MALICIOUS — 05fcb36d0d0f42ca168661001634bb5cf9efb8dd4a4448c2913d4c7080a42888.zip
MALICIOUS — 05fcb36d0d0f42ca168661001634bb5cf9efb8dd4a4448c2913d4c7080a42888.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
05fcb36d0d0f42ca168661001634bb5cf9efb8dd4a4448c2913d4c7080a42888 - SHA-1:
67a82171c43da66b3fba7a5b02ec1ef12ee015c7 - MD5:
eb56c75d48cf31ecfd07a8624f4347fc - ssdeep:
24:9OLMPA/N184oSNbKk372SKmx/yzpj9N+CVGC/JFjl8cQxBVvhX:9OLMPAg4ZbfV1yzpeM7/nKBVvx - TLSH:
T1E41378C1275D7223F3E0A858D015201F6CB5106620939C4609D0205FB5DBBB79AB5127 - Submitted as: 05fcb36d0d0f42ca168661001634bb5cf9efb8dd4a4448c2913d4c7080a42888.zip
- File type: zip · Size: 1291 bytes
- Verdict: malicious (89/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Wacatac.C!ml
- Kaspersky (KVRT): HEUR:Trojan-Downloader.Script.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 3 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL (rule
Sanesecurity.Foxhole.Hta_Zip_2.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: nfe_doc-VXNTFD.hta - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- nfe_doc-VXNTFD.hta -
2053a83f4339fc9cb02b0d43b497024d1b998946d1f45b4b051ec7698e2a820b
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report