MALICIOUS — virussign.com_0ca2aa34fb50ba71375a1c198874eef0.vir
MALICIOUS — virussign.com_0ca2aa34fb50ba71375a1c198874eef0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Urelas family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
be7ca52ded481cfb3e8c214c656987b6665a86865cbef27f3e896f3fda9852d5 - SHA-1:
8127a9a54b6a54159b899fe50450d838c315d1e9 - MD5:
0ca2aa34fb50ba71375a1c198874eef0 - imphash:
372467513fc37686aa91f0703e76e7b1 - ssdeep:
12288:AIfBoDWoyFblU6hAJQnOzer5+nZoWL1rA1YaL8i0DM2:AIfjoga6u1AVD2 - TLSH:
T10256279D71E8479FCDBFCE4E9848079D22B904F93374ED68424095D478DAA33AFA011A - Submitted as: virussign.com_0ca2aa34fb50ba71375a1c198874eef0.vir
- File type: pe · Size: 1459139 bytes
- Verdict: malicious (93/100) · Family: Urelas
Source: VirusSign · first seen 2026-08-13T00:00:00.000Z · SHA-256 verified
Detections (7 of 52 engines)
- ClamAV (daily): Win.Trojan.Urelas-9635181-0
- YARA: delivr.to detections: DLV_HTML_Smuggling
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Urelas.WE!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Mint.SP.Urelas.1
- Trellix Stinger (McAfee): Corrupt-FY!0CA2AA34FB50
- Kaspersky (KVRT): Backdoor.Win32.Plite.bhty
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Urelas-9635181-0 (rule
Win.Trojan.Urelas-9635181-0) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_HTML_Smuggling (rule
DLV_HTML_Smuggling) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://example-cmdline.test, http://example.test/path, http://example2.test/?query - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://example-cmdline.test
- http://example.test/path
- http://example2.test/?query
- http://example.test.file
- http://example.test
- http://example2.test
- https://www.example.com/
- https://clients1.google.com/tbproxy
- https://content-autofill.googleapis.com/
- http://www.google.com/
- https://example.com/
- https://chromium.org
- https://chromium.org/
- https://www.google.com
- http://foo.com/
- http://foo.com/#:~:text=hello%20world
- http://foo.com/#:~:text=hello
- http://facebook.com/my-profile
- http://foo.com/#bar
- http://foo.com/#bar:~:text=hello%20world
- http://foo.com/#bar:~:text=baz
- http://foo.com/#bar:~:text=baz&text=qux
- http://foo.com/#bar:~:baz=keep&text=remove&baz=keep2
- http://foo.com/#bar:~:baz=keep&baz=keep2&text=hello%20world
- http://www.site-with-http.com
Embedded domains
- stack.cc
- field.cc
- logging.cc
- blink.net
- crbug.com
- thread.cc
- zip.cc
- www.example.com
- initech.com
- gmail.com
- a.com
- b.com
- clients1.google.com
- content-autofill.googleapis.com
- bounds.top
- wonderland.com
- www.google.com
- foo.com
- example.com
- chromium.org
- facebook.com
- start.com
- bar.com
- window.name
- rect.top
Embedded IP addresses
- 1.234.83.146
- 133.242.129.155
- 218.54.31.226
- 218.54.31.165
File paths
- C:\TEMP
More Urelas samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report