MALICIOUS — 08455ba4e16126ebee709b30cd8f6cbdd4707ba01da42187d9d67d0096f0d452.zip
MALICIOUS — 08455ba4e16126ebee709b30cd8f6cbdd4707ba01da42187d9d67d0096f0d452.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
08455ba4e16126ebee709b30cd8f6cbdd4707ba01da42187d9d67d0096f0d452 - SHA-1:
749d68372151603dd2cf5d8eb58ea4d5331506de - MD5:
9efa76f606791b8e3c83be89fc4892ce - ssdeep:
12:5ji5o8L0ZxwI5AFYOtKFEOuOTUHwtbDFPb9pM75/x2npljfu8u745o8LvfZviag:9j60TwIGF7tKf4HyDVb7M75/x2Dfu8ul - TLSH:
T1ED0F41063C66EB11D13D583208F1648ECC97B142557222EA9FB1CC006310073E42BA50 - Submitted as: 08455ba4e16126ebee709b30cd8f6cbdd4707ba01da42187d9d67d0096f0d452.zip
- File type: zip · Size: 581 bytes
- Verdict: malicious (87/100)
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (2 of 54 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Archive contains executables: nfe_-P4N4WU.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- nfe_-P4N4WU.lnk -
ccdf022f48885bc57c4f4ea16a5a74fad41fc05d4c4566e68cf87a9f2f2fa4e0
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report