MALICIOUS — b295f1b6ba2945d95e42234bb20ca7f496b33983fcfad10a68e14788f61de49e
MALICIOUS — b295f1b6ba2945d95e42234bb20ca7f496b33983fcfad10a68e14788f61de49e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Expiro family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
b295f1b6ba2945d95e42234bb20ca7f496b33983fcfad10a68e14788f61de49e - SHA-1:
46444bc405bf62bb6c1136443cb8681adea88298 - MD5:
deea95938b9c2667e065597b762f5990 - imphash:
3b1494b15b4dae22812c269c29d3e478 - ssdeep:
6144:+3fQbJf1MDUa0GDstYJY+/QzmFz2D+Hhqsr6zxXdamp0vygpDHPc:+CJfSUanD3JFAQIsr69XJSvygpg - TLSH:
T1BD496CECE7DFD981D2A9EF01F7ADA81E4C75E70210B05170422A96F322E2C537515E2A - Submitted as: b295f1b6ba2945d95e42234bb20ca7f496b33983fcfad10a68e14788f61de49e
- File type: pe · Size: 425984 bytes
- Verdict: malicious (86/100) · Family: Expiro
Detections (4 of 52 engines)
- ClamAV (daily): Win.Virus.Expiro-9897086-0
- Microsoft Defender: Virus:Win64/Expiro.PABG!MTB
- Emsisoft (Emergency Kit): Win32.Expiro.Gen.6
- Kaspersky (KVRT): HEUR:Virus.Win32.Expiro.gen
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Virus.Expiro-9897086-0 (rule
Win.Virus.Expiro-9897086-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Expiro samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report