Windows Analysis Report
MDE_File_Sample_4e3ac7a53f0f368b9218bf717162d5e073a0f7df.zip

Overview

General Information

Sample name: MDE_File_Sample_4e3ac7a53f0f368b9218bf717162d5e073a0f7df.zip
Analysis ID: 1446151
MD5: 05d4307c0410d0f2ba15858d0300d7ab
SHA1: 64d44f0112f8e1a3cb3a2c76d10c796aad8f5165
SHA256: 7634ab3dd7c6dfb1678aa1ff24049f5d39261d71c6aaf63ba635b1026d0df9a4

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)

Classification

Source: classification engine Classification label: clean0.winZIP@1/0@0/0
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: MDE_File_Sample_4e3ac7a53f0f368b9218bf717162d5e073a0f7df.zip Static file information: File size 1699270 > 1048576
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
⊘No contacted IP infos