MALICIOUS — virussign.com_425427b3035e13aecbf0f7cce27e13c0.vir
MALICIOUS — virussign.com_425427b3035e13aecbf0f7cce27e13c0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Downware family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
987412822ea966f2218a35b8efb6a685f436b2d702b6ebe525782d9ee03d94b1 - SHA-1:
e54f3271df617fee231fbf8bb9b46c6248ab6bda - MD5:
425427b3035e13aecbf0f7cce27e13c0 - imphash:
87bed5a7cba00c7e1f4015f1bdae2183 - ssdeep:
48:qfAqMrhWR69rDvrXkxLVYuX/2svystYVzwG4RApLeQN:FlrY6JrrXk3vbduVzwG4+T - TLSH:
T1BD176447E37838E4E746FB7960A3980DFEF528611127BC829D59DC71528C9A32001736 - Submitted as: virussign.com_425427b3035e13aecbf0f7cce27e13c0.vir
- File type: pe · Size: 3584 bytes
- Verdict: malicious (98/100) · Family: Downware
Source: VirusSign · first seen 2026-07-16T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- ClamAV (daily): Win.Adware.Downware-242
- Microsoft Defender: TrojanDownloader:Win32/Andromeda.SIB!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Zusy.325289
- Kaspersky (KVRT): Worm.Win32.Debris.aq
- Trellix Stinger (McAfee): Trojan-FCPJ!425427B3035E
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Adware.Downware-242 (rule
Win.Adware.Downware-242) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7220) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged TrojanDownloader:Win32/Andromeda.SIB!MTB (rule
TrojanDownloader:Win32/Andromeda.SIB!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Zusy.325289 (rule
Gen:Variant.Zusy.325289) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
49 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
Embedded domains
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.cloud.microsoft
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- outlook.office365.com
- www.bing.com
- config.edge.skype.com
- tas02.sls.update.microsoft.com
- to-do.microsoft.com
- settings-win.data.microsoft.com
- dns.msftncsi.com
- ctldl.windowsupdate.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- teams.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- msedge.api.cdp.microsoft.com
More Downware samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report