SUSPICIOUS — virussign.com_465f63399ad862a1265962ea6d496790.vir
SUSPICIOUS — virussign.com_465f63399ad862a1265962ea6d496790.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
a9fdc71681ffc0f1921ba2e5b392b2c1c71f5acfe2d81a560a36ece766dae037 - SHA-1:
076b36e198f963939a5f86e7abf4e7d13c86dd46 - MD5:
465f63399ad862a1265962ea6d496790 - ssdeep:
768:Gq0bT5ugg15aTwW0bT5ugg15aTwZnsG8ew:FAT5ugg15aTwWAT5ugg15aTwZnY - TLSH:
T1793194C93E0B468FD40C2D11B85CB8A46DDEE7EBD82088D6C559D78C8CD4988BE8D578 - Submitted as: virussign.com_465f63399ad862a1265962ea6d496790.vir
- File type: html · Size: 41321 bytes
- Verdict: suspicious (54/100)
Source: VirusSign · first seen 2026-08-22T00:00:00.000Z · SHA-256 verified
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://random-affiliate.atimaze.com/, https://images.purevpnaffiliates.com, https://s-img.adskeeper.com/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- settings-win.data.microsoft.com
- windows.msn.com
- officeclient.microsoft.com
- www.msn.com
- odc.officeapps.live.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- licensing.mp.microsoft.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Embedded URLs
- https://random-affiliate.atimaze.com/
- https://images.purevpnaffiliates.com
- https://s-img.adskeeper.com/
- https://paid.outbrain.com/network/redir
- https://rcm-fe.amazon-adsystem.com/
- https://challenges.cloudflare.com/turnstile/v0/api.js
- https://www.cloudflare.com/learning/access-management/phishing-attack/
- https://www.cloudflare.com/5xx-error-landing
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- random-affiliate.atimaze.com
- images.purevpnaffiliates.com
- s-img.adskeeper.com
- paid.outbrain.com
- wallpaperaccess.com
- body.no
- rcm-fe.amazon-adsystem.com
- div.app
- div.cc
- div.dev
- div.edu
- div.eu
- challenges.cloudflare.com
- uselnk.com
- passtechusa.com
- www.cloudflare.com
Embedded IP addresses
- 0.0.1.1
- 90.187.238.157
- 20.42.72.131
- 57.155.104.224
- 4.230.171.124
- 52.230.60.54
- 74.178.76.54
- 172.215.188.225
- 20.184.175.19
- 20.165.94.63
- 52.110.12.28
- 52.110.12.48
- 92.223.78.30
- 172.66.2.5
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report