MALICIOUS — virussign.com_0c02d66648e87cd717466a3cc79fada0.vir
MALICIOUS — virussign.com_0c02d66648e87cd717466a3cc79fada0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Neshuta family. 6 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a34b9fb5390555cd31016a5effbb2ca12e9c2c4b768ba81ac2437d1b1cd79572 - SHA-1:
7af9c78e4cd3573b0e275fc4ea7e7d60ccbe7e51 - MD5:
0c02d66648e87cd717466a3cc79fada0 - imphash:
9f4693fc0c511135129493f2161d1e86 - ssdeep:
49152:xwqTBMEbZ+aXlKDixBcjs2QSGrHg1w5MpMPxV+J+S:NBRPMiQvI3CQS - TLSH:
T1BA5D6C9A40172122D0F9DD45B421C8DDC023F95995359DCE8207DA2BD3AAEBBBBE00F5 - Submitted as: virussign.com_0c02d66648e87cd717466a3cc79fada0.vir
- File type: pe · Size: 2782288 bytes
- Verdict: malicious (100/100) · Family: Neshuta
Source: VirusSign · first seen 2026-07-16T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- ClamAV (daily): Win.Trojan.Neshuta-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Win32.Neshta.A
- Kaspersky (KVRT): Virus.Win32.Neshta.a
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Neshuta-1 (rule
Win.Trojan.Neshuta-1) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 6 finding(s), e.g. RWX/private injected region in powershell.exe (pid 2524) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Neshta.A (rule
Win32.Neshta.A) - engine signal, weight 0.55, confidence 0.85 - Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Extracted Neshta config (0 C2) - engine signal, weight 0.45, confidence 0.60
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://perfetto.dev/docs/contributing/getting-started#community, https://cr.brave.com, 149.1.91.180 - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
38148 behavior events · 1 ATT&CK techniques · 12 dropped files.
Runtime network
- www.msftconnecttest.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- www.bing.com
- edge.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
- www.msftncsi.com
- self.events.data.microsoft.com
- fs.microsoft.com
- msedge.api.cdp.microsoft.com
- 192.168.122.106
- 192.168.122.255
- 224.0.0.252
- 192.168.122.1
- 239.255.255.250
- 192.168.122.107
Dropped files
- /opt/CAPEv2/storage/analyses/3503/files/4f97faf091b62f5388d1a1a47a6bc01e4fe043b097e7a5058c8c5113d07338e4 -
4f97faf091b62f5388d1a1a47a6bc01e4fe043b097e7a5058c8c5113d07338e4 - /opt/CAPEv2/storage/analyses/3503/files/ca214b1eb79affecbc8243e3623adf24a71e997b16645b7f6f75f7d3bc73eea3 -
ca214b1eb79affecbc8243e3623adf24a71e997b16645b7f6f75f7d3bc73eea3 - /opt/CAPEv2/storage/analyses/3503/files/1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce -
1d226b903057fe28368936de50d0bb76313e640658c58eabc557bd19bdc99bce - /opt/CAPEv2/storage/analyses/3503/files/8be4d3fe6d043736cc43ff142e5777f8031061b59a3bfb759cc412d4f3aa27e4 -
8be4d3fe6d043736cc43ff142e5777f8031061b59a3bfb759cc412d4f3aa27e4 - /opt/CAPEv2/storage/analyses/3503/files/c6906999be24eb179a7d10da68e30225afd714df64cd7a61b5c3ed86b11821df -
c6906999be24eb179a7d10da68e30225afd714df64cd7a61b5c3ed86b11821df - /opt/CAPEv2/storage/analyses/3503/files/e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad -
e0ba6e5956df3030ad88ce1b9cf7a9fc2ac3cff515de74e4d00121093ef93cad - /opt/CAPEv2/storage/analyses/3503/files/1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 -
1107131572ebfc722a3ff7285a01b94ac46199b43deda582733440e2f08b4108 - /opt/CAPEv2/storage/analyses/3503/files/485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4 -
485a638ad44e80f2d49584e04d9983c163d2e6bec927fe037d897c3a84bb55f4 - /opt/CAPEv2/storage/analyses/3503/files/0cbd2e0569b8bd047bc5a764d5858025914e41bfcc17d76a4361a1f1a6ea50f8 -
0cbd2e0569b8bd047bc5a764d5858025914e41bfcc17d76a4361a1f1a6ea50f8 - /opt/CAPEv2/storage/analyses/3503/files/ca436eb4ebf620e689939f7a4ef39ec7a4a7f56f0cce58b54f65713a84f1a09d -
ca436eb4ebf620e689939f7a4ef39ec7a4a7f56f0cce58b54f65713a84f1a09d - /opt/CAPEv2/storage/analyses/3503/files/c6882fa9aa153a41b466dee923b7a0504b8f0338e33ab7c6132c74c09c28a581 -
c6882fa9aa153a41b466dee923b7a0504b8f0338e33ab7c6132c74c09c28a581 - /opt/CAPEv2/storage/analyses/3503/files/f0222b4034c53d1069526bec74684ef347eadc991d8f28fdd183b43dc8023817 -
f0222b4034c53d1069526bec74684ef347eadc991d8f28fdd183b43dc8023817
Embedded URLs
- https://perfetto.dev/docs/contributing/getting-started#community
- https://cr.brave.com
- http://www.digicert.com/CPS0
Embedded domains
- openssl.org
- mutex.cc
- field.cc
- time.cc
- utils.cc
- rds.descriptor.name
- descriptor.name
- perfetto.dev
- regex.cc
- allocator.cc
- executor.cc
- parser.cc
- cr.brave.com
- blink.net
- thread.cc
- sequence.cc
- values.cc
- histogram.cc
- mem.cc
- regexp.cc
- re2.cc
- tostring.cc
- simplify.cc
- parse.cc
- onepass.cc
Embedded IP addresses
- 149.1.91.180
More Neshuta samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report