MALICIOUS — virussign.com_37765b7cbf4c334f81612f80caea6360.vir
MALICIOUS — virussign.com_37765b7cbf4c334f81612f80caea6360.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Pioneer family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
7ec8e003e8c23255a85beb2e8aa0f1ec26514d7407203b0b4a28b0193cd285dd - SHA-1:
06062e04da18d3ae5ffe675b33156eb640fc3aca - MD5:
37765b7cbf4c334f81612f80caea6360 - imphash:
55df0a7d46dcea966502b011ac4cb938 - ssdeep:
3072:vanYtBhrPGUl1GqOgqq7C1e1W2lQBV+UdE+rECWp7hKUAYgESJ:SYtBZOgqqwWcBV+UdvrEFp7hKhYgESJ - TLSH:
T1CE3EC0778137A058E326F39EA502138CA8C29CADE66A30805707D6DF2D95C2F7D7D690 - Submitted as: virussign.com_37765b7cbf4c334f81612f80caea6360.vir
- File type: pe · Size: 136991 bytes
- Verdict: malicious (89/100) · Family: Pioneer
Source: VirusSign · first seen 2026-08-10T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Pioneer-9111434-0
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Virus.Pioneer-9111434-0 (rule
Win.Virus.Pioneer-9111434-0) - engine signal, weight 0.90, confidence 0.95 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
Embedded domains
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
File paths
- d:\SRC\XecureCertShare\XCSClient\XCSNativeMng\vs2005project\Win32\Release\XCSNativeMng.pdb
More Pioneer samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report