Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 fd94e76ad953daa3…

MALICIOUS

Archive / .ZIP

12.50 MB
MD5: 5942e0bd15ecd25eac5223e9f40f0f36 SHA-1: fa87023b7a0e0333a1e886e283cc3e76ad5ab894 SHA-256: fd94e76ad953daa3928c17954ff178a8631ef3cacdf3fd523ba5b405bce4530f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is a ZIP archive that exceeded its entry limit during static analysis, indicating a large number of contained files. One of these files was identified as malicious, suggesting the archive's purpose is to deliver malware. The specific nature of the malicious member is not detailed, but its presence within an archive points to a delivery mechanism.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.