Windows Analysis Report
ae_3_5_7_web_e5b0d3c29e.zxp

Overview

General Information

Sample name: ae_3_5_7_web_e5b0d3c29e.zxp
Analysis ID: 1467033
MD5: 01f25257f2834a361271e09996ae8c9f
SHA1: 6786aa5c23bb07603b0d2fa9b47008f0872de73d
SHA256: bbbb2b3c9294b7f8b291e136786bee7e47df3e993ebd6703f8fffccbc4ead435

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)

Classification

Source: classification engine Classification label: clean0.winZXP@1/0@0/0
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: ae_3_5_7_web_e5b0d3c29e.zxp Static file information: File size 2426727 > 1048576
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos