MALICIOUS — virussign.com_eb23b0326b073143ae28acbaa217df80.vir
MALICIOUS — virussign.com_eb23b0326b073143ae28acbaa217df80.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Virlock family. 6 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6ee1adcbb9846a87538e9cda8ecd8a71fe61d9b38521896970070b55f29ad5bd - SHA-1:
940c3ad44fe4e31217dac7e635ed972126d89fa3 - MD5:
eb23b0326b073143ae28acbaa217df80 - imphash:
a9689556034c6915188af9ac0355d86d - ssdeep:
49152:ueVX4Akm/kBaiZUJHO/2jLuhwNB9oqv3tJQIz/fBcQuNeRM4JZZh9TcDqYtw+oy7:Hoj/WLuhwNB9V9S9zeRy/ - TLSH:
T1D85ED06E3FDC61CAB96AF441417C708F209D60C681C252225B7A8D9BAECF1073A5D2F5 - Submitted as: virussign.com_eb23b0326b073143ae28acbaa217df80.vir
- File type: pe · Size: 3013120 bytes
- Verdict: malicious (92/100) · Family: Virlock
Source: VirusSign · first seen 2026-08-05T00:00:00.000Z · SHA-256 verified
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Virus.Virlock-6332874-0
- Microsoft Defender: Trojan:Win32/Mikey.HNB!MTB
- Emsisoft (Emergency Kit): Win32.Virlock.Gen.1
- Trellix Stinger (McAfee): W32/VirRansom.b
- Kaspersky (KVRT): Virus.Win32.PolyRansom.b
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Virus.Virlock-6332874-0 (rule
Win.Virus.Virlock-6332874-0) - engine signal, weight 0.90, confidence 0.95 - Contacted 34 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
212 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/33206/files/cedacf90bcc905832bbfe50f768374b917eb532bf030bcc4ec421e823f4a6401 -
cedacf90bcc905832bbfe50f768374b917eb532bf030bcc4ec421e823f4a6401 - /opt/CAPEv2/storage/analyses/33206/files/0f05d0b7e39a6e1850ee84623462733018d741f4f05e9fc72668e6c648c1c0cd -
0f05d0b7e39a6e1850ee84623462733018d741f4f05e9fc72668e6c648c1c0cd - a2350e29a548a91234c16501fe1a6558bb3db7b96921f8c723f8c29c44348bdd -
a2350e29a548a91234c16501fe1a6558bb3db7b96921f8c723f8c29c44348bdd
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1787184187&P2=404&P3=2&P4=U1HQ5KV6I1GEDClwxYpFpJbyQPZFeEER0%2f2%2fDnhAyVR1aK7YagpEwPkVlytCHxjx2LlxU6Rf7SBCcz2pCYSTiA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- c.to
- h.sh
Embedded IP addresses
- 184.84.165.138
- 40.74.98.196
- 52.230.59.222
- 4.230.171.124
- 57.155.101.212
- 74.178.76.128
- 20.184.175.18
- 74.179.77.164
- 52.123.129.14
- 20.236.44.162
- 52.123.128.14
- 20.42.65.88
- 172.178.240.162
- 203.26.79.13
- 72.145.35.96
- 135.233.95.80
- 52.148.114.188
- 125.56.205.26
- 52.110.12.31
- 52.110.12.26
- 125.56.205.17
File paths
- m:\zc
- V:\]T
More Virlock samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report