MALICIOUS — virussign.com_78577c9fe2b3216b69cd8950386e3130.vir
MALICIOUS — virussign.com_78577c9fe2b3216b69cd8950386e3130.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Copak family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7277184c4e79ceaa424ed1e147cf8cdaaa17849c4d87f6afee2c4aef22245356 - SHA-1:
44ab83739a2901021a45ba701bb8a41a4b550b03 - MD5:
78577c9fe2b3216b69cd8950386e3130 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
1536:0oaL5rQqU+amc5X820k3ySrGhRSkHrU8A7ZkC0CmuJd4BXac6F:lIQqNDoM5K6o8OZfBbd4InF - TLSH:
T146390280B364BEEFED509698801C01EFF41740CDA4B9A6C4B2C9877548A393794A7BD7 - Submitted as: virussign.com_78577c9fe2b3216b69cd8950386e3130.vir
- File type: pe · Size: 88609 bytes
- Verdict: malicious (99/100) · Family: Copak
Source: VirusSign · first seen 2026-07-17T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Packed.Copak-9853643-0
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Variant.Lazy.327786
- Kaspersky (KVRT): HEUR:Trojan.Win32.Copak.vho
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Packed.Copak-9853643-0 (rule
Win.Packed.Copak-9853643-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 8 finding(s), e.g. process hollowing in tsk_32844d7ab7 (pid 1600) (rule
windows.hollowprocesses.HollowProcesses) - memory signal, weight 0.70, confidence 0.85 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Lazy.327786 (rule
Gen:Variant.Lazy.327786) - engine signal, weight 0.55, confidence 0.85 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
109 behavior events · 1 ATT&CK techniques · 6 dropped files.
Runtime network
- www.msftconnecttest.com
- searchapp.bundleassets.example
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- desktop-hsgcbep
- config.edge.skype.com
- www.bing.com
- fd.api.iris.microsoft.com
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/3577/files/77d127c3e002b381c77c197b407211216adea83a8f6dd466d6e468e38652d52b -
77d127c3e002b381c77c197b407211216adea83a8f6dd466d6e468e38652d52b - 8c2385d89f00dcfc99e94d71b47b3ee90f761c8691cba7320eb7da7565ca452c -
8c2385d89f00dcfc99e94d71b47b3ee90f761c8691cba7320eb7da7565ca452c - 4c45e99c5ce882dcc900d019c0e040f6ddaa71f3cfa8ba1c5c6152fc9ddbd0d6 -
4c45e99c5ce882dcc900d019c0e040f6ddaa71f3cfa8ba1c5c6152fc9ddbd0d6 - b4927ab1f4db113037803364fc79740a3c52b1a57d6a5fd1a64cda1a0ef85db6 -
b4927ab1f4db113037803364fc79740a3c52b1a57d6a5fd1a64cda1a0ef85db6 - 09310d6c932cc35d2f6c97ef10d3b347110c2e2af22517439cbe74a59d567fe1 -
09310d6c932cc35d2f6c97ef10d3b347110c2e2af22517439cbe74a59d567fe1 - 2f0206255c41899474e6f2e61968a3e3638b3b2c4457cf4c81e0452f1a91946c -
2f0206255c41899474e6f2e61968a3e3638b3b2c4457cf4c81e0452f1a91946c
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
- www.msftconnecttest.com
- searchapp.bundleassets.example
- outlook.office.com
- outlook.office365.com
- config.edge.skype.com
- www.bing.com
- fd.api.iris.microsoft.com
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- ecs.office.com
- g.live.com
- www.msftncsi.com
- fs.microsoft.com
- watson.events.data.microsoft.com
More Copak samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report