MALICIOUS — virussign.com_6bc68a7540bc85ccaca629a69289d370.vir
MALICIOUS — virussign.com_6bc68a7540bc85ccaca629a69289d370.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (74/100), attributed to the Container family. 3 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
fbf4718dc46a19e5415ae9826cd8d9f03d35b52615ef632d43b15a783afafe75 - SHA-1:
e1df0e79a18798cbf11091ca8e215f2911675c65 - MD5:
6bc68a7540bc85ccaca629a69289d370 - imphash:
ef55a4d338fe22ff6f4c4f9cd1ad1b05 - ssdeep:
98304:FlZvw1kofkp8V1zf1CDQ4D+UDdRzaFDbmC333p3336Q:rZvwKoJpCP+YahD - TLSH:
T116646BDF9A1B3216D7B9D7045520AEBE08F3F8470277A89C01B7852FE6F14232E6151A - Submitted as: virussign.com_6bc68a7540bc85ccaca629a69289d370.vir
- File type: pe · Size: 5131264 bytes
- Verdict: malicious (74/100) · Family: Container
Source: VirusSign · first seen 2026-08-04T00:00:00.000Z · SHA-256 verified
Detections (3 of 52 engines)
- capa (capabilities): capability:collection/keylog
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
MITRE ATT&CK
Why this verdict
The malicious score of 74/100 is the fusion of 6 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://www.innosetup.com/, 7.0.0.3 - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.innosetup.com/
Embedded domains
- schemas.microsoft.com
- vnd.ahead.space
- vnd.digital
- vnd.net
- vnd.sun.j2me.app
- www.innosetup.com
Embedded IP addresses
- 7.0.0.3
File paths
- T:\:`:d:h:l:p:t:x:
- X:\:`:d:h:p:x:
- X:\:`:d:h:l:p:t:x:
- X:\:f:n:
- X:\:
- J:\:q:
- I:\:k:}:
- X:\:`:h:p:t:x:
- X:\:`:l:p:t:
- X:\:`:d:l:
- X:\:`:d:h:l:p:t:
- X:\:`:d:h:v:
- X:\:`:
- K:\:
- U:\:f:
- G:\:j:}:
- M:\:d:r:~:
- X:\:`:x:
- X:\:`:d:h:u:
- X:\:`:m:
- X:\:`:d:h:l:p:
- T:\:d:l:t:
- M:\:g:w:
- E:\:q:y:
- J:\:k:s:
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report