MALICIOUS — 06679e29d82fed607a695c4eb74ebb2e7737735ac5e917db9c8b375f28d664f8.zip
MALICIOUS — 06679e29d82fed607a695c4eb74ebb2e7737735ac5e917db9c8b375f28d664f8.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
06679e29d82fed607a695c4eb74ebb2e7737735ac5e917db9c8b375f28d664f8 - SHA-1:
294bbc10ccb69f6ccbb2d8696a0e01beff2a4c02 - MD5:
9496be2f6667cc78de2ca62537f8d4ed - ssdeep:
12:5j6ujyjDnovXOIQKsAv3FsJKbuL3OVf0drNv0eEszccujvjDYai:9XOj8fOI9sISIujOedrNvgsoFDjq - TLSH:
T1110F02A54572C0D0C5315BC82B113ACFC6570E6A49B054F6CB79E30A775D89740085D0 - Submitted as: 06679e29d82fed607a695c4eb74ebb2e7737735ac5e917db9c8b375f28d664f8.zip
- File type: zip · Size: 618 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Script/Phonzy.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.81019927
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: JustificantePDF2107-0HK3HS.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- JustificantePDF2107-0HK3HS.lnk -
4a793f850c28a4c1f445d1b79731892b63bd0072f9201e3c6f52b334e47b81db
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report