MALICIOUS — 5c571976e8c6e43d858026aa09f2e611ce73f83ecfd78d4817877a3a7d3f8617
MALICIOUS — 5c571976e8c6e43d858026aa09f2e611ce73f83ecfd78d4817877a3a7d3f8617 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Expiro family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
5c571976e8c6e43d858026aa09f2e611ce73f83ecfd78d4817877a3a7d3f8617 - SHA-1:
669e838b93e14c70ac7e7c843c3f9f01129f753e - MD5:
105831a96d06ed82ce54515387d791f7 - imphash:
f60e1294a3d382cb326decebd143ded4 - ssdeep:
6144:wGvEaLlz6Re5Xmxe/Lzi1U5zoV4r/7qT7a9gTWwevGU9bmSV6KVR:w8H5rXXziG5O4r/7jgiwevX9iS6K - TLSH:
T1B14BCFCC161385D1CEB4EA606C35A4CC4DF0B9416471A2A8091BC4AFEAEA87FBD7DD05 - Submitted as: 5c571976e8c6e43d858026aa09f2e611ce73f83ecfd78d4817877a3a7d3f8617
- File type: pe · Size: 475648 bytes
- Verdict: malicious (89/100) · Family: Expiro
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Expiro-9893367-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win64.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win64.Expiro.gen
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Virus.Expiro-9893367-0 (rule
Win.Virus.Expiro-9893367-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- zakaz.za
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report