SUSPICIOUS — virussign.com_6e9394b36faced371fb9c109e91a26e0.vir
SUSPICIOUS — virussign.com_6e9394b36faced371fb9c109e91a26e0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (43/100), attributed to the STRATO family. 2 of 52 detection engines flagged it.
Identification
- SHA-256:
e4ee9745bc96cd5a9db258e1521386d81e2c92f87cf02b7e03ddd182d5d89a6a - SHA-1:
b261e26fb8ebf1cbdeb5dce561db6037945b409b - MD5:
6e9394b36faced371fb9c109e91a26e0 - imphash:
1d125246f7af0c4270171f7a754cff0c - ssdeep:
12288:V0lHQuJhYo2SoqMcUmHAGel4K32s2lUWCW0eENn0DjfIyyyos3yj:GlHQXo2iMcTHAGemKGs2lhCW05N0YYy - TLSH:
T1A6527D26822BB217F1BEE494ACF55EDC9431B0FC207A994A9603D88F60D52379DF2174 - Submitted as: virussign.com_6e9394b36faced371fb9c109e91a26e0.vir
- File type: pe · Size: 949432 bytes
- Verdict: suspicious (43/100) · Family: STRATO
Source: VirusSign · first seen 2026-08-06T00:00:00.000Z · SHA-256 verified
Detections (2 of 52 engines)
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The suspicious score of 43/100 is the fusion of 2 weighted signals:
- YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://java.com
- https://java.com/help
- https://docs.oracle.com/javase/
- http://www.digicert.com/CPS0
- https://java.com/ja/download/help/index.xml
- https://java.com/zh_CN/download/help/index.xml
- https://java.com/ko/download/help/index.xml
- https://java.com/zh_TW/download/help/index.xml
- https://java.com/de/download/help/index.xml
- https://java.com/es/download/help/index.xml
- https://java.com/fr/download/help/index.xml
- https://java.com/it/download/help/index.xml
- https://java.com/sv/download/help/index.xml
- https://java.com/pt_BR/download/help/index.xml
- https://java.com/en/download/help/index.xml
Embedded domains
- docs.oracle.com
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- java.com
File paths
- c:\jenkins\workspace\8-2-build-windows-x64-cygwin-sans-NAS\jdk8u481\2490\install\src\windows\common\Dll.h
- c:\jenkins\workspace\8-2-build-windows-x64-cygwin-sans-NAS\jdk8u481\2490\install\src\windows\common\MsiUtils.h
- c:\jenkins\workspace\8-2-build-windows-x64-cygwin-sans-NAS\jdk8u481\2490\install\src\windows\common\InstalledJavaTracker.h
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report