MALICIOUS — virussign.com_1838e5e1b870f6551b2e6dd897470470.vir
MALICIOUS — virussign.com_1838e5e1b870f6551b2e6dd897470470.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the GenericFCA family. 1 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
eb081217c5e4ed4fd8998e40fe03fa598b59937c51341963df1ead8462fc926a - SHA-1:
823f7ed3ab3b5724a1e17ea0d52d77dd312c7a67 - MD5:
1838e5e1b870f6551b2e6dd897470470 - ssdeep:
3072:/6Kww6H/4S7WEADrXIVG1iQU+LM9RAdzTuFT/PUzbPuauYE6ie0:/gH/4S7WEADrXIVG8QUSe - TLSH:
T1263FC620B2ADCF9AC0800BF4A578B466E4457D561C51BCD641F9CB4ECECC961F4B2CAA - Submitted as: virussign.com_1838e5e1b870f6551b2e6dd897470470.vir
- File type: html · Size: 155507 bytes
- Verdict: malicious (96/100) · Family: GenericFCA
Source: VirusSign · first seen 2026-07-22T00:00:00.000Z · SHA-256 verified
Detections (1 of 51 engines)
- Emsisoft (Emergency Kit): Trojan.GenericFCA.9174
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 10 weighted signals:
- Memory forensics: 6 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 7880) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericFCA.9174 (rule
Trojan.GenericFCA.9174) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 37 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Contacted 37 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://ogp.me/ns#, https://rankmath.com/, https://shamrockfcp.com/ - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
276 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- dns.msftncsi.com
- config.edge.skype.com
- officeclient.microsoft.com
- v10.events.data.microsoft.com
- ctldl.windowsupdate.com
- ocsp.digicert.com
- oneocsp.microsoft.com
- odc.officeapps.live.com
- v20.events.data.microsoft.com
- aps.prod.windows.com
- watson.events.data.microsoft.com
- desktop-hsgcbep
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
- msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded URLs
- https://ogp.me/ns#
- https://rankmath.com/
- https://shamrockfcp.com/
- https://schema.org
- https://shamrockfcp.com/#organization
- https://shamrockfcp.com
- https://shamrockfcp.com/#logo
- https://shamrockfcp.com/wp-content/uploads/2025/10/Frame-1.svg
- https://shamrockfcp.com/#website
- https://shamrockfcp.com/wp-content/uploads/2025/10/2025-09-30-16.11.27.jpg
- https://shamrockfcp.com/#webpage
- https://shamrockfcp.com/author/shmopqrmedsn/
- https://secure.gravatar.com/avatar/e5779190455b93e6c4ddd69bc7c34e34dc9ea609f76d24adde4d88fe183feb99?s=96&d=mm&r=g
- https://shamrockfcp.com/#richSnippet
- https://shamrockfcp.com/feed/
- https://shamrockfcp.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fshamrockfcp.com%2F
- https://shamrockfcp.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fshamrockfcp.com%2F&format=xml
- https://shamrockfcp.com/wp-content/plugins/fluentform/assets/css/fluent-forms-elementor-widget.css?ver=6.1.15
- https://shamrockfcp.com/wp-content/uploads/elementor/css/custom-frontend.min.css?ver=1784522550
- https://shamrockfcp.com/wp-content/uploads/elementor/css/custom-widget-icon-list.min.css?ver=1784522550
- https://shamrockfcp.com/wp-content/plugins/elementor/assets/css/widget-image.min.css?ver=3.35.8
- https://shamrockfcp.com/wp-content/plugins/elementor/assets/css/widget-social-icons.min.css?ver=3.35.8
- https://shamrockfcp.com/wp-content/uploads/elementor/css/custom-apple-webkit.min.css?ver=1784522550
- https://shamrockfcp.com/wp-content/uploads/elementor/css/post-990.css?ver=1784522550
- https://shamrockfcp.com/wp-content/uploads/elementor/css/post-209.css?ver=1784522550
Embedded domains
- ogp.me
- rankmath.com
- shamrockfcp.com
- schema.org
- secure.gravatar.com
- api.w.org
- www.w3.org
- www.facebook.com
- www.instagram.com
- www.linkedin.com
- m.me
- ig.me
- s.w.org
- polygon.drpc.org
- polygon-bor-rpc.publicnode.com
- polygon.rpc.subquery.network
- polygon-public.nodies.app
- polygon-pokt.nodies.app
- webanalytics-cdn.icu
- polygon.lava.build
- oneclient.sfx.ms
- searchapp.bundleassets.example
- www.msftconnecttest.com
- www.bing.com
- dns.msftncsi.com
Embedded IP addresses
- 23.33.238.114
- 52.123.252.244
- 151.101.30.172
- 23.40.52.85
- 52.123.252.233
- 20.42.65.89
- 13.69.239.69
- 172.178.240.161
- 92.223.78.30
- 52.123.252.227
- 52.123.252.222
- 74.178.232.29
- 203.26.79.13
- 20.165.94.63
- 135.232.92.97
- 23.33.238.102
- 150.171.28.11
- 52.168.117.170
- 150.171.109.17
- 23.11.37.157
- 131.253.33.203
- 23.40.52.123
- 52.110.12.20
- 52.110.12.44
- 40.126.14.164
More GenericFCA samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report