storage/analyses/3644/files/f8899f76d966f78a12102053bde038b6c8c3ff46b6139ae9e84062a65a240a95 -
f8899f76d966f78a12102053bde038b6c8c3ff46b6139ae9e84062a65a240a95 - /opt/CAPEv2/storage/analyses/3644/files/708e375cb5fe09d4bbd61dd5622f3ce1b5a11c5c4648cb7c4ce87d96f9c6151c -
708e375cb5fe09d4bbd61dd5622f3ce1b5a11c5c4648cb7c4ce87d96f9c6151c - /opt/CAPEv2/storage/analyses/3644/files/394dc21d1306e93028653b9c87b24ca352cdbb71d7e17bf7bbe1f298a92ebc5d -
394dc21d1306e93028653b9c87b24ca352cdbb71d7e17bf7bbe1f298a92ebc5d - /opt/CAPEv2/storage/analyses/3644/files/299781884e3ad77a2f8451eeb9073d12e2b4f8990648c8deeea5fda235d01cc7 -
299781884e3ad77a2f8451eeb9073d12e2b4f8990648c8deeea5fda235d01cc7 - /opt/CAPEv2/storage/analyses/3644/files/b8bb3390a885dad6217a75da3ecd06a026746c6c4e2dc39afb5124f04acb3c8a -
b8bb3390a885dad6217a75da3ecd06a026746c6c4e2dc39afb5124f04acb3c8a - /opt/CAPEv2/storage/analyses/3644/files/3d568500f214f01c68f828b22da79d26a817e3c0fc5466ea74cd5290ed7498b0 -
3d568500f214f01c68f828b22da79d26a817e3c0fc5466ea74cd5290ed7498b0
Embedded domains
- staging.to-do.officeppe.com
- bublikiadministrator.com
- bublikimanager.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- outlook.office365.com
- www.bing.com
- config.edge.skype.com
- dns.msftncsi.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- tas02.sls.update.microsoft.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- watson.events.data.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- www.msftncsi.com
More Socks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report