MALICIOUS — virussign.com_f592105e2eb003aba6be1a964a700b10.vir
MALICIOUS — virussign.com_f592105e2eb003aba6be1a964a700b10.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Fesber family. 8 of 51 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ef8666042aec506aabf82bce1385b7c14263eeb2209f68a820b4069b8375408e - SHA-1:
7b1a0a2127699f965a6a274709a6bd045efbd91e - MD5:
f592105e2eb003aba6be1a964a700b10 - imphash:
acd618b3278a04b17611fa6889b3bdf0 - ssdeep:
12288:jJHPvTyUjD5xszt9euP+b0SoRUJDJhL95+B7a2SoEWKtsm45:13TjsznhmbLoY0BW1oE1tT45 - TLSH:
T1A7554BC87136B641DEB5E6338853CD4C8242E4F565BD188D2797C12FA1AB4F3AA73190 - Submitted as: virussign.com_f592105e2eb003aba6be1a964a700b10.vir
- File type: pe · Size: 1330704 bytes
- Verdict: malicious (97/100) · Family: Fesber
Source: VirusSign · first seen 2026-07-31T00:00:00.000Z · SHA-256 verified
Detections (8 of 51 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Worm.Fesber-9939497-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Microsoft Defender: TrojanDropper:Win32/Delf.BB
- Emsisoft (Emergency Kit): Trojan.Dropper.Delf.BB
- Kaspersky (KVRT): Backdoor.Win32.Delf.lz
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Worm.Fesber-9939497-0 (rule
Win.Worm.Fesber-9939497-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.tsx.org, http://nsis.sf.net/NSIS_Error, https://qsurvey.mozilla.com/s3/FF-Desktop-Post-Uninstall?channel=release&version=108.0.2&osversion= - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://upx.tsx.org
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
- http://www.digicert.com/CPS0
- http://nsis.sf.net/NSIS_Error
- https://support.mozilla.org
- https://www.mozilla.org/firefox/108.0.2/releasenotes
- https://www.mozilla.org
- https://support.mozilla.org/kb/refresh-firefox-reset-add-ons-and-settings
- https://incoming.telemetry.mozilla.org/submit/telemetry/
- https://qsurvey.mozilla.com/s3/FF-Desktop-Post-Uninstall?channel=release&version=108.0.2&osversion=
Embedded domains
- bar.com
- upx.tsx.org
- schemas.microsoft.com
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- nsis.sf.net
- mozilla.org
- support.mozilla.org
- www.mozilla.org
- incoming.telemetry.mozilla.org
- qsurvey.mozilla.com
File paths
- C:\Windows\system32\fsb.tmp
- C:\Program
- C:\Users\jim\Desktop\metro
- T:\:d:l:t:
- C:\mozilla-source\mozilla-central\other-licenses\nsis\Contrib\HttpPostFile\Release\HttpPostFile.pdb
More Fesber samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report