Open-source atomic malware analysis

Analyze another

2a0d0488b52f6b28c5adbc91d80d31d0a75a2118aaffa758ea28fd465372df65

PE
Verdict: SUSPICIOUS
AI Google Chrome installer binary
Mal-ecule
K₂(Li₂Te)O₆(C₂PAsEr₂PrDy)H₁₀(Cm₆Cr₃Db₅F₈HfMg₂Os₁₇Po₁₆TiU₂)Md₄(Bi₃Pt)
Size 7.7 MB download
First seen 16 days ago
Analyzed 14 days ago
Source virussign.com
Also detected by 2 sources
Resource loader with registry and anti-debug: virussign.com_d10695f8baf68e63d1a72afc34f91000.vir:0x5bef10
Unsigned native Run-key replacement persistence: virussign.com_d10695f8baf68e63d1a72afc34f91000.vir:0x5d117e
PE copies a file and installs Run or RunOnce persistence: virussign.com_d10695f8baf68e63d1a72afc34f91000.vir:0x5f9240
virussign.com_d10695f8baf68e63d1a72afc34f91000.vir pe
0x5bee90 69006d0065002d006c0031002d003100 i.m.e.-.l.1.-.1.
0x5beea0 2d003200000000007500730065007200 -.2.....u.s.e.r.
0x5beeb0 33003200000000006100700069002d00 3.2.....a.p.i.-.
0x5beec0 6d0073002d0000006500780074002d00 m.s.-...e.x.t.-.
0x5beed0 6d0073002d0000001200000000000000 m.s.-...........
0x5beee0 41726546696c6541706973414e534900 AreFileApisANSI.
0x5beef0 0800000012000000436f6d7061726553 ........CompareS
0x5bef00 7472696e674578000500000012000000 tringEx.........
0x5bef10 456e756d53797374656d4c6f63616c65 EnumSystemLocaleResource loader with registry and anti-debug
0x5bef20 73457800000000000100000013000000 sEx.............
0x5bef30 466c7347657456616c75653200000000 FlsGetValue2....
0x5bef40 00000000120000004765744461746546 ........GetDateF
0x5bef50 6f726d61744578000500000012000000 ormatEx.........
0x5bef60 4765744c6f63616c65496e666f457800 GetLocaleInfoEx.
0x5bef70 000000001200000047657454696d6546 ........GetTimeF
0x5bef80 6f726d61744578000500000012000000 ormatEx.........
0x5bef90 4765745573657244656661756c744c6f GetUserDefaultLo
0x5befa0 63616c654e616d650000000000000000 caleName........
0x5befb0 0500000012000000497356616c69644c ........IsValidL
0x5befc0 6f63616c654e616d6500000000000000 ocaleName.......
0x5befd0 05000000120000004c434d6170537472 ........LCMapStr
0x5befe0 696e6745780000000600000012000000 ingEx...........
0x5beff0 4c434944546f4c6f63616c654e616d65 LCIDToLocaleName
0x5bf000 00000000000000000500000012000000 ................
0x5bf010 4c6f63616c654e616d65546f4c434944 LocaleNameToLCID
0x5bf020 000000 ...
0x5d108c 6368696c64007365742d657374696d61 child.set-estima
0x5d109c 7465642d73697a652d76616c75650076 ted-size-value.v
0x5d10ac 6563746f720053004f00460054005700 ector.S.O.F.T.W.
0x5d10bc 4100520045005c004d00690063007200 A.R.E.\.M.i.c.r.
0x5d10cc 6f0073006f00660074005c0057006900 o.s.o.f.t.\.W.i.
0x5d10dc 6e0064006f00770073005c0043007500 n.d.o.w.s.\.C.u.
0x5d10ec 7200720065006e007400560065007200 r.r.e.n.t.V.e.r.
0x5d10fc 730069006f006e005c0049006e007300 s.i.o.n.\.I.n.s.
0x5d110c 740061006c006c00650072005c005500 t.a.l.l.e.r.\.U.
0x5d111c 73006500720044006100740061005c00 s.e.r.D.a.t.a.\.
0x5d112c 0000000053002d0031002d0035002d00 ....S.-.1.-.5.-.
0x5d113c 3100380000005c00500072006f006400 1.8...\.P.r.o.d.
0x5d114c 75006300740073005c0000005c004900 u.c.t.s.\...\.I.
0x5d115c 6e007300740061006c006c0050007200 n.s.t.a.l.l.P.r.
0x5d116c 6f007000650072007400690065007300 o.p.e.r.t.i.e.s.
0x5d117c 000053004f0046005400570041005200 ..S.O.F.T.W.A.R.Unsigned native Run-key replacement persistence
0x5d118c 45005c004d006900630072006f007300 E.\.M.i.c.r.o.s.
0x5d119c 6f00660074005c00570069006e006400 o.f.t.\.W.i.n.d.
0x5d11ac 6f00770073005c004300750072007200 o.w.s.\.C.u.r.r.
0x5d11bc 65006e00740056006500720073006900 e.n.t.V.e.r.s.i.
0x5d11cc 6f006e005c0055006e0069006e007300 o.n.\.U.n.i.n.s.
