MALICIOUS — virussign.com_638262004737b1d36798a5907f287ee0.vir
MALICIOUS — virussign.com_638262004737b1d36798a5907f287ee0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Emotet family. 8 of 52 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
f2912ad18a8a68b6f427c01b3287f1e884ea483441311331eef51b662b1aa9a2 - SHA-1:
2635f9c91f7146b94a9dcf559e95714b8b6df62f - MD5:
638262004737b1d36798a5907f287ee0 - imphash:
332f7ce65ead0adfb3d35147033aabe9 - ssdeep:
24576:dnsJ39LyjbJkQFMhmC+6GD9XAlJx8Eporn:dnsHyjtk2MYC5GDtMCEOrn - TLSH:
T153549F6D132B7703DA76DB245D016E5F0075F8DE50BA688C8693843EA3E68BBBC4121D - Submitted as: virussign.com_638262004737b1d36798a5907f287ee0.vir
- File type: pe · Size: 1112576 bytes
- Verdict: malicious (96/100) · Family: Emotet
Source: VirusSign · first seen 2026-08-04T00:00:00.000Z · SHA-256 verified
Detections (8 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Emotet-9850453-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Worm:Win32/AutoRun!atmn
- Emsisoft (Emergency Kit): Win32.Comet.A
- Trellix Stinger (McAfee): W32/Synaptics
- Kaspersky (KVRT): Backdoor.Win32.DarkKomet.hqxy
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Emotet-9850453-0 (rule
Win.Trojan.Emotet-9850453-0) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978, https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1, http://xred.site50.net/syn/SUpdate.ini - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
- https://docs.google.com/uc?id=0BxsMXGfPIZfSVlVsOGlEVGxuZVk&export=download
- https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1
- http://xred.site50.net/syn/SUpdate.ini
- https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download
- https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1
- http://xred.site50.net/syn/Synaptics.rar
- https://docs.google.com/uc?id=0BxsMXGfPIZfSTmlVYkxhSDg5TzQ&export=download
- https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=1
- http://xred.site50.net/syn/SSLLibrary.dll
- http://www.microsoft.com/exporting
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.sysinternals.com
Embedded domains
- afraid.org
- smtp.gmail.com
- xred.mooo.com
- freedns.afraid.org
- docs.google.com
- www.dropbox.com
- xred.site50.net
- gmail.com
- www.microsoft.com
- crl.microsoft.com
- technet.microsoft.com
- agreement.in
- change.to
- www.sysinternals.com
Embedded IP addresses
- 0.0.0.1
- 1.0.0.4
File paths
- X:\:`:d:h:l:p:t:x:
- K:\:
- R:\:i:
- L:\:l:t:x:
- C:\agent\_work\88\s\Win32\Release\Autologon.pdb
- T:\:d:l:t:
- D:\:
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report