SUSPICIOUS — virussign.com_fbc3aee1c42074339fc31f4e4689bad0.vir
SUSPICIOUS — virussign.com_fbc3aee1c42074339fc31f4e4689bad0.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 53 detection engines flagged it.
Identification
- SHA-256:
fbb2983e700f21db515d74f7d84c0445378596865e4f9608720bea40eacabdb7 - SHA-1:
0f6575c9f1aa5439cbce106e2b6b59d30f4ca4a3 - MD5:
fbc3aee1c42074339fc31f4e4689bad0 - ssdeep:
384:ES21cnvAFE6N4WWZPY1aXPY1p6D2gNuyI+RJkJhrbXa:ES21cnvAFE6NfWZiqiQDB/R9 - TLSH:
T1C135316A53613D8F8BF95C0DB45928AC51C5E2DF896120F9EBCCDF8E9820D61E00B635 - Submitted as: virussign.com_fbc3aee1c42074339fc31f4e4689bad0.vir
- File type: html · Size: 59720 bytes
- Verdict: suspicious (54/100)
Source: VirusSign · first seen 2026-08-18T00:00:00.000Z · SHA-256 verified
Detections (0 of 53 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 2 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (layers: concat) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Embedded network infrastructure: https://fonts.googleapis.com, https://cdn.jsdelivr.net, https://lumyrixscalarai.live/assets/img/bg.webp - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://fonts.googleapis.com
- https://fonts.gstatic.com
- https://cdn.jsdelivr.net
- https://cloudflare.com
- https://lumyrixscalarai.live/assets/img/bg.webp
- http://lumyrixscalarai.live
- https://lumyrixscalarai.live/frontend/assets/favicon.png
- https://lumyrixscalarai.live
- https://schema.org
- https://fonts.googleapis.com/css2?family=Montserrat:wght@400
- https://lumyrixscalarai.live/assets/css/main.css?v=5
- https://lumyrixscalarai.live/assets/css/form.css
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/css/intlTelInput.css
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/img/flags.webp
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/img/flags@2x.webp
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/img/globe.webp
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/img/globe@2x.webp
- https://lumyrixscalarai.live/assets/video/post.webp
- https://cdn.jsdelivr.net/npm/intl-tel-input@25.8.3/build/js/intlTelInput.min.js
- https://flagcdn.com/gb.svg
- https://flagcdn.com/sa.svg
- https://flagcdn.com/bg.svg
- https://flagcdn.com/bd.svg
- https://flagcdn.com/cz.svg
- https://flagcdn.com/dk.svg
Embedded domains
- fonts.googleapis.com
- fonts.gstatic.com
- cdn.jsdelivr.net
- cloudflare.com
- lumyrixscalarai.live
- schema.org
- flagcdn.com
- intl-tel-input.com
- github.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report