SUSPICIOUS — virussign.com_9154f4c953de9058d9c445ab17798c10.vir
SUSPICIOUS — virussign.com_9154f4c953de9058d9c445ab17798c10.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 4 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
55cc18ea00fb4139d239c148d8f47688a36e63dca754dad327357831b15b0e6f - SHA-1:
3bf5c997e92cfe60a535cdc12e3ee67556cc35f5 - MD5:
9154f4c953de9058d9c445ab17798c10 - imphash:
d5006f9e23934fe71d908e1c3968d3d9 - ssdeep:
24576:Q1yeY/ixYyuLqEXpTbTvTsqjnhMgeiCl7G0nehbGZpbD:MyX/iBO5TfDmg27RnWGj - TLSH:
T19D548B2D5E065602DF6EB064DBE569DCCF523CBD11E496DBE202C80ADCA191FCBA2131 - Submitted as: virussign.com_9154f4c953de9058d9c445ab17798c10.vir
- File type: pe · Size: 1205248 bytes
- Verdict: suspicious (54/100)
Source: VirusSign · first seen 2026-08-20T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- Microsoft Defender: Virus:Win32/Expiro.HNW!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.7
- Trellix Stinger (McAfee): W32/Expiro.gen.re
- Kaspersky (KVRT): Virus.Win64.Moiva.a
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 8 weighted signals:
- Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 38 external host(s) at runtime (77 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://www.winimage.com/zLibDll - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 21 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
14034 behavior events · 2 ATT&CK techniques · 24 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- pywolwnvd.biz
- ssbzmoy.biz
- cvgrf.biz
- npukfztj.biz
- przvgke.biz
- zlenh.biz
- knjghuig.biz
- uhxqin.biz
- anpmnmxo.biz
- www.anpmnmxo.biz
Dropped files
- C:\Windows\System32\dllhost.exe -
d2e60fde36ca48bc468b65a2b5a27d374bbe5023f20a4166ed755696e9ae00af - C:\Program Files\LibreOffice\program\update_service.exe -
0173ae2d2ce935a282f6ed84a442af0c807a191694a79d3171664f7e738b87eb - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
2cca96a5df707406e7fb68633c22c1e0ba34db4eda03fe5b40dc6dcbc850fd04 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe -
e323700fea7692c0344fb3589e7c35bb8f66e523937bca3d59568dd3f6ae77d8 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
4d3a139de9fb7af42e5483d50d5e7344a0d52016514ad5e9272c9b1601a7212d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccesswalker.exe -
615c5bc407c733993f4030a6a7b493913d78b74cfcddd101906bbdbc3d7fcd64 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
d6d6e269686b204f78ddef09de1f88f40ff319caf615f0b15b0912ade5eb8c8a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\klist.exe -
da7aa92b6035342a550b07cff5b845b73de2a35a650549a8edd3171094241089 - C:\Program Files (x86)\Microsoft\Edge\Application\150.0.4078.105\elevation_service.exe -
2119adebc1b8db2862c960624ebe284362897eeb96a4d82912375ee62dc2d27a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jrunscript.exe -
253d7e185c4e36de28a4e82a10b2a5cbdbfb9041ce833787d68586d4a060442d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jwebserver.exe -
609ec10a170eb768b4b1b1dcdc13b737a01e86d07e40388f4bcefc7a8951dc95 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
483c7d10e1819b522f2f6595e4f0c68197e1801153e516c7b66c07cd37a07408 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jabswitch.exe -
2890c2aa5643b39f3248f8daa6c60e25fd0ed63949a6ece169855045dcc45d21 - C:\Windows\SysWOW64\perfhost.exe -
9c4f783f941a2afeafbf9d7c43a5091e5687777dc5382e62d91b7a9b77bcda97
Embedded URLs
- http://www.winimage.com/zLibDll
- http://schemas.microsoft.com/SMI/2020/WindowsSettings
- https://download.onlyoffice.com/install/desktop/editors/windows/onlyoffice/appcastdev.json
- https://download.onlyoffice.com/install/desktop/editors/windows/onlyoffice/appcast.json
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://pywolwnvd.biz/habvqyvjbirytep
- http://ssbzmoy.biz/itgskpop
- http://cvgrf.biz/xjsvhymrx
- http://npukfztj.biz/x
- http://przvgke.biz/ichfarfmr
- http://przvgke.biz/rjxsunf
- http://zlenh.biz/pqud
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787850375&P2=404&P3=2&P4=lNLOU4vT6HRS3JgYMScdglQ2lK3afkLQIlwZ7ilP13M8kBxku9thTifg6Fgv6LJK8%2fimQVFyI9QccPeThGnldQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://knjghuig.biz/pegtplpkekytmf
- http://anpmnmxo.biz/mcxc
- http://www.anpmnmxo.biz/mcxc
- http://pywolwnvd.biz/sepcdbfmrgfkwe
- http://anpmnmxo.biz/srrbrps
- http://www.anpmnmxo.biz/srrbrps
- http://lpuegx.biz/taipwwiyp
- http://vjaxhpbji.biz/obtshvpltjoawp
- http://xlfhhhm.biz/pxulrinucrtwyu
Embedded domains
- www.winimage.com
- schemas.microsoft.com
- download.onlyoffice.com
- pywolwnvd.biz
- ssbzmoy.biz
- cvgrf.biz
- npukfztj.biz
- przvgke.biz
- zlenh.biz
- knjghuig.biz
- uhxqin.biz
- anpmnmxo.biz
- www.anpmnmxo.biz
- lpuegx.biz
- vjaxhpbji.biz
- xlfhhhm.biz
- ifsaia.biz
- saytjshyf.biz
- vcddkls.biz
- fwiwk.biz
- tbjrpv.biz
- deoci.biz
- gytujflc.biz
- qaynky.biz
- bumxkqgxu.biz
Embedded IP addresses
- 20.184.175.9
- 52.230.60.54
- 4.230.171.124
- 4.247.188.233
- 135.233.95.144
- 52.168.117.170
- 74.178.76.54
- 20.112.250.133
- 52.123.128.14
- 40.103.64.226
- 52.123.129.14
- 40.104.4.2
- 20.42.179.204
- 52.123.252.215
- 44.244.22.128
- 34.41.139.193
- 135.234.160.246
- 3.229.117.57
- 52.27.79.221
- 203.26.79.13
- 50.16.27.236
- 2.59.170.19
- 52.16.171.153
- 3.238.30.69
- 20.165.94.46
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report