MALICIOUS — 00fd9eba8a0df263f587e18d42d6ef6794ef08ca6780485ccb45ef9206cfb5ef.zip
MALICIOUS — 00fd9eba8a0df263f587e18d42d6ef6794ef08ca6780485ccb45ef9206cfb5ef.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
00fd9eba8a0df263f587e18d42d6ef6794ef08ca6780485ccb45ef9206cfb5ef - SHA-1:
da5f5c7af276829bebe87c2d26698a61935a67f1 - MD5:
bdf001ae991be36bb7ece4a4df68105b - ssdeep:
12:5jFWb2OpJ145fb3cPCzSRIB5LGPPwXvyn1KV6HxwgNmjPTXaeLEM6sLeNopnWbQl:9FPOn1ubsqz1UQCbR7m7TXaWEhk7pnjH - TLSH:
T1840F0CC569228C16DAB80B01946099FEA43F24032FA213D95C264C6A3CB8A5326F3602 - Submitted as: 00fd9eba8a0df263f587e18d42d6ef6794ef08ca6780485ccb45ef9206cfb5ef.zip
- File type: zip · Size: 585 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (3 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Kaspersky (KVRT): HEUR:Trojan.Multi.GenBadur.genw
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: DOC-HOZUAY.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- DOC-HOZUAY.lnk -
01f1fac525a1f0193bba7f0f442b395280e3071b7df6f43ae0b975bb1187cfd6
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report