MALICIOUS — 05bf37660d1163fa9263a3fe8a1729c89def93a47dcd96443a94ee5171e59101.zip
MALICIOUS — 05bf37660d1163fa9263a3fe8a1729c89def93a47dcd96443a94ee5171e59101.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
05bf37660d1163fa9263a3fe8a1729c89def93a47dcd96443a94ee5171e59101 - SHA-1:
273a719e0d3e71e95f575dddc4d5c1b876e1047f - MD5:
8cb05c7b5333a999260817345019b2e6 - ssdeep:
24:9RjM5oQ37+UdTejF9MAxzlynCkPh1wpjpB0Vc6TLF2EbakWFvzxJS4rfq1V9BuJ:9RjMb373dT0rzlQPhoiy6XwE8zxs4rfH - TLSH:
T16D13E49A21A2A4D2C1132E0048BBD4DD48AF022E0C749ADA98381C0C40CC1874AAAB0D - Submitted as: 05bf37660d1163fa9263a3fe8a1729c89def93a47dcd96443a94ee5171e59101.zip
- File type: zip · Size: 1244 bytes
- Verdict: malicious (89/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Sabsik.EN.A!ml
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 3 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL (rule
Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: DOC-FZ6NSX.hta - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- DOC-FZ6NSX.hta -
31ff0643ef1adfc0a94a2ba2181e197c3e82144a65906d96baea2a9a133626a0
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report