Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 9fd28b0aaa7753f3…

MALICIOUS

Archive / .ZIP

23.60 MB
MD5: c36ebbca8d8ecfd0738161516f23e719 SHA-1: 09a1ff07ddcede0778da7583617a9028329e4be7 SHA-256: 9fd28b0aaa7753f3486f7c03db53b6fd4e3cecbf77c4cf2bcbb12839ace93cda
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a ZIP archive that exceeds the entry limit, indicating a large number of contained files. One of these contained files, identified by SHA256 hash 8e0ba2587e3696cd743e81bfb34c4036ebbf0f363b89aee7c528e180bb6ef26e, was flagged as malicious. This suggests a multi-stage attack where the initial archive serves to deliver a secondary malicious payload.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.