SUSPICIOUS — virussign.com_2411764d1171a739a4907c05d791bc20.vir
SUSPICIOUS — virussign.com_2411764d1171a739a4907c05d791bc20.vir is a zip sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (43/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
6d80c006a307ca644dead4baa4cb1116be0ed2ad9c19be96536489c6df44db18 - SHA-1:
a4a055323f4d5e75b279f59d9aad6bd0af39eeb4 - MD5:
2411764d1171a739a4907c05d791bc20 - ssdeep:
24576:MohtwO3Ay0OUF7sf/MvcpPITChDat5V7jHYVZyJp6NE5:Mo4OWFo/MvcZiAIjv4VZyL5 - TLSH:
T13051337591B8A37023948E3BC04563E853ADA80956CD9B231565FF938FD93EC8D7908C - Submitted as: virussign.com_2411764d1171a739a4907c05d791bc20.vir
- File type: zip · Size: 906020 bytes
- Verdict: suspicious (43/100)
Source: VirusSign · first seen 2026-08-31T00:00:00.000Z · SHA-256 verified
Detections (1 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 43/100 is the fusion of 3 weighted signals:
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: b4it_v2.exe - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- b4it_v2.exe -
961d64f8067e92c37258eb3a870fa5c364782be152e798373f44ea3d9320306b
Embedded domains
- ri0.gg
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report