MALICIOUS — virussign.com_2f38531759a143fe5b6460bcf29267c0.vir
MALICIOUS — virussign.com_2f38531759a143fe5b6460bcf29267c0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Expiro family. 6 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
5b9ef1b3dd80959e38d0effeb8f30ec79e3023270baa3f74a4c3e07b66ebd7c5 - SHA-1:
500e61b67acfaaddf98d80be2c9704490087f38e - MD5:
2f38531759a143fe5b6460bcf29267c0 - imphash:
6ffb37b89b83059db3d703cb46fb084f - ssdeep:
12288:eZw9th2NeGyS0VTBG//sop9bw/W1wR/kjy6FtgQAdJsg0HjoMWt:eZw9tg0nQ/tbw/2Mkjy6Fr7g0ot - TLSH:
T120560299451AB631F6F2EB489850DC9D4435F08C607666DE5A03EAAF50F0133ECF32A9 - Submitted as: virussign.com_2f38531759a143fe5b6460bcf29267c0.vir
- File type: pe · Size: 1446400 bytes
- Verdict: malicious (99/100) · Family: Expiro
Source: VirusSign · first seen 2026-08-20T00:00:00.000Z · SHA-256 verified
Detections (6 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Virus.Expiro-9970350-0
- Microsoft Defender: Virus:Win64/Expiro.EM!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.7
- Trellix Stinger (McAfee): W32/Expiro.gen.re
- Kaspersky (KVRT): Virus.Win64.Moiva.a
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Virus.Expiro-9970350-0 (rule
Win.Virus.Expiro-9970350-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 3 finding(s), e.g. RWX/private injected region in tsk_790c402ad3 (pid 9064) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 43 external host(s) at runtime (87 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://www.nirsoft.net/ - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 78 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
19520 behavior events · 2 ATT&CK techniques · 81 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- pywolwnvd.biz
- ssbzmoy.biz
- cvgrf.biz
- npukfztj.biz
- przvgke.biz
- zlenh.biz
- knjghuig.biz
- uhxqin.biz
- anpmnmxo.biz
- www.anpmnmxo.biz
Dropped files
- C:\Windows\System32\dllhost.exe -
d2e60fde36ca48bc468b65a2b5a27d374bbe5023f20a4166ed755696e9ae00af - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\w32.exe -
76785561fa17b4f51f9ce543e792ba3b8730d1ea7ea20ec8e80619059ecebf29 - C:\Python310-32\Lib\venv\scripts\nt\python.exe -
1c3e03f86685866fcbb52dd6381057d55e726ca492f81db8623305cd0aab24b9 - C:\Python310-32\Lib\site-packages\setuptools\gui-64.exe -
a4ce4d441a9df6282f0946e3b33227a59898ea74d7d248de9690926cd093f874 - C:\Program Files\LibreOffice\program\swriter.exe -
01e8000354d5b5e93428827e333c63abd19741901cc6b72e066813a3077b3621 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\ktab.exe -
ce692dc6c5b282f17c9e61c46c833364a0ea1f6b69d7c4166fba9854ea648bbb - C:\Python310-32\Lib\site-packages\pip\_vendor\distlib\w64.exe -
1fa0c5b4c638f6340a93e961d5377db124b76de77c3205c6bbc84edf70a1f964 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
0f9b8bed0b5eb001df8ca88c3de24629da1554fa3b84d38f391662c919655592 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\LibreOffice\program\sdraw.exe -
1c3aea224082d33bcf4d6a72e3ee1ad528679ff43ae6aec68ba3d12c548a9cb6 - C:\Program Files\LibreOffice\program\minidump_upload.exe -
1fd899875c4f4a0a020214f9b12f4666d47ae3c76ed5e1237673245f3861ae2a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
7ab44168049af50da1c5cfa93411a3cf9b3c4137dc709f07b184b3c7a748eb9f - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\setuptools\cli.exe -
da7851d7b13dda43790809308a3cd5d6796b648742b999ff40af523454a46101 - C:\Program Files\LibreOffice\program\sweb.exe -
1fcaffac63e070b853d5ec6c4bd497bc91374f57ce3be971269b5758d58cc98d - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccessinspector.exe -
99b71c6de91d2eceb99ea5b60e6b022433039f0390cb6430006e8580b79f6fff
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.nirsoft.net/
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://pywolwnvd.biz/v
- http://ssbzmoy.biz/flvcm
- http://cvgrf.biz/tawfendqmvnfgqb
- http://npukfztj.biz/kexbnaovn
- http://przvgke.biz/u
- http://przvgke.biz/anon
- http://zlenh.biz/ctmifhhrjmwk
- http://knjghuig.biz/cawstv
- http://anpmnmxo.biz/acjm
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787850374&P2=404&P3=2&P4=VAgC7Ie5KTaIrExSOSUwzZ%2fizBthKz9l1t41U6gdWaULNd8Me%2bYdUWDxWot4JZ85zAUmudEjfvoRg4%2bzhtmqeQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://www.anpmnmxo.biz/acjm
- http://anpmnmxo.biz/xcjuusayip
- http://www.anpmnmxo.biz/xcjuusayip
- http://lpuegx.biz/wgcrtfcvn
- http://vjaxhpbji.biz/gjppcmgoq
- http://xlfhhhm.biz/cmgcbsqinvvqkf
- http://ifsaia.biz/v
- http://saytjshyf.biz/blntbmhhublv
- http://vcddkls.biz/nudedpompcqyrnyx
Embedded domains
- schemas.microsoft.com
- co.cf
- p.us
- www.nirsoft.net
- pywolwnvd.biz
- ssbzmoy.biz
- cvgrf.biz
- npukfztj.biz
- przvgke.biz
- zlenh.biz
- knjghuig.biz
- uhxqin.biz
- anpmnmxo.biz
- www.anpmnmxo.biz
- lpuegx.biz
- vjaxhpbji.biz
- xlfhhhm.biz
- ifsaia.biz
- saytjshyf.biz
- vcddkls.biz
- fwiwk.biz
- tbjrpv.biz
- deoci.biz
- gytujflc.biz
- qaynky.biz
Embedded IP addresses
- 20.184.175.9
- 57.154.63.210
- 4.230.171.124
- 52.230.60.54
- 4.247.188.233
- 135.233.95.144
- 74.178.76.54
- 52.168.117.170
- 40.104.4.2
- 52.123.129.14
- 20.231.239.246
- 52.123.128.14
- 40.99.133.242
- 52.123.252.239
- 135.234.160.246
- 44.244.22.128
- 34.41.139.193
- 3.229.117.57
- 203.26.79.13
- 52.27.79.221
- 50.16.27.236
- 2.59.170.19
- 104.219.250.36
- 52.16.171.153
- 3.238.30.69
File paths
- c:\Projects\VS2005\FullEventLogView\x64\Release\FullEventLogView.pdb
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report