MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96cd16eb3bb1797f3d9357ae221c6b3626c0a7ce2716f2904d121b8ddad91c05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 96cd16eb3bb1797f3d9357ae221c6b3626c0a7ce2716f2904d121b8ddad91c05
SHA3-384 hash: 4d4027c247b9ea57c16e23840889056406fa4b635d5819a11016ca05cc314e4e9d3ec28a2d7e99b03a65a511a548fbb2
SHA1 hash: 5786ae77b09722f5f8a51c0dfc9557fbf6760989
MD5 hash: 16e1b20c47fd8195ef5cfb44c7152f3a
humanhash: colorado-don-tennis-stairway
File name:jailbreaks.zip
Download: download sample
File size:3'891 bytes
First seen:2026-06-16 11:46:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9e56qGD6hX+xz4Yku6ed7VhkYHcH+TljhqvKcYss5668CjvLGFwcPTo35e4K3y:E5FGD7d5ku6edZ5ZhqE5D8CuToJi3y
TLSH T11B81A47296B98484F479E3FA619B3753F660818FE7704AC302C8B592CD721363E0B329
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
HU HU
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:grok.txt.lnk
File size:661 bytes
SHA256 hash: b902944f70f4699404fb7809697e172f48c9245caf5390faa64e368392a999aa
MD5 hash: 5ac151d10db386501a1ccc82a789fec4
MIME type:application/octet-stream
File name:deepseek.txt.lnk
File size:677 bytes
SHA256 hash: ed85a73725a5dc248fccecaa1fb95bb5da7e93a35beb5a1289a526586bcd4b44
MD5 hash: 2e259f0305e6b7665137a23ac8e9b7d6
MIME type:application/octet-stream
File name:random.txt.lnk
File size:673 bytes
SHA256 hash: 6e7f5549967c761665113c848e99bc633bc94c6ae1c8f07b029c48d04ae358cb
MD5 hash: 11fb81ce199b808f31ba4b31382b420f
MIME type:application/octet-stream
File name:gpt.txt.lnk
File size:659 bytes
SHA256 hash: bbc5159caf345643890088a16e9b7a9da0de510ebc9f17917f0b74b09a28a090
MD5 hash: a89cc0f1ff9b5b1201291eecdf90d827
MIME type:application/octet-stream
File name:sonnet5050.txt.lnk
File size:673 bytes
SHA256 hash: fe5dbdd7dd02a295d43509cca4d24836bea8685019f0a01381532ed8a9627bab
MD5 hash: 96e9c4f099ee5b225900cc55f4749188
MIME type:application/octet-stream
File name:desktop.ini
File size:140 bytes
SHA256 hash: 18c589d8e572c2fdfbda471d42ce40337c4e9d40b079d3adec6f53154a784a4b
MD5 hash: e1ab4cc7b74a2443bb13bc8540f21a60
MIME type:text/plain
File name:gpt.txt
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70.0%
Tags:
shell overt sage
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-15T12:08:00Z UTC
Last seen:
2026-06-16T00:17:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-06-17 21:42:00 UTC
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Views/modifies file attributes
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops desktop.ini file(s)
Checks computer location settings
Deletes itself
Executes dropped EXE
Modifies file permissions
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments