MALICIOUS — virussign.com_d7bbea88f63b93d102f4c5b63da41bc0.vir
MALICIOUS — virussign.com_d7bbea88f63b93d102f4c5b63da41bc0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Reactor family. 6 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bc7613d0b1a3bfebe202aacf740f7488f3f992aeae163c50c17adf54587c2e24 - SHA-1:
e7957bb32be7c66d1b888f6cf5c597213c101a08 - MD5:
d7bbea88f63b93d102f4c5b63da41bc0 - imphash:
88016fcdef7f227c62171d0afad9aae4 - ssdeep:
49152:yAX7NMIUt1ITeLKFhVCsmMqrc+BG2L8dGV:yAX7aIqKTeWFDvqrc+3L - TLSH:
T1F85AAD8A775A362BC769D32010A0BB7F05F7AC47037F99C803A68A1FDAF48271571919 - Submitted as: virussign.com_d7bbea88f63b93d102f4c5b63da41bc0.vir
- File type: pe · Size: 2091365 bytes
- Verdict: malicious (95/100) · Family: Reactor
Source: VirusSign · first seen 2026-07-16T00:00:00.000Z · SHA-256 verified
Detections (6 of 53 engines)
- capa (capabilities): beacon to command-and-control
- MalwareAnalyser heuristics (entropy/packer): .NET Reactor 2.X-3.X
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:.NET Reactor 2.X-3.X
- Emsisoft (Emergency Kit): QD:Trojan.Astraea.8B0A926E36
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Win32.OffLoader.gen
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 11 weighted signals:
- Memory forensics: 6 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7948) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Emsisoft (Emergency Kit) flagged QD:Trojan.Astraea.8B0A926E36 (rule
QD:Trojan.Astraea.8B0A926E36) - engine signal, weight 0.55, confidence 0.85 - beacon to command-and-control (rule
beacon to command-and-control) - capa signal, weight 0.45, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:.NET Reactor 2.X-3.X (rule
DIE:.NET Reactor 2.X-3.X) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline, 7.0.0.3 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: .NET Reactor 2.X-3.X - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
6269 behavior events · 1 ATT&CK techniques · 3 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- desktop-hsgcbep
- config.edge.skype.com
- dns.msftncsi.com
- settings-win.data.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
- 192.168.122.107
- 192.168.122.1
Dropped files
- /opt/CAPEv2/storage/analyses/3510/files/0f33fedc890792fb4d28109c54b4170e079104e1ae428af113886cb22af459f7 -
0f33fedc890792fb4d28109c54b4170e079104e1ae428af113886cb22af459f7 - fd1c75626a4bdfba996cae5c1e2211395e12b8ffd30a2570cfcf1a9cd82a8a83 -
fd1c75626a4bdfba996cae5c1e2211395e12b8ffd30a2570cfcf1a9cd82a8a83 - edfd9a488a1d18caf653d02c0f9effe914a2e82eb18c7063b61cc4d382d262f8 -
edfd9a488a1d18caf653d02c0f9effe914a2e82eb18c7063b61cc4d382d262f8
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
Embedded domains
- schemas.microsoft.com
- jrsoftware.org
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- config.edge.skype.com
- dns.msftncsi.com
- settings-win.data.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- ecs.office.com
- g.live.com
- fs.microsoft.com
- self.events.data.microsoft.com
- www.msftncsi.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- geover.prod.do.dsp.mp.microsoft.com
- watson.events.data.microsoft.com
Embedded IP addresses
- 7.0.0.3
File paths
- T:\:d:l:p:t:x:
- X:\:`:d:h:l:
- X:\:`:d:h:l:p:t:x:
- X:\:j:
- M:\:d:t:
- E:\:j:}:
- X:\:`:d:h:l:p:t:
- T:\:d:l:t:
- w:\[
- C:\Coding\Is\issrc-build\Components\ChaCha20.pas
- x:\dirname
More Reactor samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report