MALICIOUS — 01dcb10d30ff53563888a37201e266c12a9a17ecfdf31bdb79831e6eda6b0565.zip
MALICIOUS — 01dcb10d30ff53563888a37201e266c12a9a17ecfdf31bdb79831e6eda6b0565.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
01dcb10d30ff53563888a37201e266c12a9a17ecfdf31bdb79831e6eda6b0565 - SHA-1:
5248b7074b4ef7d7302c962d1ace2548bb31efce - MD5:
c5efffe3477b9dbc00c0ea7f05cc0d4d - ssdeep:
12:5jUlh997pFd0byyWZfo1SrqCVVat/ZM5Q+OrdG7H2yEaor:98h9dpFdjFD5VIGO+EQH2nr - TLSH:
T1C90F478E714C0D52DBE0BD049613F8FE520E501334F168591981544856384DF1646580 - Submitted as: 01dcb10d30ff53563888a37201e266c12a9a17ecfdf31bdb79831e6eda6b0565.zip
- File type: zip · Size: 589 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.81034078
- Kaspersky (KVRT): HEUR:Trojan.Multi.GenBadur.genw
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: DOC-6RTNN5.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- DOC-6RTNN5.lnk -
62ce397389f724e50819dde5b56b82ccb07ec332cb113da49476e32d41928991
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report