MALICIOUS — virussign.com_2761f8573f54d24658462da8ce505a60.vir
MALICIOUS — virussign.com_2761f8573f54d24658462da8ce505a60.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Crypted family. 5 of 56 detection engines flagged it.
Identification
- SHA-256:
8e14122c3b73b6aabe87a10cb1b21d76e8ac2dc6e53b5fef55be177f735fddf6 - SHA-1:
51e71bbba8cbd045029fb8537dc188291ed4fea2 - MD5:
2761f8573f54d24658462da8ce505a60 - imphash:
e113f8a903eeb141d2133ab70f1616dc - ssdeep:
1536:xtABTEQaaVuVJUs05DI455n55G55n55n55I55I55I55o+5555555555Ac553555C:LuzalzUagh4g+2eso - TLSH:
T17D354A1092DCA85DD8F58869B085DEFFEB321BDE343415A9D3C45EC1E86A4CB500E6E8 - Submitted as: virussign.com_2761f8573f54d24658462da8ce505a60.vir
- File type: pe · Size: 60416 bytes
- Verdict: malicious (99/100) · Family: Crypted
Source: VirusSign · first seen 2026-08-25T00:00:00.000Z · SHA-256 verified
Detections (5 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: TrojanDownloader:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Backdoor.Hangup.B
- Trellix Stinger (McAfee): Trojan-FVOJ!2761F8573F54
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
Why this verdict
The malicious score of 99/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanDownloader:Win32/Berbew!pz (rule
TrojanDownloader:Win32/Berbew!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Backdoor.Hangup.B (rule
Backdoor.Hangup.B) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FVOJ!2761F8573F54 (rule
Trojan-FVOJ!2761F8573F54) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Spy.Win32.Qukart.af (rule
Trojan-Spy.Win32.Qukart.af) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://metalink.oracle.com
Embedded domains
- microsoft.com
- metalink.oracle.com
- www.oracle.com
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report