MALICIOUS — b0f0da7b1cd401c152bc611f03bc0693d5619b9d30b1e165c79ae6c15aa32c0f
MALICIOUS — b0f0da7b1cd401c152bc611f03bc0693d5619b9d30b1e165c79ae6c15aa32c0f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the EYLR family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
b0f0da7b1cd401c152bc611f03bc0693d5619b9d30b1e165c79ae6c15aa32c0f - SHA-1:
c9c9d1f0afa1bacbca51c5b688054221f9d4e8aa - MD5:
f5583d7710fc61071fb7c5b5bd1a5fc6 - imphash:
802dcac7aab948c19738ba3df9f356d9 - ssdeep:
3072:UrorlrLrlrrrlrLrlrbrlrLrlrrrlrLr: - TLSH:
T16544A76705A19D5BF617D6FB5480CF0D28F2E4F899B701D81E82DC0DA67CC5728A920E - Submitted as: b0f0da7b1cd401c152bc611f03bc0693d5619b9d30b1e165c79ae6c15aa32c0f
- File type: pe · Size: 262144 bytes
- Verdict: malicious (72/100) · Family: EYLR
Detections (3 of 25 engines)
- Microsoft Defender: Trojan:Win32/Zexa.WE!MTB
- Emsisoft (Emergency Kit): Trojan.Agent.EYLR
- Kaspersky (KVRT): Trojan.Win32.Agentb.kntn
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Trojan:Win32/Zexa.WE!MTB (rule
Trojan:Win32/Zexa.WE!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.EYLR (rule
Trojan.Agent.EYLR) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\
More EYLR samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report