SUSPICIOUS — virussign.com_b06c1731e56438217eeda7f7198ac9e0.vir
SUSPICIOUS — virussign.com_b06c1731e56438217eeda7f7198ac9e0.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (42/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
f2fe42831d42b8c00221a85fe42737b9efb3abf68db30b7e4f2b361c8b02d035 - SHA-1:
b18572ee7f78f4aa539d38c1d48db2ec85acaaf5 - MD5:
b06c1731e56438217eeda7f7198ac9e0 - ssdeep:
1536:CkAT5ugg15aTwlAT5ugg15aTwlAT5ugg15aTw9:Cku5ugg15aTwlu5ugg15aTwlu5ugg15l - TLSH:
T1D136A4C97D4B0687D40C2C11B89CF8A47DDEE66BD92089D6C459CB8CCCE4948BE8D978 - Submitted as: virussign.com_b06c1731e56438217eeda7f7198ac9e0.vir
- File type: html · Size: 66335 bytes
- Verdict: suspicious (42/100)
Source: VirusSign · first seen 2026-08-16T00:00:00.000Z · SHA-256 verified
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 42/100 is the fusion of 2 weighted signals:
- Obfuscated unknown script: defense-evasion (rule
script-deobfuscation) - static signal, weight 0.35, confidence 0.75 - Embedded network infrastructure: https://random-affiliate.atimaze.com/, https://images.purevpnaffiliates.com, https://s-img.adskeeper.com/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://random-affiliate.atimaze.com/
- https://images.purevpnaffiliates.com
- https://s-img.adskeeper.com/
- https://paid.outbrain.com/network/redir
- https://rcm-fe.amazon-adsystem.com/
- http://www.w3.org/2000/svg
Embedded domains
- random-affiliate.atimaze.com
- images.purevpnaffiliates.com
- s-img.adskeeper.com
- paid.outbrain.com
- wallpaperaccess.com
- body.no
- rcm-fe.amazon-adsystem.com
- div.app
- div.cc
- div.dev
- div.edu
- div.eu
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report