MALICIOUS — 4be2b258e96df071001e073cc20687a040623d4359bc4825422b19583e0a2a77
MALICIOUS — 4be2b258e96df071001e073cc20687a040623d4359bc4825422b19583e0a2a77 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the EYLR family. 3 of 55 detection engines flagged it.
Identification
- SHA-256:
4be2b258e96df071001e073cc20687a040623d4359bc4825422b19583e0a2a77 - SHA-1:
d146d504642c47cda205b4f89d1b04f63e1d9114 - MD5:
cef930b181b6e3c5d8e92a5e86ce4b1c - imphash:
802dcac7aab948c19738ba3df9f356d9 - ssdeep:
1536:ytri2HOitri2eOitri2cOitri2eOitri23Oitri2eOitri2cOitri2eO:UrJrGrkrGrZrGrkr - TLSH:
T13A3DA66705A19D5BF617D6FB9480DF0D28F2E4F899B701D81E82DC0DA67CC5328A920E - Submitted as: 4be2b258e96df071001e073cc20687a040623d4359bc4825422b19583e0a2a77
- File type: pe · Size: 131072 bytes
- Verdict: malicious (72/100) · Family: EYLR
Detections (3 of 55 engines)
- Microsoft Defender: Trojan:Win32/Zexa.WE!MTB
- Emsisoft (Emergency Kit): Trojan.Agent.EYLR
- Kaspersky (KVRT): Trojan.Win32.Agentb.kntn
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Zexa.WE!MTB (rule
Trojan:Win32/Zexa.WE!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.EYLR (rule
Trojan.Agent.EYLR) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\
More EYLR samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report