Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 52a9bdcf8c2238ae…

MALICIOUS

Archive / .ZIP

25.36 MB
MD5: bcbc082573fbbde993a4d3e8648e6d9e SHA-1: 379ddf145ff85505cd9416051526f6824844afa3 SHA-256: 52a9bdcf8c2238ae876de92b4b88187a7e3adcf015a16ceab96b871d4530f21d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The archive file exceeded its entry limit, suggesting an attempt to hide malicious content. A critical heuristic identified a nested malicious member, identified by its SHA256 hash. This indicates a multi-stage attack where the archive serves as a container for further malicious payloads.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.