MALICIOUS — virussign.com_8a72fdd7a68c406b72ea4c816f54b100.vir
MALICIOUS — virussign.com_8a72fdd7a68c406b72ea4c816f54b100.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the ShellObject family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
c5ae5e5fdfa60763a00b5d2b6bfdccc359a348e5659689f211d6c52835e7ae22 - SHA-1:
ade63832f534f2b2aa67c5a02968cf02ec54d32c - MD5:
8a72fdd7a68c406b72ea4c816f54b100 - imphash:
e0694fdfb223f0597230804c2f630838 - ssdeep:
1536:tyxUQcYeSF5slw6ODF6jpB+CPanFuDRXI3QRRRRRRRRRRRRRR+vgH+RQ8ZlRMRz5:tesOTDFh25RRRRRRRRRRRRRR+oee8Zlw - TLSH:
T110396D306226AC16ECEF4CDA98816A2DAD53C4FE6438AC3171CCD6C5B877537231A257 - Submitted as: virussign.com_8a72fdd7a68c406b72ea4c816f54b100.vir
- File type: pe · Size: 92672 bytes
- Verdict: malicious (98/100) · Family: ShellObject
Source: VirusSign · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Crypted-30
- Microsoft Defender: Backdoor:Win32/Padodor.SK!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.ShellObject.f0W@a8rAQKh
- Trellix Stinger (McAfee): Trojan-FVOK!8A72FDD7A68C
- Kaspersky (KVRT): Backdoor.Win32.Padodor.gen
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-30 (rule
Win.Trojan.Crypted-30) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Padodor.SK!MTB (rule
Backdoor:Win32/Padodor.SK!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Trojan.ShellObject.f0W@a8rAQKh (rule
Gen:Trojan.ShellObject.f0W@a8rAQKh) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Trojan-FVOK!8A72FDD7A68C (rule
Trojan-FVOK!8A72FDD7A68C) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://oracle.com/contracts
Embedded domains
- r.office.microsoft.com
- oracle.com
- microsoft.com
- www.oracle.com
- go.microsoft.com
More ShellObject samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report