Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 fa23e2e4900e9e5c…

MALICIOUS

Archive / .ZIP

12.05 MB First seen: 2026-05-13
MD5: 83d3e72535bbcfec646e625fd26f5e4e SHA-1: 21290268e781ff6f2fb7aab1c018d3eef108765d SHA-256: fa23e2e4900e9e5c020aca243eb997ec3da460000c54e03f48c16ba42bdc27ca
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The sample is a ZIP archive that contains a malicious PDF file. The PDF likely uses embedded URLs to download and execute a secondary payload, as indicated by the 'ARCHIVE_CHILD_MALICIOUS' heuristic and the presence of numerous unknown reputation URLs. The specific attack pattern is likely a lure to trick the user into opening the PDF, which then initiates the malicious download. No scripts were extracted from this sample.

Heuristics 3

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://efxhifatwe.com/nte/trest9/eH6bd9a6a6V0100f060006R00000000102T7f87d555201l0409K360cfdcf In document body
    • http://ajxpeehuvpcv.com/nte/TREST1.html/eH4c5da2e2V0100f060006R84f8f7dc102T93febc5d201l0019Ka9a46d98In document body
    • http://kachmp3.cn/login/exe.phpIn document body
    • http://91.216.11.157/xx3/l.php?i=4In document body
    • http://mysterio.info/cgi-bin/worker/z006106201r0019Rb103bf3eXb49c37d2Y775727f7Z0100f060In document body
    • http://beancountercity.in/cgi-bin/uiq/eH627ed5e0V0100f060006Re2b845b9106T1a3e3961201l0019In document body
    • http://cefela.info/page/news.php/n002106201r0409Rd8685d19X61e7ec1fY1f8f91a2Z0100f080In document body
    • http://googleinru.in/cgi-bin/etn/z002106201r0019Re45d2d60X828aa88fY23488278Z0100f060In document body
    • http://betapopup.com/cgi-bin/cliche/n002106203r000cRcc61c9f6Xc88d6411Y4524a21cZ0100f060In document body
    • http://googleinru.in/cgi-bin/etn/z002106201r0019R940c337cX8ff1e290Y24b1205eZ0100f060In document body
    • http://webgetwise.com/cgi-bin/153/n002106203r000cXdc441dfcY7538bdffZ0100f060In document body
    • http://frQGo3Mt.elpwy/psCPJmIn document body
    • http://93.174.93.11/~delmonca/u/load.phpIn document body
    • http://sky1wezz3xo.com/ww/l.php?i=16In document body
    • http://qzeo-ad.info/cgi-bin/gjj/eH4a39b196V0100f060006Ra2f23783102Td198c861201l0019In document body
    • http://diarqsjdncz.com/nte/GNH11.asp/yH65c15151V0100f060006R84224d52102Te096a6ed203l000cIn document body
    • http://googleinru.in/cgi-bin/etn/z002106201r0019R69711430Xb4b58750Y04274ad6Z0100f060In document body
    • http://googleinru.in/cgi-bin/etn/z002106201r0019R9b46c741X98021beaY153a315eZ0100f060In document body
    • http://gowinsc.info/cgi-bin/mode/z00a102801r0007J11000601R3d1126efX9453a6e4Y785c9dd0Z03008f35In document body
    • http://click-reklama.com/cgi-bin/plt/z002106201r0019R31f2c8c7Xcac7a230Y1122e4d6Z0100f060In document body
    • http://qhjcwfbqthr.com/nte/prox.exe/eH50d153a6V0100f060006R83c4b01e102T89b57690203l000cK755a514bIn document body
    • http://91.216.11.157/xx3/l.php?i=5In document body
    • http://beancountercity.in/cgi-bin/uiq/eH336ff178V0100f060006Rab597329102T51afe7be203l0019In document body
    • http://greenlpl.com/exe.php?spl=PDF%20(printdIn document body
    • http://greenlpl.com/exe.php?spl=PDF%20(EmailInfoIn document body
    • http://greenlpl.com/exe.php?spl=PDF%20(util_printfIn document body
    • http://greenlpl.com/exe.php?spl=PDF%20(GetIconIn document body
    • http://kbclyokkthr.com/nte/INDEPHANDLER.py/eU230d9c2eH4054b03dV0100f060006Rdedb4260102T1d1128ef203l000cKfbd8d5c6In document body
    • http://chura.pl/hlp/getexe.php?spl=pdfIn document body
    • http://click-reklama.com/cgi-bin/plt/z002106201r0019R96c20059X0519e9f6Y13dc40e3Z0100f060In document body
    • http://click-reklama.com/cgi-bin/plt/z002106201r0019Rc4f30710Xc425507fY0773b5d9Z0100f060In document body
    • http://kozzz.in/2/load.php?spl=pdf_newIn document body
    • http://kozzz.in/2/load.php?spl=pdf_packIn document body
    • http://gold-smerch.cn/img1/getexe.phpIn document body
    • http://asspuc.com/us/sid1/load.php?spl=pdf_2012In document body
    • http://polygraphy-p.ru/elexp/getexe.php?spl=pdf_emailIn document body
    • http://polygraphy-p.ru/elexp/getexe.php?spl=pdf_prntfIn document body
    • http://polygraphy-p.ru/elexp/getexe.php?spl=pdf_icnIn document body
    • http://polygraphy-p.ru/elexp/getexIn document body
    • http://beancountercity.in/cgi-bin/uiq/eH5e21c0f8V0100f060006R7bbfe3ca102Tbc87ce0f201l0019In document body
    • http://193.43.134.58/pb3/l.php?i=4In document body
    • http://botiire.com/info/sun.html/n002106204r0409R6d713d81X09306f89Y2bc571e2Z0100f060In document body
    • http://jlixup.info/cgi-bin/plt/eH1bc3362aV01001f50006R6ba960a6106Tc97c06a7201l0019In document body
    • http://estguard.com/cgi-bin/ca7/z002106201r0019Rb97250fdXb26d6571Y4bb3a2a8Z0100f060In document body
    • http://vgeohemef.info/cgi-bin/ae/eH3e71e7dcV0100f060006R376948c7102Tc4ba9ecb201l0019In document body
    • http://googleinru.in/cgi-bin/etn/z006106201r0019R97f3b4e5Xd92de303Y4919599eZ0100f060In document body
    • http://beancountercity.in/cgi-bin/uiq/eH18fedbdcV0100f060006R18b17df4102T43e37a12203l0019In document body
    • http://click-reklama.com/cgi-bin/plt/z002106201r0019R8038b82dXdb4c0a44Y21e53336Z0100f060In document body
    • http://www.xfa.org/schema/xfa-template/2.5/In document body
    • http://ns.adobe.com/xdp/In document body
    +11 more URL(s)