MALICIOUS — virussign.com_42ad506165670c5ea17ac250c2f73b80.vir
MALICIOUS — virussign.com_42ad506165670c5ea17ac250c2f73b80.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the MPRESS family. 7 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8fd2c72213278d1e8ceb52faf2a83447d5b5dd5aa66de76e955e93561a0ebb93 - SHA-1:
70fc862311e3d937b634f3d20ce96ece32ec78dc - MD5:
42ad506165670c5ea17ac250c2f73b80 - imphash:
9dacd5fc505421be83fd9ef325d44b59 - ssdeep:
1536:mAocdpeVoBDulhzHMb7xNAa04Mcg5bx7DUQeDac7AkT70:0cdpeeBSHHMHLf9Rybx7DYec7F0 - TLSH:
T16F3BC86796A7A489CD34709B3F4F7350B040B9F00612798635ACE29FBE7758B46838C6 - Submitted as: virussign.com_42ad506165670c5ea17ac250c2f73b80.vir
- File type: pe · Size: 110252 bytes
- Verdict: malicious (97/100) · Family: MPRESS
Source: VirusSign · first seen 2026-07-13T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Trojan.BlackMoon-4255490-1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS 2.01-2.12
- Microsoft Defender: TrojanDropper:Win32/Dinwod!pz
- Trellix Stinger (McAfee): Trojan-FPCQ!BA60F51D4D97
- Kaspersky (KVRT): Trojan-Dropper.Win32.Dinwod.acqn
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.BlackMoon-4255490-1 (rule
Win.Trojan.BlackMoon-4255490-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7384) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 2.01-2.12 (rule
DIE:MPRESS 2.01-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 2.01-2.12 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
25 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- www.bing.com
- config.edge.skype.com
- desktop-hsgcbep
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- edge.microsoft.com
- msedge.api.cdp.microsoft.com
- 192.168.122.108
- 192.168.122.1
- 192.168.122.255
- 224.0.0.252
- 192.168.122.105
- 192.168.122.106
Embedded domains
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- www.bing.com
- config.edge.skype.com
- aps.prod.windows.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- to-do.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- edge.microsoft.com
- msedge.api.cdp.microsoft.com
More MPRESS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report