MALICIOUS — 244f99aee7d8cc63cca05e29ad19f03043165a8bde6ad4f21ec88cc6bafa858a.zip
MALICIOUS — 244f99aee7d8cc63cca05e29ad19f03043165a8bde6ad4f21ec88cc6bafa858a.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Egairtigado family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
244f99aee7d8cc63cca05e29ad19f03043165a8bde6ad4f21ec88cc6bafa858a - SHA-1:
d7eaebc2a1d2c670b7724837ae9579b196f1d75f - MD5:
2311e517cd16ad4e7921f04f2805f0c9 - ssdeep:
24:9/tuhHuyxWBOT3jlrppBYTQj5i8EJBIt/S4jmk3KbW3sW8xhJi37Wk1t9ye4T:9/t8HI0ppAQj5xEJuxBTz1u67W+tY - TLSH:
T11613E97577C1444FEA421B92280C947DA3DC1D33926A2AD344CBEE9620B846B01E563D - Submitted as: 244f99aee7d8cc63cca05e29ad19f03043165a8bde6ad4f21ec88cc6bafa858a.zip
- File type: zip · Size: 1467 bytes
- Verdict: malicious (97/100) · Family: Egairtigado
Source: MalwareBazaar · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL
- Microsoft Defender: Trojan:Win32/Egairtigado!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80977042
- Kaspersky (KVRT): HEUR:Trojan.WinLNK.Agent.gen
Why this verdict
The malicious score of 97/100 is the fusion of 5 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL (rule
Sanesecurity.Foxhole.Lnk_Zip_1.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Egairtigado!rfn (rule
Trojan:Win32/Egairtigado!rfn) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.GenericKD.80977042 (rule
Trojan.GenericKD.80977042) - engine signal, weight 0.55, confidence 0.85 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: photov_351499307841.lnk - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- photov_351499307841.lnk -
159575c757cedd859acc08f2c0029c0279e663c48dee4c102d7e4d040a4ccf97
More Egairtigado samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report