Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 cc9f17b1156c1e13…

MALICIOUS

Archive / .ZIP

32.19 MB
MD5: fa59322a8569b52a81267154334532bf SHA-1: 9386fae6f7c49cfef8e90c09a88e548a27d9e3f0 SHA-256: cc9f17b1156c1e1348ef78c63ca21a0e0a8ec24d606c4250e13e94d55138256b
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a ZIP archive that exceeded the entry limit during static analysis, indicating a large number of contained files. One of the archive members, identified by SHA256 hash f208035f8c4e4b297efe4f438f192e11da745866112a5b3559a56f6ff233bff6, was flagged as malicious with a high risk score. This suggests the archive is likely a container for delivering a malicious payload.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.