MALICIOUS — virussign.com_9464ef68c5aec3b4f121251119458d40.vir
MALICIOUS — virussign.com_9464ef68c5aec3b4f121251119458d40.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Revell family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
efadebb7f107eb3da9cac29d37976b5edc5fd8d38f8bc804cf5279d031cf0e36 - SHA-1:
c73d84df7f562486738358249bd1d69c42327551 - MD5:
9464ef68c5aec3b4f121251119458d40 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
6144:e7aik2SN1K8sdIw69dct47h4QpUprOzLYoEPFfbCwuWTSIoXNHnr1GJOl4uvjgd5:eaj9Lw63ct47h4QKA/YzTeWcRGJlFZ - TLSH:
T1CB4B4A12110A272EE9B2C4E8C92D6E4C8153BDED61BA83CDC553C51ED3E69F328354E6 - Submitted as: virussign.com_9464ef68c5aec3b4f121251119458d40.vir
- File type: pe · Size: 475344 bytes
- Verdict: malicious (96/100) · Family: Revell
Source: VirusSign · first seen 2026-07-14T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Revell-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Revell-1 (rule
Win.Trojan.Revell-1) - engine signal, weight 0.90, confidence 0.95 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- https://go.microsoft.com/fwlink/?linkid=798306
- https://aka.ms/dotnet-core-applaunch
Embedded domains
- schemas.microsoft.com
- www.norton.com
- norton.com
- yahoo.com
- www.yahoo.com
- microsoft.com
- www.microsoft.com
- windowsupdate.com
- www.windowsupdate.com
- www.mcafee.com
- mcafee.com
- www.nai.com
- nai.com
- www.ca.com
- ca.com
- liveupdate.symantec.com
- www.sophos.com
- www.google.com
- rohitab.com
- www.rohitab.com
- securityresponse.symantec.com
- www.google.ca
- www.crackedmindstechnologies.com
- sf.net
- crl.microsoft.com
File paths
- D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\dotnet\dotnet.pdb
More Revell samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report