MALICIOUS — virussign.com_6041adfd7b111ec0771ca709e5173b40.vir
MALICIOUS — virussign.com_6041adfd7b111ec0771ca709e5173b40.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Razy family. 7 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
73e9de9fd143d7dfd2d31b3317bb812001fdc58fd4bfca76ac9b9ee3ebd933b9 - SHA-1:
670d3f26f35d2ca3e19e305dbe84ab3ad75d27b0 - MD5:
6041adfd7b111ec0771ca709e5173b40 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
49152:QepLwwNhQD42mAuH+rZ+Mf+OX3s+W5kKG1YgJZGJvb+ay3BV:hpNhQT/X85k1ZYvy3 - TLSH:
T1E461AD8E31E84B8EC96ACF4EA844074D217706F93270ED69464C59A17CDE7336F5232A - Submitted as: virussign.com_6041adfd7b111ec0771ca709e5173b40.vir
- File type: pe · Size: 3883008 bytes
- Verdict: malicious (95/100) · Family: Razy
Source: VirusSign · first seen 2026-08-15T00:00:00.000Z · SHA-256 verified
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Razy-9859339-0
- YARA: delivr.to detections: DLV_HTML_Smuggling
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Injector.RAQ!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.Heur.T3W@!3u3dIo
- Kaspersky (KVRT): HEUR:Trojan.Win32.Copak.pef
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Malware.Razy-9859339-0 (rule
Win.Malware.Razy-9859339-0) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_HTML_Smuggling (rule
DLV_HTML_Smuggling) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://example-cmdline.test, http://example.test/path, http://example2.test/?query - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://example-cmdline.test
- http://example.test/path
- http://example2.test/?query
- http://example.test.file
- http://example.test
- http://example2.test
- https://www.example.com/
- https://clients1.google.com/tbproxy
- https://content-autofill.googleapis.com/
- http://www.google.com/
- https://example.com/
- https://chromium.org
- https://chromium.org/
- https://www.google.com
- http://foo.com/
- http://foo.com/#:~:text=hello%20world
- http://foo.com/#:~:text=hello
- http://facebook.com/my-profile
- http://foo.com/#bar
- http://foo.com/#bar:~:text=hello%20world
- http://foo.com/#bar:~:text=baz
- http://foo.com/#bar:~:text=baz&text=qux
- http://foo.com/#bar:~:baz=keep&text=remove&baz=keep2
- http://foo.com/#bar:~:baz=keep&baz=keep2&text=hello%20world
Embedded domains
- schemas.microsoft.com
- stack.cc
- field.cc
- logging.cc
- blink.net
- crbug.com
- thread.cc
- zip.cc
- pickle.cc
- www.example.com
- initech.com
- gmail.com
- a.com
- b.com
- clients1.google.com
- content-autofill.googleapis.com
- bounds.top
- wonderland.com
- www.google.com
- foo.com
- example.com
- chromium.org
- facebook.com
- start.com
- bar.com
More Razy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report