MALICIOUS — virussign.com_fa16178585b301e2a2746b863a964a70.vir
MALICIOUS — virussign.com_fa16178585b301e2a2746b863a964a70.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Virlock family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
8f5e05c41c4e28959d3900bfa64ca0b6f091cb19fe277893497910969c9ec28d - SHA-1:
39c3f16ab31622553fd4c0263089c5285756c003 - MD5:
fa16178585b301e2a2746b863a964a70 - imphash:
3faf9451777b936ed8007027686e62ad - ssdeep:
12288:lRGHK+gbmSN8eQjaLiXsE+7YalafHeYmIeAWuWdCQi0MAPlp:PGgqYiP+7DTYmIehuWdCNMp - TLSH:
T19F53ACA952A433F0C2C6EF5199E60CAD2B0B1F5172409579317FDA06B09FBDFA2910B1 - Submitted as: virussign.com_fa16178585b301e2a2746b863a964a70.vir
- File type: pe · Size: 1092608 bytes
- Verdict: malicious (86/100) · Family: Virlock
Source: VirusSign · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Virlock-6332874-0
- Kaspersky (KVRT): Virus.Win32.PolyRansom.b
- Microsoft Defender: Virus:Win32/Nabucur.A
- Emsisoft (Emergency Kit): Win32.Virlock.Gen.1
- Trellix Stinger (McAfee): W32/VirRansom.b
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Virus.Virlock-6332874-0 (rule
Win.Virus.Virlock-6332874-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Virlock samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report