MALICIOUS — virussign.com_c70e97f1c8ec9f5f10fbe2aa6c4d6dc0.vir
MALICIOUS — virussign.com_c70e97f1c8ec9f5f10fbe2aa6c4d6dc0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Container family. 12 of 52 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
eeec3c27aa51940498e5d78aaf924962bbe863e1eaf2ed480a7ecb6124eb5d89 - SHA-1:
c007616f1fa5abcee9a8b3eab1ea7cc24f84b56b - MD5:
c70e97f1c8ec9f5f10fbe2aa6c4d6dc0 - imphash:
3ea2acf4ffdf8aded4b1ed114289a780 - ssdeep:
49152:kvRNgnxpV9ERtoYsj3cUgnDIAVx6IG1jjcwgiLwKAdL+clBpDr8vsiIPhsZ4O8bL:532oirV0tsiLwHft8vAO6 - TLSH:
T12865C4958FD33045D0F6BD049461C8AC421FF55EA77FC68ED702D43892ABABB8EA4052 - Submitted as: virussign.com_c70e97f1c8ec9f5f10fbe2aa6c4d6dc0.vir
- File type: pe · Size: 6050821 bytes
- Verdict: malicious (99/100) · Family: Container
Source: VirusSign · first seen 2026-08-10T00:00:00.000Z · SHA-256 verified
Detections (12 of 52 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Ransomware.Ransomware-10058995-0
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Ransom:Win64/Azov.psyA!MTB
- Emsisoft (Emergency Kit): Trojan.Ransom.Azov.1
- Trellix Stinger (McAfee): Trojan-JARZ!C70E97F1C8EC
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 99/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Ransomware.Ransomware-10058995-0 (rule
Win.Ransomware.Ransomware-10058995-0) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://rna-pdf-resource.acrobat.com/, https://crbug.com/820996, https://msmip.reader.com/authorize - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oobe.adobe.com/
- https://rna-pdf-resource.acrobat.com/
- http://www.w3.org/TR/REC-html40
- https://oobe.adobe.com/federation_start
- https://oobe.adobe.com
- https://oobe.adobe.com/delegation_start
- https://oobe.adobe.com/delegation_end
- https://oobe.adobe.com/delegation_error
- https://oobe.adobe.com/federation_end
- https://oobe.adobe.com/federation_error
- https://crbug.com/820996
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.digicert.com/CPS0
- https://clients2.google.com/service/update2/crx
- https://helpx.adobe.com/acrobat/kb/acrobat-failed-load-core-dll.html
- https://helpx.adobe.com/acrobat/kb/failed-to-connect-to-dde-server.html
- https://acrobatoauth.adobe.com
- https://acrobatoauth.adobe.com/
- https://msmip.reader.com/authorize
- https://mail.google.com/
Embedded domains
- oobe.adobe.com
- rna-pdf-resource.acrobat.com
- www.w3.org
- dc-api.adobe.io
- dc-api-stage.adobe.io
- crbug.com
- ns.adobe.com
- schemas.microsoft.com
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
- clients2.google.com
- helpx.adobe.com
- help.adobe.com
- adobehelp.corp.adobe.com
- adobe.com
- dc.acrobat.com
- documentcloud.adobe.com
- dc.stage.acrobat.com
- acrobat.adobe.com
- stage.acrobat.adobe.com
- ims-na1.adobelogin.com
- ims-na1-stg1.adobelogin.com
- adobeid-na1.services.adobe.com
Registry keys
- HKEY_CURRENT_USER\%s\*
- HKEY_CURRENT_USER\Software\Adobe\Acrobat
- HKEY_CURRENT_USER\Software\Adobe\Adobe
- HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage
- HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes\Installer*
- HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes*
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech*
- HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties*
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
- HKEY_CURRENT_USER\SOFTWARE\Adobe\CommonFiles*
File paths
- D:\T\M\Acrobat\Viewer\Win\EXEs\ViewerExe\ChromeSandboxLaunch.cpp
- D:\T\M\BuildResults\bin\Release_x64\AcrobatExe.pdb
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report