MALICIOUS — virussign.com_075a77aae1a88756ee1dd9254a507f30.vir
MALICIOUS — virussign.com_075a77aae1a88756ee1dd9254a507f30.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Pioneer family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
aaff1a8d2892a72860336c5a325de000be99696b0a7c31ffbe66e1d479376f9f - SHA-1:
431c5eda8c92a6f00bda23a4a4a07d6883366fa8 - MD5:
075a77aae1a88756ee1dd9254a507f30 - imphash:
a68cdbcdef134517d8c0ef74e69b1e44 - ssdeep:
12288:zAPX+pd167QhE0s7+jM+M6ugRfMMkIM7ovX+pd167QhE0u7+YrBjvrEH7JA:YE6Ehg7mM+M6RkMkIM7gE6Eh67ZrEH7y - TLSH:
T1764FCFE80B23220FC9B15B07AD0A4A4E65678872D56E5E4CD30BD1AC9DE757F843C0B9 - Submitted as: virussign.com_075a77aae1a88756ee1dd9254a507f30.vir
- File type: pe · Size: 751319 bytes
- Verdict: malicious (89/100) · Family: Pioneer
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Pioneer-9111434-0
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Virus.Pioneer-9111434-0 (rule
Win.Virus.Pioneer-9111434-0) - engine signal, weight 0.90, confidence 0.95 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- go.microsoft.com
File paths
- V:\:j:
More Pioneer samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report