MALICIOUS — 06846ed63aa7169f0586e404daf38d5179c9b2fd5ea88d0235679e62acd21d41.zip
MALICIOUS — 06846ed63aa7169f0586e404daf38d5179c9b2fd5ea88d0235679e62acd21d41.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
06846ed63aa7169f0586e404daf38d5179c9b2fd5ea88d0235679e62acd21d41 - SHA-1:
616b06706a6031b6805c1bc3e782b812f7327df1 - MD5:
2288ce3e9ffeef851e0ef60d70cd9174 - ssdeep:
12:5jVoAqgjPahDrSsMiKbfxmVSm6NXZKb93EYNJzq2aJD21e1f7o/qgjPYaZ:92WPsyTiAfySm6FYEYDq2iDbRMVPl - TLSH:
T1530FC0F3911746E1D6B4060858243E6F983A95AA78F998169130A08D297231784766D6 - Submitted as: 06846ed63aa7169f0586e404daf38d5179c9b2fd5ea88d0235679e62acd21d41.zip
- File type: zip · Size: 534 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Trellix Stinger (McAfee): Suspect-CY!2288CE3E9FFE
- Kaspersky (KVRT): HEUR:Trojan-Downloader.WinLNK.Agent.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: Clique_aqui_Instalar-APP--9FM6F9.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- Clique_aqui_Instalar-APP--9FM6F9.lnk -
ed59c265a1be2c1bd540069110a0c9452dfb271d0ffff6dbcc75a3f2901ad770
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report