MALICIOUS — virussign.com_ab2f1a30f28fc9b5bcd70715ecbf5640.vir
MALICIOUS — virussign.com_ab2f1a30f28fc9b5bcd70715ecbf5640.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Porcupine family. 9 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a426bea7d2bee5dc12fbf22e7fd25dcf0db71934c9c2b95882699ea2a2140195 - SHA-1:
5c6fa778970c8e78e0883a803d88ac24e3341919 - MD5:
ab2f1a30f28fc9b5bcd70715ecbf5640 - imphash:
949cef2334ce15b6cd657f1ef7e0d772 - ssdeep:
49152:f4qMMGqeFE9xVJHBcN6KlaBz2VhAa5cR1fiYGOzuh0a3xt:fTMMGqeFMVDcN6YaBz2H5+1KYGOzuh0S - TLSH:
T1515BBF6A1941B702F9B7C7A2BC125E4DA011A8EB31FC2E4DA3936C2F5EC745F624D019 - Submitted as: virussign.com_ab2f1a30f28fc9b5bcd70715ecbf5640.vir
- File type: pe · Size: 2194551 bytes
- Verdict: malicious (98/100) · Family: Porcupine
Source: VirusSign · first seen 2026-08-09T00:00:00.000Z · SHA-256 verified
Detections (9 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 8 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sv.symcb.com/sv.crl0f, https://d.symcb.com/rpa0, http://sv.symcb.com/sv.crt0 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://sv.symcb.com/sv.crl0f
- https://d.symcb.com/rpa0
- http://sv.symcb.com/sv.crt0
- http://www.symauth.com/cps0
- http://www.symauth.com/rpa00
- http://s1.symcb.com/pca3-g5.crl0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://crl.thawte.com/ThawteTimestampingCA.crl0
Embedded domains
- schemas.microsoft.com
- sv.symcb.com
- d.symcb.com
- www.symauth.com
- s1.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- crl.thawte.com
File paths
- D:\SVNs\_ChainInstaller\trunk\Release\inst.pdb
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
- f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report