Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 fa23e2e4900e9e5c…

MALICIOUS

Archive / .ZIP

12.05 MB
MD5: 83d3e72535bbcfec646e625fd26f5e4e SHA-1: 21290268e781ff6f2fb7aab1c018d3eef108765d SHA-256: fa23e2e4900e9e5c020aca243eb997ec3da460000c54e03f48c16ba42bdc27ca
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The archive file exceeded its entry limit, indicating a large number of contained files. One of the archive members was identified as malicious, suggesting this archive is a container for distributing malware. The specific attack pattern is likely Spearphishing Attachment, as archives are commonly used to deliver malicious payloads.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.