MALICIOUS — 05b6c5dcdce1753216b966301da89959caf84a93d6d19201e181e06546365250
MALICIOUS — 05b6c5dcdce1753216b966301da89959caf84a93d6d19201e181e06546365250 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Expiro family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
05b6c5dcdce1753216b966301da89959caf84a93d6d19201e181e06546365250 - SHA-1:
54de6465d60ca65fcbc1f1ca56c78dfc98d53563 - MD5:
60568a9b28ae48fa3d690b27e2be666a - imphash:
0ba39925cc55187335fdc1a6bb929fef - ssdeep:
6144:mrGU4hqLIVUdy3wdEJClfeUWo/+ghGA9XFTVw92bqThsqhkP55L+AyI:7U4hqIUwgdEUlWUWo/nu9hsPbT - TLSH:
T1F849CED07205D44DFA746CADB1BB631FF0A48AC835779050B7A92A6B1FEA20FB0C1951 - Submitted as: 05b6c5dcdce1753216b966301da89959caf84a93d6d19201e181e06546365250
- File type: pe · Size: 418304 bytes
- Verdict: malicious (96/100) · Family: Expiro
Detections (4 of 55 engines)
- ClamAV (daily): Win.Virus.Xpiro-9916472-1
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win64.Expiro.gen
Why this verdict
The malicious score of 96/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Virus.Xpiro-9916472-1 (rule
Win.Virus.Xpiro-9916472-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win64/Expiro.PABG!MTB (rule
Virus:Win64/Expiro.PABG!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win64.Expiro.Gen.6 (rule
Win64.Expiro.Gen.6) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\rmid_objs\rmid.pdb
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report