MALICIOUS — virussign.com_b9d4889cb04097a70b5f2e1845361d30.vir
MALICIOUS — virussign.com_b9d4889cb04097a70b5f2e1845361d30.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Small family. 5 of 55 detection engines flagged it.
Identification
- SHA-256:
a920b9e288d4f276efe98e39b0a1ec4f8ff7b2be1e2a3cbd06521ea920836d9e - SHA-1:
7679cca9aefb982d37fff50a0a01dff3a338d9b8 - MD5:
b9d4889cb04097a70b5f2e1845361d30 - imphash:
46646950e38cdd1519d35c0c539d2b12 - ssdeep:
1536:M3y/8KS2W1htUTvuDhzgzii+7EQr4aBC0HvpC:4KS2W1htUT2tIiiPSZBHBC - TLSH:
T15A360299112E149BCF2690749C3BD6FC16EF68A83047AF2EE1E2044F1268C274F5BE55 - Submitted as: virussign.com_b9d4889cb04097a70b5f2e1845361d30.vir
- File type: pe · Size: 66561 bytes
- Verdict: malicious (87/100) · Family: Small
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Trojan.Small-5420
- Microsoft Defender: Virus:Win32/Sality.AT
- Emsisoft (Emergency Kit): Trojan.SalityStub.F
- Kaspersky (KVRT): Virus.Win32.Sality.sil
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Small-5420 (rule
Win.Trojan.Small-5420) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Small samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report