MALICIOUS — virussign.com_66bbe368d85be9807d5465c325d9c850.vir
MALICIOUS — virussign.com_66bbe368d85be9807d5465c325d9c850.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Convagent family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
911e8d9e7b6a0c9e020359c4d635319fdf2fccc466229285153c69e179ed6c63 - SHA-1:
8308eb33939ee61f9779010a4af49743e7c149e6 - MD5:
66bbe368d85be9807d5465c325d9c850 - imphash:
20c3dae8b5858a3256f3a0cb80094852 - ssdeep:
3072:5m87+KH8//ov1Ji5gBJqSXDBx1Lfo3UHnS8dY/FNG4qDXhJgBqL:5m6+Y8H81JieJ/rZoz8kN1qDXhJg2 - TLSH:
T1323CF1622E782398E6928A9BAE884C1CE472537CDFF2049965C3EC5953DDE372524C48 - Submitted as: virussign.com_66bbe368d85be9807d5465c325d9c850.vir
- File type: pe · Size: 122392 bytes
- Verdict: malicious (92/100) · Family: Convagent
Detections (4 of 55 engines)
- ClamAV (daily): Win.Malware.Convagent-9981433-0
- Microsoft Defender: Trojan:Win32/Zusy.CCJL!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKDZ.119224
- Kaspersky (KVRT): Trojan.Win32.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Convagent-9981433-0 (rule
Win.Malware.Convagent-9981433-0) - engine signal, weight 0.90, confidence 0.95 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://app.csvhost.info/loader/spoolsv.tmp, http://app.csvhost.info/loader/ - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://app.csvhost.info/loader/spoolsv.tmp
- http://app.csvhost.info/loader/
Embedded domains
- app.csvhost.info
File paths
- D:\Dropbox\My
More Convagent samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report