Is 2026-10-06.Tax Documents_4202.zip safe?
Eighteen of 75 engines flagged this newly observed tax-themed ZIP, while sandbox execution launched an embedded executable and contacted an unusual external domain.
The archive is strongly associated with a Mikey/Silverfox-style trojan: 18 of 75 engines detected it, including five independent high-trust votes. A completed sandbox run launched a tax-themed executable from a temporary directory and contacted asdopdkdz.cn over port 8443, reinforcing the static detections despite no explicit sandbox verdict.
33783d41e82040527b…2623cfbe0f6d61Recommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive is strongly associated with a Mikey/Silverfox-style trojan: 18 of 75 engines detected it, including five independent high-trust votes. A completed sandbox run launched a tax-themed executable from a temporary directory and contacted asdopdkdz.cn over port 8443, reinforcing the static detections despite no explicit sandbox verdict.
The detection pattern is substantial rather than a low-trust-only anomaly: 18 of 75 engines flagged the archive and five independent high-trust votes were recorded. BitDefender, Emsisoft, and GData use the same Mikey label, while Kaspersky identifies Silverfox and ESET identifies an Agent trojan. During one completed sandbox run, an embedded tax-document-themed executable ran from a temporary directory and made an HTTPS connection to asdopdkdz.cn on port 8443. The file is newly observed, extremely rare, and uses a document-themed ZIP name that could entice a recipient to launch the payload. The lack of an explicit sandbox malware verdict and the clean cached host lookup are counter-signals, but they do not outweigh the multi-vendor detections and observed payload execution.
What We Detected
18 of 75 antivirus engines flagged the archive, including five independent high-trust detections. BitDefender, Emsisoft, and GData identify Mikey, Kaspersky reports Silverfox, and ESET-NOD32 reports an Agent trojan. The archive is newly observed, has only one known submission source, and contains a PE executable despite presenting as tax documents.
Threat Behavior
One completed sandbox run launched a tax-document-themed executable from the user's temporary directory. The process contacted asdopdkdz.cn over HTTPS on port 8443, producing the network communication technique T1071. The single contacted host was fully checked against the available cache and had no existing malicious or suspicious classification, while the dropped child remained unclassified; these limitations do not negate the observed execution and engine evidence.
What To Do Now
Do not open or extract the archive. Quarantine or delete it while keeping endpoint protection enabled; if it was already executed, disconnect the affected system from the network and perform a full scan and incident review.
Where this verdict could be wrong4 caveats
- engines.tier1FamilyConsensus.strong=false, so high-trust engines do not establish a strong single-family consensus.
- behaviour.hasMaliciousSandboxVerdict=false and behaviour.offensiveCount=0; the completed run did not issue an explicit malicious verdict or observe malware-exclusive techniques.
- contactedHosts.inspected=1 found no cached malicious or suspicious result for the single contacted host.
- droppedChildren.hasMaliciousChild=false, although the inspected child has no assigned verdict.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No explicit malicious sandbox verdict was issued
- No malware-exclusive MITRE techniques were observed
- The fully covered contacted-host lookup had no cached malicious or suspicious match
- No inspected child was confirmed malicious
- No external intelligence rules or database hits were returned
- 18/75 antivirus detections
- Five independent high-trust malicious votes
- Mikey label repeated by BitDefender, Emsisoft, and GData
- Tax-document-themed archive containing a PE executable
- Executable launched from a temporary directory
- Outbound HTTPS connection to asdopdkdz.cn:8443
Quarantine or delete the ZIP without extracting it, and keep endpoint protection enabled. If the embedded executable ran, isolate the device and investigate processes, persistence, credentials, and network activity.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete18 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 2 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 1MITRE ATT&CK techniques
- 1spawned processes
- 3network contacts
- 0filesystem & mutex artifacts
What this file does
Observed actions and their security significance
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
2026-10-06.Tax Documents_4202.zip
33783d41e82040527bc278544cc09877f64fe7bf51387a10532623cfbe0f6d61
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\2026-10-06.Tax Documents.exe"
02Isolated runtime analysis
Files
Created or changed
- Dropped fileDerived
e2958c256bf1d27f0bf47fe414047feda956eb35aafdbb3bd5c8b5519659d3f3
No child-file verdict was available.
03Dropped-file analysis
Network
Hosts contacted
- Contacted hostObserved
asdopdkdz.cn
Contact observed during runtime.
04Isolated runtime analysis - Contacted hostObserved
45.64.52.195
Contact observed during runtime.
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- asdopdkdz.cn
- 45.64.52.195
- https://asdopdkdz.cn:8443/
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- e2958c256bf1d27f0bf4…59d3f3Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 18 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
18 of 75 antivirus engines flagged the file, including ALYac and Arcabit.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: 2026-10-06.Tax Documents_4202.zip — 33783d41e82040527bc278544cc09877f64fe7bf51387a10532623cfbe0f6d61
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\<USER>\AppData\Local\Temp\2026-10-06.Tax Documents.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Dropped file: e2958c256bf1d27f0bf47fe414047feda956eb35aafdbb3bd5c8b5519659d3f3 — No child-file verdict was available.
ProvenanceDerivedSourceDropped-file analysisObserved at - 06
Contacted host: asdopdkdz.cn — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 45.64.52.195 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
18 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 18 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- 2026-10-06.Tax Documents_4202.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 73.2 KB
- Last analyzed
- Oct 6, 2026, 10:02 AM UTC
33783d41e82040527bc278544cc09877f64fe7bf51387a10532623cfbe0f6d61Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is 2026-10-06.Tax Documents_4202.zip a virus?
What is 2026-10-06.Tax Documents_4202.zip?
How many antivirus engines detected 2026-10-06.Tax Documents_4202.zip?
What should I do if I already opened or extracted 2026-10-06.Tax Documents_4202.zip?
How do I remove 2026-10-06.Tax Documents_4202.zip?
What kind of malware is 2026-10-06.Tax Documents_4202.zip?
What is the SHA-256 hash of 2026-10-06.Tax Documents_4202.zip?
How up to date is this analysis of 2026-10-06.Tax Documents_4202.zip?
Community
Member reviews and reports for this exact file hash.