MALICIOUS — virussign.com_3be3129b3c041c88a7ee71f816132520.vir
MALICIOUS — virussign.com_3be3129b3c041c88a7ee71f816132520.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Virut family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
68fa7c436e293739e98bb04034db6d6a3e40a9b9991de5d147368fb696044499 - SHA-1:
cb39e471f962cc1a65304018804b7f26e6404754 - MD5:
3be3129b3c041c88a7ee71f816132520 - imphash:
3cba1ed6640987387f2c728a00db04c4 - ssdeep:
1536:jVonxm6MZNFfrvEaoiT/GyphjXDYjKwttoswRmhApE41f8LMlhNzlxC:GnxwVfR/DVG7wBpE4eLM15 - TLSH:
T17D3FF2D56838065DC102C31837D855BCD5EA77EBE19893300182AEB259BDD2BBFE0169 - Submitted as: virussign.com_3be3129b3c041c88a7ee71f816132520.vir
- File type: pe · Size: 151040 bytes
- Verdict: malicious (92/100) · Family: Virut
Detections (4 of 52 engines)
- Microsoft Defender: Trojan:Win32/Zusy.HNAA!MTB
- Emsisoft (Emergency Kit): Win32.Virtob.Gen.12
- Trellix Stinger (McAfee): W32/Virut.n.gen
- Kaspersky (KVRT): Virus.Win32.Virut.ce
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Zusy.HNAA!MTB (rule
Trojan:Win32/Zusy.HNAA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Virtob.Gen.12 (rule
Win32.Virtob.Gen.12) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged W32/Virut.n.gen (rule
W32/Virut.n.gen) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Virut.ce (rule
Virus.Win32.Virut.ce) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Virut samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report