MALICIOUS — virussign.com_384cd4bab12cfb3aba7a1fe86f739650.vir
MALICIOUS — virussign.com_384cd4bab12cfb3aba7a1fe86f739650.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Porcupine family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
a18280c9c08a4bb7ab5ba0534912a60d4951a34ee8eaff7434c6a21e9c3d6ca0 - SHA-1:
62f4577eefd12c6339e4df825c473994d39d49ac - MD5:
384cd4bab12cfb3aba7a1fe86f739650 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:SVRqsmdySFmQe15V6k4RFzV0nPdI+rkLzC5TP4c4OU4jc:2q3vje1L6k4RFzGnPl4C134P4jc - TLSH:
T1425301BD6FAB8D01C4FED01139B188ECA4D8BB47786C64C4E753627602D9A375C2486B - Submitted as: virussign.com_384cd4bab12cfb3aba7a1fe86f739650.vir
- File type: pe · Size: 1098752 bytes
- Verdict: malicious (94/100) · Family: Porcupine
Source: VirusSign · first seen 2026-08-07T00:00:00.000Z · SHA-256 verified
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:MSIL/DarkCloud.APYB!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.81049860
- Kaspersky (KVRT): HEUR:Trojan-PSW.MSIL.Agensla.gen
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://tempuri.org/DataSet1.xsd - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text, Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://tempuri.org/DataSet1.xsd
Embedded domains
- tempuri.org
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report