MALICIOUS — virussign.com_65aff9415289754227a0b0b986097b50.vir
MALICIOUS — virussign.com_65aff9415289754227a0b0b986097b50.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Floxif family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
bb62e570284d0316674416957e0b4ee22792f4892bbac5b8e991fce3f65c943f - SHA-1:
c328e52c931930c4af9ff30f2d5e35dfefa4f754 - MD5:
65aff9415289754227a0b0b986097b50 - imphash:
a68cdbcdef134517d8c0ef74e69b1e44 - ssdeep:
12288:hiPX+pd167QhE0s7+jM+M6ugRfMMkIM7ovX+pd167QhE0u7+YrBjvrEH7sX:oE6Ehg7mM+M6RkMkIM7gE6Eh67ZrEH7+ - TLSH:
T1D64FCFE80B23220FC9B15B07AD0A4A4E65678872D56E5E4CD30BD1AC9DE757F843C0B9 - Submitted as: virussign.com_65aff9415289754227a0b0b986097b50.vir
- File type: pe · Size: 751319 bytes
- Verdict: malicious (97/100) · Family: Floxif
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Pioneer-9111434-0
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Virus.Pioneer-9111434-0 (rule
Win.Virus.Pioneer-9111434-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Floxif.H (rule
Virus:Win32/Floxif.H) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Floxif.A (rule
Win32.Floxif.A) - engine signal, weight 0.55, confidence 0.85 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- go.microsoft.com
File paths
- V:\:j:
More Floxif samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report