MALICIOUS — virussign.com_30d6fa7dff48d982ef601ee573f8ac60.vir
MALICIOUS — virussign.com_30d6fa7dff48d982ef601ee573f8ac60.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Barys family. 5 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ec51c5a9635a965114903d4f36c392ec3b2b6c1064e36f29c4b287bec3b8de38 - SHA-1:
2d7255315615b2f33b9955cdad6a0ec9dd1438e0 - MD5:
30d6fa7dff48d982ef601ee573f8ac60 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
96:bKHwf6GtSpZnNYZ7MhmHfOrD7+ewhv2Vc+Q+APT7/J/PnUzoxN:YwfztU678mHfOaeQkQ+QB/x - TLSH:
T19F1FD7CF72245630CAA7ED2244A0DAFDA8D26C56D8B5010C0E4C157B1E78A17DD7C2BE - Submitted as: virussign.com_30d6fa7dff48d982ef601ee573f8ac60.vir
- File type: pe · Size: 7168 bytes
- Verdict: malicious (97/100) · Family: Barys
Source: VirusSign · first seen 2026-07-23T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- Microsoft Defender: Trojan:MSIL/Barys.ARS!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Adware.Barys.61515
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Injector.gen
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 97/100 is the fusion of 9 weighted signals:
- Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 8096) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:MSIL/Barys.ARS!MTB (rule
Trojan:MSIL/Barys.ARS!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Adware.Barys.61515 (rule
Gen:Variant.Adware.Barys.61515) - engine signal, weight 0.55, confidence 0.85 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (windows)
49 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- searchapp.bundleassets.example
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- settings-prod-sea-2-tagged.southeastasia.cloudapp.azure.com
- s-0005.dual-s-msedge.net
- outlook.office.com
- outlook.office365.com
- atm.outlook.mira.tm.svc.cloud.microsoft
- outlook.cloud.microsoft
- bg.microsoft.map.fastly.net
- www.msftconnecttest.com
- settings-prod-eus-1-tagged.eastus.cloudapp.azure.com
- settings-prod-cin-2-tagged.centralindia.cloudapp.azure.com
- ln-0007.ln-msedge.net
- svc.ms-acdc-teams.office.com
- onedsblobvmssprdwus02.westus.cloudapp.azure.com
- onedsblobvmssprdcus02.centralus.cloudapp.azure.com
- mr-b02.tm-azurefd.net
- mr-b01.tm-azurefd.net
- onedscolprdcus61.centralus.cloudapp.azure.com
Embedded domains
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- s-0005.dual-s-msedge.net
- atm.outlook.mira.tm.svc.cloud.microsoft
- outlook.cloud.microsoft
- glb.sls.prod.dcat.dsp.trafficmanager.net
- ln-0007.ln-msedge.net
- glb.api.prod.dcat.dsp.trafficmanager.net
- aefd.nelreports.net
- mr-b02.tm-azurefd.net
- mr-b01.tm-azurefd.net
- searchapp.bundleassets.example
- settings-prod-sea-2-tagged.southeastasia.cloudapp.azure.com
- outlook.office.com
- outlook.office365.com
- bg.microsoft.map.fastly.net
- www.msftconnecttest.com
- settings-prod-eus-1-tagged.eastus.cloudapp.azure.com
- settings-prod-cin-2-tagged.centralindia.cloudapp.azure.com
- svc.ms-acdc-teams.office.com
- onedsblobvmssprdwus02.westus.cloudapp.azure.com
- onedsblobvmssprdcus02.centralus.cloudapp.azure.com
- onedscolprdcus61.centralus.cloudapp.azure.com
- onedscolprdwus73.westus.cloudapp.azure.com
- onedscolprdwus50.westus.cloudapp.azure.com
Embedded IP addresses
- 23.221.133.185
- 52.123.252.197
- 23.33.238.114
File paths
- C:\Windows\System32\CheckNetIsolation.exe
- C:\Windows\System32\CloudExperienceHostBroker.exe
More Barys samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report