MALICIOUS — I-Worm.Nimda.zip
MALICIOUS — I-Worm.Nimda.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the UNOFFICIAL family. 2 of 48 detection engines flagged it.
Identification
- SHA-256:
70e37ea05b1d89e37e04b1c2ce98731e65b6c37cf718dc72a109d862ca36cc2a - SHA-1:
9386f9265791878c36a39be267b1e332ecc75ece - MD5:
844855b2ec58f20718cff30d874ab43e - ssdeep:
3072:mUIpQH9KIUYxqpNuxoL4FhPH9hdGdElGmUKVjre6u:K6H9z+46LKRdhdVlFHu - TLSH:
T18D3C02DE8F8A5B59CB670D9008D9940C85BE8D5ED1B4490B6FA475FAB2FD0CF09242C2 - Submitted as: I-Worm.Nimda.zip
- File type: zip · Size: 112623 bytes
- Verdict: malicious (89/100) · Family: UNOFFICIAL
Source: theZoo · first seen 2026-07-25T18:26:26.224Z · SHA-256 not source-verified
Detections (2 of 48 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): {HEX}bin.trojan.generic.n.93.UNOFFICIAL
Why this verdict
The malicious score of 89/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged {HEX}bin.trojan.generic.n.93.UNOFFICIAL (rule
{HEX}bin.trojan.generic.n.93.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: main_menu.js, I-WORM~1.VBS - static signal, weight 0.25, confidence 0.50
Archive contents (3 executables)
This zip carries 3 extracted members, each analyzed as its own sample:
- I-WORM~1.VBS -
bb9f9fcea94271478da1e6fda01d089979a152eee642fa711e2a81990518d3b7 - main_menu.js -
ec44bf9b374a9477850a6f65ff1b0f1b92574664653e31717aafa46eb0bc9ede - readme.eml -
c4a60096ad81f6e4ce7412f4873465de408eab69d7ac35b9af9b0b1a4ccd3eea
More UNOFFICIAL samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report