MALICIOUS — virussign.com_593458b033468cce0a4fdfae56b14af0.vir
MALICIOUS — virussign.com_593458b033468cce0a4fdfae56b14af0.vir is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 2 of 51 detection engines flagged it.
Identification
- SHA-256:
c2cf4793a64d555769a8322b6e5c85cae9b7227d9e28b77c634b8231b24eb3de - SHA-1:
570f61b5643b2d5e2cc0c046a8944a0471d436dd - MD5:
593458b033468cce0a4fdfae56b14af0 - ssdeep:
196608:SwgIenlFkpeseekN16mMKvHcVKR3Gj4+vjZTIfmzEMa:S9IenlaN7KR28Gj6/ - TLSH:
T1C46633D6E69D867ADBDCF83044DB309C9DDF9894602CBB9524D091BE9A204EF21C3163 - Submitted as: virussign.com_593458b033468cce0a4fdfae56b14af0.vir
- File type: zip · Size: 6730398 bytes
- Verdict: malicious (89/100)
Source: VirusSign · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (2 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.JS_Zip_11.UNOFFICIAL
Why this verdict
The malicious score of 89/100 is the fusion of 3 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.JS_Zip_11.UNOFFICIAL (rule
Sanesecurity.Foxhole.JS_Zip_11.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: BUG��˾ 2.15/extensions/dynamicMapEditor.js, BUG��˾ 2.15/extensions/localSave.js, BUG��˾ 2.15/libs/actions.js, BUG��˾ 2.15/libs/control.js, BUG��˾ 2.15/libs/core.js - static signal, weight 0.25, confidence 0.50
Archive contents (15 executables)
This zip carries 15 extracted members, each analyzed as its own sample (listing truncated):
- docsify.min.js -
769c6eac503ed151495606a6d060b1b4cd217200b0b046eec1ed6e0fe2d841f0 - docsify.min.js -
769c6eac503ed151495606a6d060b1b4cd217200b0b046eec1ed6e0fe2d841f0 - search.min.js -
3f7b20425f81cea9bc60499495cb2d4a89315303509cf04ec8e1e3218b9cf098 - acorn.min.js -
f8cd99186521a90314a164070c42f83ac499daeba09db1108e7f326358a8404a - beautify.min.js -
9dd1391bf0fb4cdabfd87f9043a8eaec655a09e869cd3f8c6df91672abfb42bc - codeMirror.bundle.min.js -
7b5277fff495c8fc86f70c16bec5efaaf10fa40a2a7dd2698cb1736bf53c5b4f - codeMirror.plugin.js -
534519d5ab2b0875fba6b331b82a687226ed16515ec9b9a3ab27d870d94d835f - codeMirror.plugin.min.js -
c87f083330dda171b3a1c1b912c218591aa9bb6b0b82b5f3c2ded5fea912f4b8 - defs.js -
948dcefd94f12724793c31839f3bf151507f699d8adce851aac452fd75bc909d - jshint.min.js -
66d1da5898b2155ec5db102da723641197b3996f5d3e5f006e358151dcc27c8b - tern.min.js -
80e7157d5d685c0f2e46696b04996921a5d62501bd75ad4c7a23eb7e82dfbe76 - MotaActionParser.js -
58cf52f16dcb492df84650a32a107418f1bb26d4f19fbb45ae259a00f19d38c3 - Converter.bundle.min.js -
502e00f5867b2308843d890f7f8255f9445867352dd7db5cb7b8be242b2aee51 - blockly_compressed.js -
b3e34ea1b0d8bb10055de06e0e3bf866b4b41f09198f395b1d8380bab39a7b1e - blocks_compressed.js -
5ca694af22099a3dc5a20d32e84f5a1be88ebaf1ff5e8eb4cd2bec28159a774a
Dynamic analysis
This zip is a container, so it was not detonated itself. Its extracted members were re-submitted and analyzed as their own samples, and the runtime behaviour lives on those reports.
Embedded domains
- te.jp
- btf.pw
- mt.br
- 1s.ua
- paint.net
File paths
- E:\JB
- P:\rM
- L:\:B
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report