MALICIOUS — 05692c5e3cba38e608bcbdce866e7b1dc887add796b48d85671934546e38fbc0.zip
MALICIOUS — 05692c5e3cba38e608bcbdce866e7b1dc887add796b48d85671934546e38fbc0.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
05692c5e3cba38e608bcbdce866e7b1dc887add796b48d85671934546e38fbc0 - SHA-1:
1a5e9bd1445dd255a004419c1d3f0f3b375eb1f9 - MD5:
2445d7e75805c837c3dae11ff947b24c - ssdeep:
12:5jbmBfx7oRbIbuoz7AV2AYWRwPmefIVZ0Smfh5mXFmH6viaU:9bmBfuYz7AV2AYWmPnI7pmfh5mXFmavG - TLSH:
T1B90F623C31A08B86CB68C0024E41C05EE14900461B71603FA1EE31F7145454B086A511 - Submitted as: 05692c5e3cba38e608bcbdce866e7b1dc887add796b48d85671934546e38fbc0.zip
- File type: zip · Size: 604 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.81020119
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: Nota_-P2300I.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- Nota_-P2300I.lnk -
cbb2ccc5f4472b84ef54b2a4053808669eaf6f9454e184bdba4556eab01f9e02
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report