SUSPICIOUS — virussign.com_87782d6fb9f7b88e98ad847e7ab19890.vir
SUSPICIOUS — virussign.com_87782d6fb9f7b88e98ad847e7ab19890.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100), attributed to the Emotet family. 2 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
89fe5dc3429716b0629ea60cad08b593ed1f431114973cc7849b752e662a0dfa - SHA-1:
3ada9d91b01111ccf841da72d36c9313a5bd032f - MD5:
87782d6fb9f7b88e98ad847e7ab19890 - imphash:
780e05e5b06fcc7ae9626db5cf3582fb - ssdeep:
24576:VKy1zwORVeEGRBOZRTnE7/N+x6diMgQXe9:DOueBRUZRbgW5pQXe9 - TLSH:
T12751F10A01073115C6F4ED2AA072E9ED0857FB1BA436CECA9302E94AC5C5F5FADE1479 - Submitted as: virussign.com_87782d6fb9f7b88e98ad847e7ab19890.vir
- File type: pe · Size: 839680 bytes
- Verdict: suspicious (51/100) · Family: Emotet
Source: VirusSign · first seen 2026-08-09T00:00:00.000Z · SHA-256 verified
Detections (2 of 52 engines)
- YARA: JPCERT/CC: JPCERT_Emotet
- Microsoft Defender: Virus:Win32/Expiro.HAB!MTB
MITRE ATT&CK
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://crash-reports.mozilla.com/submit, https://crash-reports-xpsp2.mozilla.com/submit - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2017/WindowsSettings
- https://crash-reports.mozilla.com/submit
- https://crash-reports-xpsp2.mozilla.com/submit
Embedded domains
- schemas.microsoft.com
- crash-reports.mozilla.com
- crash-reports-xpsp2.mozilla.com
File paths
- z:\task_1581954009\build\src\obj-firefox\toolkit\crashreporter\client\crashreporter.pdb
- F:\_i
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report