Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 1afcc261f672b12d…

MALICIOUS

Archive / .ZIP

10.81 MB
MD5: 375afae464276a8d448c5af43414181c SHA-1: 738deaea8630d48554207359ed6559be4e2f1939 SHA-256: 1afcc261f672b12dc79f211ca33e57c385efbadd148351ebed6e224cb3bb93d0
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a ZIP archive that was flagged as malicious due to containing a malicious member. The archive exceeded the entry limit, indicating a potentially large or complex payload. The malicious member's SHA256 hash is provided as an IOC.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.