MALICIOUS — virussign.com_0685a1627d829b1454b7aca3ea84a590.vir
MALICIOUS — virussign.com_0685a1627d829b1454b7aca3ea84a590.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Socks family. 5 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6d7166a4b1161f2792ca99271d1f6132348bf5aa3768956d0df5032a13b7b182 - SHA-1:
e3a7cd9b93a31f4898a9cc5f5cea82014b240f7a - MD5:
0685a1627d829b1454b7aca3ea84a590 - imphash:
28fb261079ccd4a68cc8ba2684eee9e9 - ssdeep:
24576:L9C0XrUMFDsTB6vGPG2LW+P+mzRe+rYsVbjVljQkaZkCJNFnP+hUe3bnrR0:L9C0Xgfe2DRe+rZVbjHGJNFnP+h/Di - TLSH:
T10456338D47305474EE81EE0CB7228D5D66CD185A8BF9D32B26F88E9C62A20FF4132575 - Submitted as: virussign.com_0685a1627d829b1454b7aca3ea84a590.vir
- File type: pe · Size: 1431481 bytes
- Verdict: malicious (92/100) · Family: Socks
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Socks-10
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Backdoor:Win32/Koceg!atmnm
- Kaspersky (KVRT): HEUR:Trojan.Win32.Nosok.gen
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Worm.Socks-10 (rule
Win.Worm.Socks-10) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- ha.ru
- id.fr
File paths
- c:\stop
More Socks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report