SUSPICIOUS — virussign.com_922b576a66ddf0ce9f1e8667a1e02720.vir
SUSPICIOUS — virussign.com_922b576a66ddf0ce9f1e8667a1e02720.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (60/100), attributed to the Conti family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54ffbd4bdaf42de7f152081ac9362e2d3c29ff96abcabf8f424cf53c90168348 - SHA-1:
e5dd353c5a7f6e581bdc5ae6d1b86417c06a1dfc - MD5:
922b576a66ddf0ce9f1e8667a1e02720 - imphash:
c5d286f6edc0234189264d988bae2cff - ssdeep:
24576:47VKG/tF5T+0jM6UJfz1ET+/pFCkAAYWDhjKeGBXsOuwA+wWBGwMOZc:T6F0eMpAAYEhpXwhwWGwMf - TLSH:
T1E4577D21420A2759ECE6D8B9D00C9F6C506BB88963B58FDCAB57C60DA3D5CB384350E7 - Submitted as: virussign.com_922b576a66ddf0ce9f1e8667a1e02720.vir
- File type: pe · Size: 1474071 bytes
- Verdict: suspicious (60/100) · Family: Conti
Source: VirusSign · first seen 2026-08-08T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- YARA: Trellix/McAfee ATR: ATR_Conti_Ransomware
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Zusy.ED!MTB
- Kaspersky (KVRT): HEUR:Trojan-PSW.Win32.Stealer.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 60/100 is the fusion of 4 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_Conti_Ransomware (rule
ATR_Conti_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://gcc.gnu.org/bugs/ - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gcc.gnu.org/bugs/
- http://www.w3.org/2001/XMLSchema
- http://forefront.microsoft.com/FEP/2010/01/PolicyData
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- gcc.gnu.org
- www.w3.org
- forefront.microsoft.com
- www.microsoft.com
- crl.microsoft.com
File paths
- C:\Users\Public\README.txt
- C:\crossdev\gccmaster\build-tdm32\gcc-sjlj\mingw32\libgcc
- C:\Windows\System32
- C:\Windows\SysWOW64
- C:\Users\
More Conti samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report