MALICIOUS — 0fa5d0dfac3e7bbe0287ce8dab25fbef77ecdd9ad352401b9aa8e8ce52194e77
MALICIOUS — 0fa5d0dfac3e7bbe0287ce8dab25fbef77ecdd9ad352401b9aa8e8ce52194e77 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Expiro family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
0fa5d0dfac3e7bbe0287ce8dab25fbef77ecdd9ad352401b9aa8e8ce52194e77 - SHA-1:
1c494780aa2505d26a5411a36284f085ff9942b5 - MD5:
06c1564b5305d29f0abdbb8a47ba115b - imphash:
1e2f1157724358595d4ba5f4d5e8d784 - ssdeep:
6144:nqnVW5k/kA3byc37oK6ijKSpoVM1Az/PEx2OkAUIoGpgQDlbbzBwcGyGqJ:nqVmAdMoXpoyY3ExmcX5DlPacGy - TLSH:
T1EF4ACF29108FE261EC66FE84B0B82CBCCF74E366123D04F44A5A85D1BBC2D6751E2935 - Submitted as: 0fa5d0dfac3e7bbe0287ce8dab25fbef77ecdd9ad352401b9aa8e8ce52194e77
- File type: pe · Size: 439296 bytes
- Verdict: malicious (86/100) · Family: Expiro
Detections (4 of 52 engines)
- ClamAV (daily): Win.Virus.Expiro-9893365-0
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win64.Expiro.gen
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Virus.Expiro-9893365-0 (rule
Win.Virus.Expiro-9893365-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\jabswitch\jabswitch.pdb
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report