MALICIOUS — 0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849.zip
MALICIOUS — 0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (79/100), attributed to the RemoteAdmin family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849 - SHA-1:
5c60e0bd09d869384b7c18739804f3209bb2b902 - MD5:
725cca0ed6d921e979761aa1dc3543b5 - ssdeep:
384:KhM0gCF9kDwhLG9Xj0z4nyCGA5B+zEPyGN1imr0JZILhMB4FPQCt:VRnDkLUjNyCDazElP9IJZItA4FPQCt - TLSH:
T1A52AE0C68AFDA18BD56165CCEEC0E0FD3A531069D2964BD828C1AE4BBDBC1839570C19 - Submitted as: 0bee1bc1fbaff816f79e78a31389680fdb23c79bff30168b26e042f793c2a849.zip
- File type: zip · Size: 22152 bytes
- Verdict: malicious (79/100) · Family: RemoteAdmin
Source: MalwareBazaar · first seen 2026-07-31T00:00:00.000Z · SHA-256 verified
Detections (3 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): Trojan.GenericKD.80999986
- Kaspersky (KVRT): not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen
Why this verdict
The malicious score of 79/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80999986 (rule
Trojan.GenericKD.80999986) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen (rule
not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen) - engine signal, weight 0.55, confidence 0.85 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: client32.exe - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- client32.exe -
8000ffd1f8b32b4b85be9c3e730874865d949f9359c9a91c4386f4ff32deb180
More RemoteAdmin samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report