SUSPICIOUS — e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832.hta
SUSPICIOUS — e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832.hta is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (41/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832 - SHA-1:
fd330063fa1eccbcea1c2d41828595f5a510d3a1 - MD5:
2221b3b7ec59e22c400d1727b7a2112b - ssdeep:
768:FwJlzWQiP+qRjgrbBFXMbWkisTa7W4fK1Ua2NbIXglrwsuc:8fp2ObTsEW4fK26gZVuc - TLSH:
T17031CF2591C0BA739DB801A4795BAC793C79C79F03EA96B9181BF18C42C6DFE1A560C0 - Submitted as: e911b6bc7704a70fc60262a084813ac5ef49739ac95660d42e26c8818c044832.hta
- File type: html · Size: 39487 bytes
- Verdict: suspicious (41/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 53 engines)
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Trojan.GenericKD.81008411
- Kaspersky (KVRT): Trojan-Downloader.Script.Agentb.f
Why this verdict
The suspicious score of 41/100 is the fusion of 1 weighted signal:
- Obfuscated powershell script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report