MALICIOUS — virussign.com_84d8e68912e768c473cd4b63ac30d050.vir
MALICIOUS — virussign.com_84d8e68912e768c473cd4b63ac30d050.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Agentb family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b78b3322bb205240ea37a9141ad44824c8d374a48e740c122be334a191086d31 - SHA-1:
af10bf273f1cfafe444f5b3bf0ecb7ab04e1ff47 - MD5:
84d8e68912e768c473cd4b63ac30d050 - imphash:
dae367ed1658e14b7217d0e9721288c9 - ssdeep:
1536:YGYU/W2/HG6QMauSV3ixJHABLrmhH7i9eNOOg00GqMIK7aGZh3SOE:YfU/WF6QMauSuiWNi9eNOl0007NZIOE - TLSH:
T1583E9DAC071A7745DAFADB215CB46E1E70A3A0FE507F178C5583C16E23E3833A4A511A - Submitted as: virussign.com_84d8e68912e768c473cd4b63ac30d050.vir
- File type: pe · Size: 138184 bytes
- Verdict: malicious (92/100) · Family: Agentb
Source: VirusSign · first seen 2026-07-28T00:00:00.000Z · SHA-256 verified
Detections (4 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Agentb-9639796-0
- Kaspersky (KVRT): Trojan.Win32.Agentb.bviq
- Microsoft Defender: Trojan:Win32/Gamarue!pz
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Agentb-9639796-0 (rule
Win.Malware.Agentb-9639796-0) - engine signal, weight 0.90, confidence 0.95 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: 158.69.115.115 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
Embedded IP addresses
- 158.69.115.115
File paths
- C:\windows\system32\cmd.exe
- C:\ProgramData\Update
- C:\ProgramData\Update\wuauclt.exe
- C:\Program
- c:\windows\system32\cmd.exe
- E:\Data\My
More Agentb samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report