MALICIOUS — 009a7a169cf10d53259ca3d8a2c8edf374443cb86c5abae1ed7e361a76b29394.zip
MALICIOUS — 009a7a169cf10d53259ca3d8a2c8edf374443cb86c5abae1ed7e361a76b29394.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
009a7a169cf10d53259ca3d8a2c8edf374443cb86c5abae1ed7e361a76b29394 - SHA-1:
5dff94ba99b156cd61a62b2fd3b9553ba7a9cae5 - MD5:
bc93e3c71b8da9df66f4a099a5e2b08b - ssdeep:
12:5jIUfl+MyhEP4gzoMkYn6oQHEzHRoe3NRWZSRkVxe1MQ/d3LIdvhSOqH9haRlsa3:9ffl+HDMkYsKHRo8TWIR8+9hL9OqHUsQ - TLSH:
T1170F47E0B8934A42CC83B0311C29F25EDC5353E651B4711A5F7D8447567C1C34C36424 - Submitted as: 009a7a169cf10d53259ca3d8a2c8edf374443cb86c5abae1ed7e361a76b29394.zip
- File type: zip · Size: 599 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (3 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Ravartar!rfn
- Kaspersky (KVRT): HEUR:Trojan.Multi.GenBadur.genw
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: LeXNET-DOC-XG3BMK.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- LeXNET-DOC-XG3BMK.lnk -
b3bd47529294bc6ef410ea61061f28b022170e8db58e6898bac15f10ec1744c2
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report