MALICIOUS — malware.exe
MALICIOUS — malware.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the EyeStye family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
9e72e4553bb8d724c3b625ece13632f26f1e9bebdad61ffeeb38ea5fab14b118 - SHA-1:
c0c93f1afc0985fda540f8292f323d40f00c3198 - MD5:
cefbe57fb29cbd911b28e1d9a8918ab0 - imphash:
6303e5a175a9305847f25ad713ba443f - ssdeep:
3072:vCgR4N2ApH77yU06Y0a+rkaOQ7n4EXhMpe:6gR4NT0Z0aZah7n/hME - TLSH:
T1FF3FE1664320920ECFD69FA751815B4C60B2F5BE61FD5C842EC7A7AFBA6410F48CD218 - Submitted as: malware.exe
- File type: pe · Size: 151040 bytes
- Verdict: malicious (98/100) · Family: EyeStye
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.SpyEye-7465744-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/EyeStye
- Emsisoft (Emergency Kit): Trojan.Rootkit.Agent.NGK
- Kaspersky (KVRT): Trojan-Spy.Win32.SpyEyes.df
Why this verdict
The malicious score of 98/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.SpyEye-7465744-1 (rule
Win.Trojan.SpyEye-7465744-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/EyeStye (rule
Trojan:Win32/EyeStye) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Rootkit.Agent.NGK (rule
Trojan.Rootkit.Agent.NGK) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Spy.Win32.SpyEyes.df (rule
Trojan-Spy.Win32.SpyEyes.df) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More EyeStye samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report