MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53898e8a1aa8fa8b3a0da356ad85cc1215f4d6b5aef341fae96a41085db349a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Expiro


Vendor detections: 16


Intelligence 16 IOCs YARA 5 File information Comments

SHA256 hash: 53898e8a1aa8fa8b3a0da356ad85cc1215f4d6b5aef341fae96a41085db349a2
SHA3-384 hash: 63a6f6bbb678825582f2f9c3e01e31cd29411a6b34afade373fe8331086785c38eaec32ad75b7bb45d9275823693eab0
SHA1 hash: 81f3dfb3734bca05f694bbcd05f207c2bc6df74e
MD5 hash: 37e430117a5135e26a95c406894a160c
humanhash: butter-don-indigo-south
File name:Factura de pago_FAC-2026-001A_pdf.exe
Download: download sample
Signature Expiro
File size:1'794'048 bytes
First seen:2026-05-11 13:20:53 UTC
Last seen:2026-06-08 09:23:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'067 x AgentTesla, 20'019 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 49152:qdq4R1lvX/sR/PfeZ114OJTi1U2vsIrubJQsSrOnELzcFdBnitEckmSXvI/:qdq4R1lvX/sR/PmA1z6GbXMFdB14SXv4
TLSH T1FA8523496109D512E0CA1F340EB0D6B627B44EAEEA22AD03AFCD7FFB757C72418145A7
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter James_inthe_box
Tags:exe Expiro

Intelligence


File Origin
# of uploads :
2
# of downloads :
119
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-05-11 13:23:35 UTC
Tags:
m0yv auto-reg phishing smtp darkcloud stealer sinkhole upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
underscore infosteal
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 crypt krypt masquerade packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-08T13:40:00Z UTC
Last seen:
2026-05-13T05:49:00Z UTC
Hits:
~1000
Detections:
Trojan.Kryplod.UDP.C&C Trojan-Spy.Agent.SMTP.C&C Trojan-PSW.Win32.Stealer.sb HEUR:Virus.Win32.Generic Virus.Win64.Moiva.a Trojan.Agentb.UDP.ServerRequest HEUR:Trojan.MSIL.PowerShell.gen HEUR:Trojan-PSW.MSIL.Agensla.vho Virus.Win32.Moiva.a Trojan.Agent.HTTP.C&C Trojan-PSW.Win32.Stelega.sb Trojan-Dropper.Win32.Injector.sb PDM:Trojan.Win32.Generic Backdoor.Win32.Androm.sb Trojan.MSIL.Dnoper.sb Trojan.Win32.Agent.sb NetTool.PlainTextCredentials.SMTP.C&C
Malware family:
Generic Malware
Verdict:
Malicious
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.18 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.VenomRAT
Status:
Malicious
First seen:
2026-05-09 10:01:43 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence ransomware spyware stealer
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of SetThreadContext
Adds Run key to start application
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
53898e8a1aa8fa8b3a0da356ad85cc1215f4d6b5aef341fae96a41085db349a2
MD5 hash:
37e430117a5135e26a95c406894a160c
SHA1 hash:
81f3dfb3734bca05f694bbcd05f207c2bc6df74e
SH256 hash:
c341d9821f828d2b3182f783d97641aa78a2a6d95b769b7d2c7e68e76dd6389e
MD5 hash:
07ab002d5bd6b1ccb572490fe2d26f13
SHA1 hash:
56fc986e61f450f8e912eeea6c5150d1ec534f92
Detections:
triage_darkcloud_infostealer triage_expiro_worm
SH256 hash:
10d329d21caaa130466427ff625d0bfae6b1f1d26adfefd9f81f8a63f85b88d0
MD5 hash:
8593639303535cbb65d16fdb01b61e5b
SHA1 hash:
5c91fc8aaa38114227fd329bc9159e5eca903f23
SH256 hash:
caebf12cf2229d84b4fabdf412326d127d2d9fef20e6ec54198ace170e5110e7
MD5 hash:
0d7d14bd5d98367a66ae34fdaefefab7
SHA1 hash:
c6e7e12d4f2ff0a7faaa92d677b88633bcd8ebcb
SH256 hash:
221010c9d393cfb4aa13fed1a6e96c009f94e4cdf2880a6514d8b260eca6a562
MD5 hash:
7f5d3b1a1485658a2c8188a39ff59583
SHA1 hash:
f9a241cb7ac284ca4de070a3285a09ae5e00c8c6
SH256 hash:
3b75425895af4ae3186b36277553641e37ca1d620ae18d68e40d13351b54de6a
MD5 hash:
94d1531b52774dce52a89e33646d5b1d
SHA1 hash:
29bf887b025b97bd7a9e1e261852ba824234a625
SH256 hash:
abdd6f31a909b0b10e30ced74a1f6f037adf1f61a8a842048dbc254d6f076169
MD5 hash:
c33a7f0e25bb3f4d3c19fc8441e9d12b
SHA1 hash:
0286b277e97b9f7c217a0d029e8144f8e20b40b9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments