Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 f76db26e588830c6…

MALICIOUS

Archive / .ZIP

21.15 MB
MD5: 9ba787f47e29903210f6a6e7b77f78fd SHA-1: bb46a162a1b4d32e4ce12f7c848a862f6075273b SHA-256: f76db26e588830c65ab57cd49b6dfee50ad6c4ba89575b1549a056bbfcdf8402
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1071.001 Web Protocols

The sample is a ZIP archive that exceeded its entry limit during static analysis, indicating a potentially large or complex structure. Crucially, it contains a member identified as malicious with a high risk score. This suggests the archive is a delivery mechanism for a malicious executable.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.