MALICIOUS — 59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c
MALICIOUS — 59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Expiro family. 6 of 56 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c - SHA-1:
11aaa29956492ecf7d59487e45f2a2ed2a37d40a - MD5:
0de4274d3cb05a014c88e2eee94c03a6 - imphash:
b703859ccf1001653c4639fc48c66a9a - ssdeep:
98304:9TXyyHTw8cslg+dJxM3JCAVPJMVcNmEllPx:NXyuis8Fx - TLSH:
T171646BD64A1F3222F2BBDC54681258ECA063F179613C574EA71BC82E80D393BE9F1165 - Submitted as: 59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c
- File type: pe · Size: 5450240 bytes
- Verdict: malicious (100/100) · Family: Expiro
Detections (6 of 56 engines)
- capa (capabilities): capability:credential-access
- ClamAV (daily): Win.Virus.Expiro-10023368-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win64.Expiro.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Virus.Expiro-10023368-0 (rule
Win.Virus.Expiro-10023368-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win64/Expiro.PABG!MTB (rule
Virus:Win64/Expiro.PABG!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win64.Expiro.Gen.6 (rule
Win64.Expiro.Gen.6) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Virus.Win64.Expiro.gen (rule
HEUR:Virus.Win64.Expiro.gen) - engine signal, weight 0.55, confidence 0.85 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Contacted 1 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://en.wikipedia.org/wiki/Sha-256, http://en.wikipedia.org/wiki/Sha1, https://en.wikipedia.org/wiki/Locality-sensitive_hashing - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. RWX/private injected region in SppExtComObj.E (pid 5696) (rule
windows.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- fe3cr.delivery.mp.microsoft.com
- assets.msn.com
- v10.events.data.microsoft.com
- slscr.update.microsoft.com
Embedded URLs
- http://en.wikipedia.org/wiki/Sha-256
- http://en.wikipedia.org/wiki/Sha1
- https://msdn.microsoft.com/en-us/library/windows/desktop/aa388208
- https://en.wikipedia.org/wiki/Locality-sensitive_hashing
- http://en.wikipedia.org/wiki/MD5
- https://msdn.microsoft.com/en-us/library/windows/desktop/ms680313
- http://en.wikipedia.org/wiki/Cyclic_redundancy_check
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms680313
- https://msdn.microsoft.com/en-us/library/windows/desktop/gg258117
- https://msdn.microsoft.com/en-us/library/windows/desktop/ms680339
- https://msdn.microsoft.com/en-us/library/windows/desktop/mt823702
- https://msdn.microsoft.com/en-us/library/windows/desktop/ms724358
- https://sevillegwus.microsoft.com
- http://www.microsoft.com/sense
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- en.wikipedia.org
- msdn.microsoft.com
- sevillegwus.microsoft.com
- sevillegw.microsoft.com
- www.microsoft.com
Embedded IP addresses
- 4.150.223.113
- 48.211.4.16
- 4.144.132.114
- 52.123.252.235
- 4.230.171.124
- 135.233.95.135
- 20.184.175.2
- 74.178.240.61
- 20.184.175.12
- 52.123.252.229
- 52.110.12.54
- 52.110.12.10
- 52.110.12.3
- 125.56.205.123
- 125.56.205.24
Registry keys
- HKLM\Software\Classes\Wow6432Node\CLSID
- HKLM\Software\Classes\DirectShow
- HKLM\Software\Classes\Wow6432Node\DirectShow
- HKLM\Software\Classes\Interface
- HKLM\Software\Classes\Wow6432Node\Interface
- HKLM\Software\Classes\Media
- HKLM\Software\Classes\Wow6432Node\Media
- HKLM\Software\Classes\MediaFoundation
- HKLM\Software\Classes\Wow6432Node\MediaFoundation
- HKLM\Software
- HKLM\Software\Wow6432Node
- HKCU\Software\Classes\CLSID
- HKCU\Software\Classes\Wow6432Node\CLSID
- HKCU\Software\Classes\DirectShow
- HKCU\Software\Classes\Wow6432Node\DirectShow
- HKCU\Software\Classes\Interface
- HKCU\Software\Classes\Wow6432Node\Interface
- HKCU\Software\Classes\Media
- HKCU\Software\Classes\Wow6432Node\Media
- HKCU\Software\Classes\MediaFoundation
- HKCU\Software\Classes\Wow6432Node\MediaFoundation
- HKLM\SOFTWARE\Classes\HCP
- HKLM\SOFTWARE\Classes\AppID
- HKLM\SOFTWARE\Microsoft\COM3
- HKLM\SOFTWARE\Clients
File paths
- C:\\Windows\\System32\\.
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report