MALICIOUS — virussign.com_565c4651ac0b2e83742df659df168110.vir
MALICIOUS — virussign.com_565c4651ac0b2e83742df659df168110.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Cerbu family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
6fdc5d3a28214c3ee0defdd476e9852cf26927408026f3555254e16559aaf1e8 - SHA-1:
3698dae9a3b3309a801d453105528b546c80f5dd - MD5:
565c4651ac0b2e83742df659df168110 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
3072:l20hjjfFXzyAHPjpBczdDknNrFQfDn42WsA3MbYYpRyV5nFsZoiw:l5XzyAHPPcRDknN6dAcsXV5nFtj - TLSH:
T1863FF140236D663BC9AB259F84D5A93F40C6326F3850187083B4E69EA07CA27651F79F - Submitted as: virussign.com_565c4651ac0b2e83742df659df168110.vir
- File type: pe · Size: 150098 bytes
- Verdict: malicious (86/100) · Family: Cerbu
Detections (3 of 52 engines)
- ClamAV (daily): Win.Trojan.Cerbu-10059064-0
- Microsoft Defender: Trojan:Win32/Copak.KKA!MTB
- Kaspersky (KVRT): UDS:Trojan.Win32.Copak
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Trojan.Cerbu-10059064-0 (rule
Win.Trojan.Cerbu-10059064-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- howtotell.com
- microsoft.com
More Cerbu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report