CLEAN — virussign.com_2aaf5c23371c5c5c591cf6b3cfb4b7c0.vir
CLEAN — virussign.com_2aaf5c23371c5c5c591cf6b3cfb4b7c0.vir is a archive sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (14/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
fe318c8e9591c75c9dc43822e064b9cdc3fe72b1f3f8bede7b68758fa0debaf1 - SHA-1:
8f46a2a3752b6ccae9e3f9b86e674621fc12e6ae - MD5:
2aaf5c23371c5c5c591cf6b3cfb4b7c0 - ssdeep:
6144:qHuHvnW50AH6NQwUGqpoBl+1cOkgEyu7fu7R7sv3/MdvORrUomPIK2eOc6:qHMsDH66DVOBICgEa7JsvvivORrNmg3h - TLSH:
T196492322E442F5D1397A8AE61C0D121C3C935613E16999F598D5F8661F2203E2ACF3EF - Submitted as: virussign.com_2aaf5c23371c5c5c591cf6b3cfb4b7c0.vir
- File type: archive · Size: 391753 bytes
- Verdict: clean (14/100)
Source: VirusSign · first seen 2026-08-16T00:00:00.000Z · SHA-256 verified
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Program:Win32/Vigram.A
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The clean score of 14/100 is the fusion of 1 weighted signal:
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (1 executable)
This archive carries 1 extracted member, each analyzed as its own sample:
- FACTURA.js -
afb37dc0678f295bdae2708f5b840230f90711ced3ee1c753e9a0238d4f64eb1
Embedded domains
- gm.cn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report