0x5d11dc 740061006c006c005c007b0000007d00 t.a.l.l.\.{...}.
0x5d11ec 0000536b697070696e6720696e737461 ..Skipping insta
0x5d11fc 6c6c65722070726f7065727469657320 ller properties
0x5d120c 75706461746520626563617573652072 update because r
0x5d121c 65676973747279206b6579200020646f egistry key . do
0x5d122c 6573206e6f7420657869737420696e20 es not exist in
0x5d123c 00363400333200626974206869766500 .64.32.bit hive.
0x5d124c 0000000044006900730070006c006100 ....D.i.s.p.l.a.
0x5d125c 7900560065007200730069006f006e00 y.V.e.r.s.i.o.n.
0x5d126c 00004661696c656420746f2073657420 ..Failed to set
0x5d127c 446973706c617956657273696f6e3a20 DisplayVersion:
0x5d128c 00206e6f7420666f756e6420756e6465 . not found unde
0x5d129c 72200020636f756c64206e6f74206265 r . could not be
0x5d12ac 2077726974 writ
0x5f91c0 73696f6e2d6d616a6f720057696e646f sion-major.Windo
0x5f91d0 777356657273696f6e2d6d696e6f7200 wsVersion-minor.
0x5f91e0 57696e646f777356657273696f6e2d62 WindowsVersion-b
0x5f91f0 75696c640000000055284c9f799f394b uild....U(L.y.9K
0x5f9200 a8d0e1d42de1d5f30500000055284c9f ....-.......U(L.
0x5f9210 799f394ba8d0e1d42de1d5f31a000000 y.9K....-.......
0x5f9220 2e2e5c2e2e5c626173655c77696e5c77 ..\..\base\win\w
0x5f9230 696e5f7574696c2e6363000000000000 in_util.cc......
0x5f9240 53006f00660074007700610072006500 S.o.f.t.w.a.r.e.Unsigned native Run-key replacement persistence
0x5f9250 5c004d006900630072006f0073006f00 \.M.i.c.r.o.s.o.
0x5f9260 660074005c00570069006e0064006f00 f.t.\.W.i.n.d.o.
0x5f9270 770073005c0043007500720072006500 w.s.\.C.u.r.r.e.
0x5f9280 6e007400560065007200730069006f00 n.t.V.e.r.s.i.o.
0x5f9290 6e005c00520075006e0000007b002500 n.\.R.u.n...{.%.
0x5f92a0 300038006c0058002d00250030003400 0.8.l.X.-.%.0.4.
0x5f92b0 58002d0025003000340058002d002500 X.-.%.0.4.X.-.%.
0x5f92c0 30003200580025003000320058002d00 0.2.X.%.0.2.X.-.
0x5f92d0 25003000320058002500300032005800 %.0.2.X.%.0.2.X.
0x5f92e0 25003000320058002500300032005800 %.0.2.X.%.0.2.X.
0x5f92f0 25003000320058002500300032005800 %.0.2.X.%.0.2.X.
0x5f9300 7d0000004d0044004d00520065006700 }...M.D.M.R.e.g.
0x5f9310 69007300740072006100740069006f00 i.s.t.r.a.t.i.o.
0x5f9320 6e002e0064006c006c00000049734465 n...d.l.l...IsDe
0x5f9330 76696365526567697374657265645769 viceRegisteredWi
0x5f9340 74684d616e6167656d656e7400000000 thManagement....
0x5f9350 00000000000000000003000002000000 ................
0x5f9360 0300000006000000070000000a .............
0x601bd5 00650076006100740069006f006e0020 .e.v.a.t.i.o.n.
0x601be5 00530065007200760069006300650000 .S.e.r.v.i.c.e..
0x601bf5 00000000000000000000002000540072 ........... .T.r
0x601c05 006100630069006e0067002000530065 .a.c.i.n.g. .S.e
0x601c15 0072007600690063006500000053006f .r.v.i.c.e...S.o
0x601c25 006600740077006100720065005c004d .f.t.w.a.r.e.\.M
0x601c35 006900630072006f0073006f00660074 .i.c.r.o.s.o.f.tUnsigned native Run-key replacement persistence
0x601c45 005c0041006300740069007600650020 .\.A.c.t.i.v.e.
0x601c55 00530065007400750070005c0049006e .S.e.t.u.p.\.I.n
0x601c65 007300740061006c006c006500640020 .s.t.a.l.l.e.d.
0x601c75 0043006f006d0070006f006e0065006e .C.o.m.p.o.n.e.n
0x601c85 00740073005c00000053004f00460054 .t.s.\...S.O.F.T
0x601c95 0057004100520045005c0050006f006c .W.A.R.E.\.P.o.l
0x601ca5 00690063006900650073005c00000065 .i.c.i.e.s.\...e
0x601cb5 007800740065006e0064006500640000 .x.t.e.n.d.e.d..
0x601cc5 006100700000006e0061006d00650000 .a.p...n.a.m.e..
0x601cd5 005c0063006f0068006f007200740000 .\.c.o.h.o.r.t..
0x601ce5 0073007400610062006c006500000000 .s.t.a.b.l.e....
0x601cf5 0000000000000000000000650078 ...........e.x
