SUSPICIOUS — virussign.com_39af3deffec5c789be517168fc4d21a0.vir
SUSPICIOUS — virussign.com_39af3deffec5c789be517168fc4d21a0.vir is a archive sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
b81146bc8b926c037d392fa2fc03af579ba50744ccc6e572eed8d649f1de65ec - SHA-1:
ff61ade73f95122aa1b61cc0751434af15e14aa4 - MD5:
39af3deffec5c789be517168fc4d21a0 - ssdeep:
12288:rRi1IoiBr42qB26xKE2PBXMtnLE+tlt8+gYjsQr04v:rRr5r42/izWXCLXltEuT - TLSH:
T1834E336C084F1B42833EFCD88F8624DA4DD89E56CB885C805B15DB9C9B1BF887786179 - Submitted as: virussign.com_39af3deffec5c789be517168fc4d21a0.vir
- File type: archive · Size: 655012 bytes
- Verdict: suspicious (65/100)
Source: VirusSign · first seen 2026-08-22T00:00:00.000Z · SHA-256 verified
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Microsoft Defender flagged Trojan:Script/Sabsik.EN.A!ml (rule
Trojan:Script/Sabsik.EN.A!ml) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (1 executable)
This archive carries 1 extracted member, each analyzed as its own sample:
- Order TP21393.vbs -
6d5c364a1d67d734056aa34a5f7d0a56580b0c074cddecd2d951b39e70b6a142
File paths
- y:\.b
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report