MALICIOUS — 0052a43d23330d6cae8897a179725c40869a1d540d27a0a56430aeac1ec44d13.zip
MALICIOUS — 0052a43d23330d6cae8897a179725c40869a1d540d27a0a56430aeac1ec44d13.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 5 of 54 detection engines flagged it.
Identification
- SHA-256:
0052a43d23330d6cae8897a179725c40869a1d540d27a0a56430aeac1ec44d13 - SHA-1:
f492d25bca29e2883f8bf240548b2f0bc293a7bc - MD5:
8f3beeff7a050d0e8fdd7477e1f98326 - ssdeep:
24:9Z4f5Ssz9fIGu0xIPJ8F/hqvSP+Fwa/0+L9AGCvreiNqWghBsJEBbvl:9Ez9fXmPOb1adrCCiNnW9Bbt - TLSH:
T1D013E7E91036D876CBF8681565D80FCC9E6D753739A57AB08505071CD2AD13B4B32924 - Submitted as: 0052a43d23330d6cae8897a179725c40869a1d540d27a0a56430aeac1ec44d13.zip
- File type: zip · Size: 1267 bytes
- Verdict: malicious (89/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (5 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.81020273
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 3 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL (rule
Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: Nota_-FI6JAK.hta - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- Nota_-FI6JAK.hta -
58935ff6eb4b7894f69a861a59b4b1d3f1890528c5b504beb44f1baeb5aa92bc
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report