0x676da0 496f436f6e74726f6c00450144697363 IoControl.E.Disc
0x676db0 6172645669727475616c4d656d6f7279 ardVirtualMemory
0x676dc0 00004601446973636f6e6e6563744e61 ..F.DisconnectNa
0x676dd0 6d656450697065004f014475706c6963 medPipe.O.Duplic
0x676de0 61746548616e646c65005301456e636f ateHandle.S.Enco
0x676df0 6465506f696e746572005701456e7465 dePointer.W.Ente
0x676e00 72437269746963616c53656374696f6e rCriticalSection
0x676e10 00007b01456e756d53797374656d4c6f ..{.EnumSystemLoResource loader with registry and anti-debug
0x676e20 63616c65735700008601457869745072 calesW....ExitPr
0x676e30 6f63657373008a01457870616e64456e ocess...ExpandEn
0x676e40 7669726f6e6d656e74537472696e6773 vironmentStrings
0x676e50 5700920146696c6554696d65546f5379 W...FileTimeToSy
0x676e60 7374656d54696d6500009d0146696e64 stemTime....Find
0x676e70 436c6f736500a30146696e6446697273 Close...FindFirs
0x676e80 7446696c654578570000a80146696e64 tFileExW....Find
0x676e90 466972737446696c65570000b4014669 FirstFileW....Fi
0x676ea0 6e644e65787446696c655700be014669 ndNextFileW...Fi
0x676eb0 6e645265736f757263655700c201466c ndResourceW...Fl
0x676ec0 73416c6c6f630000c301466c73467265 sAlloc....FlsFre
0x676ed0 6500c401466c7347657456616c756500 e...FlsGetValue.
0x676ee0 c601466c7353657456616c756500c801 ..FlsSetValue...
0x676ef0 466c75736846696c6542756666657273 FlushFileBuffers
0x676f00 0000cb01466c757368566965774f6646 ....FlushViewOfF
0x676f10 696c6500cf01466f726d61744d657373 ile...FormatMess
0x676f20 616765410000d001466f726d61744d65 ageA....FormatMe
0x676f30 7373616765570000d30146726565456e ssageW....FreeEn
0x676f40 7669726f6e6d656e74537472696e6773 vironmentStrings
0x676f50 5700d401467265654c69627261727900 W...FreeLibrary.Unsigned native Run-key replacement persistence
0x676f60 db014765744143500000ea0147657443 ..GetACP....GetC
0x676f70 50496e666f00ff01476574436f6d6d61 PInfo...GetComma
0x676f80 6e644c696e6541000002476574436f6d ndLineA...GetComPE copies a file and installs Run or RunOnce persistence
0x676f90 6d616e644c696e655700250247657443 mandLineW.%.GetC
0x676fa0 6f6e736f6c654d6f6465000029024765 onsoleMode..).Ge
0x676fb0 74436f6e736f6c654f75747075744350 tConsoleOutputCP
0x676fc0 00003a0247657443757272656e744469 ..:.GetCurrentDi
0x676fd0 726563746f7279570000410247657443 rectoryW..A.GetC
0x676fe0 757272656e7450726f63657373004202 urrentProcess.B.
0x676ff0 47657443757272656e7450726f636573 GetCurrentProces
0x677000 73496400450247657443757272656e74 sId.E.GetCurrent
0x677010 54687265616400004602476574437572 Thread..F.GetCur
0x677020 72656e74546872656164496400004c02 rentThreadId..L.
0x677030 47657444617465466f726d6174570000 GetDateFormatW..
0x677040 5a024765744472697665547970655700 Z.GetDriveTypeW.
0x677050 6202476574456e7669726f6e6d656e74 b.GetEnvironment
0x677060 537472696e6773570000640247657445 StringsW..d.GetE
0x677070 6e7669726f6e6d656e74566172696162 nvironmentVariab
0x677080 6c655700670247657445786974436f64 leW.g.GetExitCod
0x677090 6550726f6365737300006d0247657446 eProcess..m.GetF

Well-known

notable severity, 99% confident.
tool PE ProductName Google Chrome Installer

Objectives

Micro-behaviors

Metadata

20 of 74 traits shown

Identity

SHA-256 2a0d0488b52f6b28c5adbc91d80d31d0a75a2118aaffa758ea28fd465372df65
Filename virussign.com_d10695f8baf68e63d1a72afc34f91000.vir
Package 2a0d0488b52f6b28c5adbc91d80d31d0a75a2118aaffa758ea28fd465372df65

Origin

Source harvest
Feed virussign
Domain virussign.com

Timeline

First seen 3 Aug 2026 13:37 UTC
First analyzed 5 Aug 2026 11:08 UTC
Last analyzed 5 Aug 2026 11:08 UTC
Last updated 5 Aug 2026 11:08 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8