MALICIOUS — virussign.com_d7bf52d81663c8afd439934fb88f5110.vir
MALICIOUS — virussign.com_d7bf52d81663c8afd439934fb88f5110.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Softonic family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
fb9acd687165a0dde8185697a3f9c1939b60e8040a1a2d8a1da15956934e0f6a - SHA-1:
3bf27839751880081a857b528ab288ded85affe3 - MD5:
d7bf52d81663c8afd439934fb88f5110 - imphash:
88016fcdef7f227c62171d0afad9aae4 - ssdeep:
24576:/XNrSLScusMmOvjjhzvLV5jeKBgkcXjPeynRkIegf+Sve+9Cx+gBbfWzOUxSXc6o:0uI2h7jHHcTeynRkfg7ve+AhrWzOUR - TLSH:
T16E5AAD9A7F1B7622C769D7201060BA7F08F3AC4F07BF5A4801A5AB1E96F441715E138B - Submitted as: virussign.com_d7bf52d81663c8afd439934fb88f5110.vir
- File type: pe · Size: 2132080 bytes
- Verdict: malicious (87/100) · Family: Softonic
Source: VirusSign · first seen 2026-08-19T00:00:00.000Z · SHA-256 verified
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Turbo Linker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Turbo Linker
- Kaspersky (KVRT): not-a-virus:HEUR:Downloader.Win32.Softonic.gen
Why this verdict
The malicious score of 87/100 is the fusion of 6 weighted signals:
- Memory forensics: 3 finding(s), e.g. RWX/private injected region in tsk_eabb7fc269 (pid 4348) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 26 external host(s) at runtime (26 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://jrsoftware.org/ishelp/index.php?topic=setupcmdline - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
897 behavior events · 0 ATT&CK techniques · 3 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\is-TSKK5PELSW.tmp\tsk_eabb7fc26905463a.tmp -
3a62ae0d102cff66fba0a1f0b9bcdf116ad369c3c4f0212eb21a53c766c75a7d - cfebfeeee24d9286f2e15b68461fd47dee4788a551d678156276fbe9e7eba302 -
cfebfeeee24d9286f2e15b68461fd47dee4788a551d678156276fbe9e7eba302 - ac294a6b6f3ae3164bf32ef440f64b9344dd143230f32ff1f690b004fa7d5b89 -
ac294a6b6f3ae3164bf32ef440f64b9344dd143230f32ff1f690b004fa7d5b89
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
- https://sectigo.com/CPS0
- http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#
- https://jrsoftware.org/ishelp/index.php?topic=setupcmdline
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787783759&P2=404&P3=2&P4=keDuCEFxHNSKvW%2bYOT7WCM4LwPm4G4svXuEoCk174tPnDqHQIcaLHiFUqlow8a01DSc%2fd2Q9s1Dj0XqMB8AudQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787783856&P2=404&P3=2&P4=DDvzBeul3GyZon5vVgj%2b3BS4r%2bah05lVyhzjFeLSLq%2bFTxZJidnPNQ7BfWMelntOI24ToE3KXaWT3aTLXUiDaA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Embedded domains
- schemas.microsoft.com
- crl.comodoca.com
- cacerts.digicert.com
- crl3.digicert.com
- crl.sectigo.com
- crt.sectigo.com
- sectigo.com
- jrsoftware.org
Embedded IP addresses
- 48.211.4.16
- 4.150.223.114
- 52.123.252.192
- 52.253.84.76
- 4.230.171.124
- 74.178.76.128
- 52.168.117.171
- 74.178.240.51
- 20.112.250.133
- 52.123.129.14
- 52.123.128.14
- 51.11.192.48
- 203.26.79.13
- 172.215.188.232
- 172.178.240.162
- 52.123.252.222
- 74.178.232.29
- 52.148.114.188
- 4.150.223.101
- 162.159.142.9
- 172.66.2.5
- 72.153.5.138
- 52.110.12.55
- 142.250.183.35
- 52.110.12.56
File paths
- T:\:d:l:p:t:x:
- X:\:`:d:h:l:p:t:x:
- N:\:k:
- E:\:
- X:\:`:h:p:x:
- U:\:c:j:t:
- T:\:j:x:
- X:\:d:h:p:t:x:
- T:\:d:l:t:
- D:\Coding\Is\issrc-build\Components\ChaCha20.pas
- x:\dirname
More Softonic samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report