MALICIOUS — virussign.com_56f3fe3a26d0c78ccb1109aaa8b7d140.vir
MALICIOUS — virussign.com_56f3fe3a26d0c78ccb1109aaa8b7d140.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Swisyn family. 2 of 52 detection engines flagged it.
Identification
- SHA-256:
e59d67e4c6db1fb4a19186f7856ade9e7d9a0ae91810766dbf3182fefefc2840 - SHA-1:
9435231f04c8f9520ca546fd82d821068716853a - MD5:
56f3fe3a26d0c78ccb1109aaa8b7d140 - imphash:
09d15f852612b78ab3da4cf59387d361 - ssdeep:
3072:hFdc0N+U5b6Wv6ipiCcVCW2F3zTX63s6+LJC1kkusTIopzqtXXDwa0vej:hn1T6Wv3iTCf3/63H+syQbzjDy - TLSH:
T1D4569ED9422EF216F3F1E9740C4F4F8D40B3A4D852FE1FD48683C42E26DA85798562A6 - Submitted as: virussign.com_56f3fe3a26d0c78ccb1109aaa8b7d140.vir
- File type: pe · Size: 1422404 bytes
- Verdict: malicious (91/100) · Family: Swisyn
Source: VirusSign · first seen 2026-08-05T00:00:00.000Z · SHA-256 verified
Detections (2 of 52 engines)
- ClamAV (daily): Win.Malware.Swisyn-6888356-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Swisyn-6888356-0 (rule
Win.Malware.Swisyn-6888356-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.sysinternals.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.sysinternals.com
Embedded domains
- www.sysinternals.com
- sysinternals.com
File paths
- X:\:h:t:
More Swisyn samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report