MALICIOUS — virussign.com_22628d2409b7ef5eb0094ab3b69abce0.vir
MALICIOUS — virussign.com_22628d2409b7ef5eb0094ab3b69abce0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (77/100). 2 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
88e36649e957034a2827d73edbc69fd83558eeebf4c49686bfc64938e1270537 - SHA-1:
14a0ecf8a326dc2e253294ff0f6637574127962b - MD5:
22628d2409b7ef5eb0094ab3b69abce0 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
384:fxlXX5prsiaN91EeAASxG36+cNpGV5iPQn94If:f/nZuPiRG31iIV5H4C - TLSH:
T153284B8E61CA3FC8E5685D2E740F4CDE0A1671E8C0D8656AEC031CF000963574E6AE6F - Submitted as: virussign.com_22628d2409b7ef5eb0094ab3b69abce0.vir
- File type: pe · Size: 17737 bytes
- Verdict: malicious (77/100)
Source: VirusSign · first seen 2026-08-26T00:00:00.000Z · SHA-256 verified
Detections (2 of 55 engines)
- Microsoft Defender: Trojan:Win32/Sabsik.EN.A!ml
- Kaspersky (KVRT): HEUR:Exploit.Win32.BypassUAC.b
MITRE ATT&CK
Why this verdict
The malicious score of 77/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Sabsik.EN.A!ml (rule
Trojan:Win32/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Exploit.Win32.BypassUAC.b (rule
HEUR:Exploit.Win32.BypassUAC.b) - engine signal, weight 0.55, confidence 0.85 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
This sample is built for arm64, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
File paths
- C:\tool
- C:\tool\ms-settings.exe
- c:\tool\ms-settings
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report