MALICIOUS — virussign.com_af34ad2552124ff0d7aad4b6488a76b0.vir
MALICIOUS — virussign.com_af34ad2552124ff0d7aad4b6488a76b0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the ASPack family. 8 of 55 detection engines flagged it.
Identification
- SHA-256:
aa089dcbee949308c4a7134e8fdd30e6fed6672870448827a59585c56dc5ed34 - SHA-1:
61246635b8f294cfb227b072b120a56d2c13da8a - MD5:
af34ad2552124ff0d7aad4b6488a76b0 - imphash:
e0c82a8bb400dee56f5455bb8939d80c - ssdeep:
768:6pQNwC3BEddsEqOt/hydxyFtwLR+7DSdAwV3BEW+Os:6eTce/U/hah36qdps - TLSH:
T1CB3D5BC90BB12499EDF2D555ECA99D9F002B9020D87ED99C779BC2191CF32B784304AE - Submitted as: virussign.com_af34ad2552124ff0d7aad4b6488a76b0.vir
- File type: pe · Size: 135203 bytes
- Verdict: malicious (93/100) · Family: ASPack
Source: VirusSign · first seen 2026-08-18T00:00:00.000Z · SHA-256 verified
Detections (8 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Visual Basic
- ClamAV (daily): Win.Malware.Genpack-6989317-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Microsoft Visual Basic
- Microsoft Defender: Trojan:Win32/Vilsel.AMAB!MTB
- Emsisoft (Emergency Kit): Worm.VB.UB
- Trellix Stinger (McAfee): Trojan-FHNB!AF34AD255212
- Kaspersky (KVRT): Trojan.Win32.Vilsel.bpxe
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-6989317-0 (rule
Win.Malware.Genpack-6989317-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Microsoft Visual Basic (rule
DIE:Microsoft Visual Basic) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Visual Basic - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Program
- C:\WINDOWS\system32\msvbvm60.dll\3
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report