Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 207ec6ecb837c292…

MALICIOUS

Archive / .ZIP

11.48 MB
MD5: 6804dfd2d6306500399879a33636d8a5 SHA-1: e6d590efdc2afa5d21bad3bd6e824e964f92333c SHA-256: 207ec6ecb837c292d150bbbe8cde6cc1d19b23bde872cd697bc4ed3dc4e64c21
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The archive file exceeded the entry limit during static analysis, indicating a large number of contained files. One of the archive members was identified as malicious, suggesting this archive is a container for delivering further malicious content. The specific attack pattern is likely a form of spearphishing attachment where the archive is sent to a victim.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.