CLEAN — bd75e2ae7e47a67d4832c409c7dd0840fb5b6b1ad2d074b7c0174fb11adc0bd6.zip
CLEAN — bd75e2ae7e47a67d4832c409c7dd0840fb5b6b1ad2d074b7c0174fb11adc0bd6.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 4 of 54 detection engines flagged it.
Identification
- SHA-256:
bd75e2ae7e47a67d4832c409c7dd0840fb5b6b1ad2d074b7c0174fb11adc0bd6 - SHA-1:
539e2c365cdd2b4abae50729794918c1ee4c1990 - MD5:
eba2bbd380b6949a249aba5c3ed13245 - ssdeep:
98304:MVlkLaiaDs4iL3PjuyWO5zt0UO5cHTKaVmplnQ5msq4KRI/jSpM/eF3WKC8XqRkt:MVlzia44iLayWOQUHuodO8+WKtqO - TLSH:
T1DE6633BCE174E1D0EE49CCD3BC4A14DE987C77644CF11AE65B05D8CE362869702B6A42 - Submitted as: bd75e2ae7e47a67d4832c409c7dd0840fb5b6b1ad2d074b7c0174fb11adc0bd6.zip
- File type: zip · Size: 6383775 bytes
- Verdict: clean (25/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Win64/ShellcodeRunner.FSY!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008416
- Kaspersky (KVRT): Trojan.Win64.Agentb.llel
Why this verdict
The clean score of 25/100 is the fusion of 2 weighted signals:
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: ClLoca.dll, ComPDFKit.Viewer.dll, WinWrapIDE.exe, Xceed.Wpf.DataGrid.dll, concrt140.dll - static signal, weight 0.25, confidence 0.50
Archive contents (15 executables)
This zip carries 15 extracted members, each analyzed as its own sample:
- ClLoca.dll -
3d4e7187f74de912f9d52f5ba6a95bd41868348b16583d72957d732c0ed8f0e7 - ComPDFKit.Viewer.dll -
3466c3524f13cb3b7c87819e619bdb482ec9034a57bcdbe0240af6a9a530b02a - WinWrapIDE.exe -
0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f - Xceed.Wpf.DataGrid.dll -
b804b9dd2726e69fb4f496a6872f90edf9146ad8044c6d3a592040ce1074a5d0 - concrt140.dll -
8032b43bdd2f18ce7eb131e7cd542967081bea9490df08681bf805ce4f4d3aab - mfc140u.dll -
fc9b1f94752d7080436824b480e83ba1ec930e3f7baa881f4e842b882e715cfc - msvcp140.dll -
def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb - msvcp140_1.dll -
ba0cd05bef6aa5f54f8e86a175742020a98e35a6df116402e5e31ff9e0e8d72b - msvcp140_2.dll -
fbb8557f73ab9a207bd67643fdcf9ae34527325d227c53707cebdf0d1c8c4658 - ucrtbase.dll -
4c5b8e529854cedfa8f46cd6906952400cdbbf25efc4cf37dda2c42d8e96ddcb - vcruntime140.dll -
184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2 - vcruntime140_1.dll -
e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605 - wwb9$000.dll -
1339e336618f8d2d396100b8d6275d497e9ba0b59cec922d9ddeaf8cae08da72 - wwb9_64.dll -
671ba5caae316b8abe01e4961eb48c9f5e4eac5a957619b30c18fc3d2f72966c - wwide9.dll -
5b71b49bad415643ff3e291ee3ba550e5edfd584eb913859dadb81634450e7e7
Embedded domains
- x.uk
- z.ws
- 2.pro
- zl.sh
- u.ch
File paths
- y:\~
- Q:\6G
- r:\DV
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report