MALICIOUS — virussign.com_fd1b1dd7d2e08e138e65a8879680d000.vir
MALICIOUS — virussign.com_fd1b1dd7d2e08e138e65a8879680d000.vir is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the UNOFFICIAL family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fce4c39655869d2e3c42af460539d6f9f8ad8e03eb7ebb4505bca4e10ad04542 - SHA-1:
ebf1b008e0e472ef520e257f8f2b5167bf86ebe7 - MD5:
fd1b1dd7d2e08e138e65a8879680d000 - ssdeep:
98304:L5FfFad2ZE+CXeT3UOkxo699ME4NFlYQQVodeGKZt4thn1wff83qiWErsa40aH6W:NFfFad2ZTCXeT3UOkxo699M3NFlYQQV7 - TLSH:
T1D463238E9F433E36235F8E12D5B49B193EF62251BB56FF882F881E4AB518F414109349 - Submitted as: virussign.com_fd1b1dd7d2e08e138e65a8879680d000.vir
- File type: unknown · Size: 4739989 bytes
- Verdict: malicious (96/100) · Family: UNOFFICIAL
Source: VirusSign · first seen 2026-07-17T00:00:00.000Z · SHA-256 verified
Detections (5 of 51 engines)
- capa (capabilities): beacon to command-and-control
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): {HEX}php.generic.globals.503.UNOFFICIAL
- Microsoft Defender: flagged
- Kaspersky (KVRT): HEUR:Backdoor.Perl.Agent.b
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged {HEX}php.generic.globals.503.UNOFFICIAL (rule
{HEX}php.generic.globals.503.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged flagged (rule
flagged) - engine signal, weight 0.55, confidence 0.85 - beacon to command-and-control (rule
beacon to command-and-control) - capa signal, weight 0.45, confidence 0.80 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Embedded domains
- t5.fi
- 5a.hk
- qv.gq
File paths
- Z:\y
More UNOFFICIAL samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report