In malware investigation, files signed by unknown sources with high VirusTotal reputation scores (e.g., 32 out of 70 detections) should trigger security alerts, as legitimate software is typically signed by known vendors like Microsoft, while unsigned or unknown-signer files often indicate malicious intent.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Malware Investigation Unmasking the Unknown Signer
Added:I just think it's important to highlight some of these things because we just went through all that work for the last 20 minutes and now look, we got to actual we're we're getting to the root cause. Now, one of the other things like when you scroll on the side here, you can see you have you know, directly embedded VirusTotal reputation score. Um You can see we keep scrolling down and now look, we have different hashes, okay? So, you can see here up until that point we're looking at like SHA-1, but you can see there's SHA-256. Now, when we clicked on this, what did it put?
513. Okay, so it actually re- it actually submits the 256, which is good.
You can see here it's an unsigned file.
That should also trigger an alarm because it's not signed. All the other sign All the other files we were looking at were signed, which is why they weren't they weren't triggering. You can see here signer was Microsoft. So, we knew right out the gate that that's a legitimate PowerShell file process because it was signed by a legitimate source. If we scroll down here further into our investigation, well, this malware this that's why it's associated with this malware label because look, the signer is unknown. And there's 32 out of 70.
Related Videos
Walmart Manager Arrested After Stealing $670,000 - A Data Analyst 800 Miles Away Caught Him
bodycamsecretsyt
111 views•2026-06-09
This Machine Still Runs on Punch Cards 🤯📄 #youtubeshorts
WaltersShortsChannel
6K views•2026-06-10
GitLab’s Manav Khurana: AI Agents, Orbit, and the Future of Coding
TechVoices-live
374 views•2026-06-10
"What's the Difference Between a Class and an Object?"#class #programming #softwaredevelopment
CS-with-Alireza
349 views•2026-06-08
I Made an Antivirus That Secretly Attacks Scammers
ScammerPayback
153K views•2026-06-13
Leetcode Weekly Contest 506 | Life's boring these days
Pudeesht
2K views•2026-06-14
Why Your Computer FREEZES?
GreshamCollege
1K views•2026-06-09
Programming in English
MattGodbolt
584 views•2026-06-14











