MALICIOUS — 14a4b4c4fdb706815ef04a36fb5bd12091c2e3ffe42a8d4651e242f75a7861bb
MALICIOUS — 14a4b4c4fdb706815ef04a36fb5bd12091c2e3ffe42a8d4651e242f75a7861bb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Expiro family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
14a4b4c4fdb706815ef04a36fb5bd12091c2e3ffe42a8d4651e242f75a7861bb - SHA-1:
80b640abd6ab128772a78f9172b9e45dfa789e54 - MD5:
72f460357cdd9c285dceb04e672d0e43 - imphash:
c2f3a8322428c0e572369481487b6b02 - ssdeep:
12288:OzQCHzCh4gaDeRSBAC6A3NfaoqfhC9CwAiFY9ER82sKe:Om7aDOC6A3NfuhCgwAWUER8D - TLSH:
T1464BBE9C1C03ABB6C276BE22FC5D684E8834B18B313831344E4799BA74E6C6B3577945 - Submitted as: 14a4b4c4fdb706815ef04a36fb5bd12091c2e3ffe42a8d4651e242f75a7861bb
- File type: pe · Size: 494592 bytes
- Verdict: malicious (89/100) · Family: Expiro
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Expiro-9891997-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win64.Expiro.gen
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Virus.Expiro-9891997-0 (rule
Win.Virus.Expiro-9891997-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- mozilla.org
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\deploy\tmp\ssvagent\obj64\ssvagent.pdb
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report