Windows Analysis Report
sample-1430485-762a7d10037b2a67e3e38aa9ab436425.zip

Overview

General Information

Sample name: sample-1430485-762a7d10037b2a67e3e38aa9ab436425.zip
Analysis ID: 1430488
MD5: b3404d0169945fd1b67157b75fd15052
SHA1: 4e427476d057d93d3714b62b428a1f74a3855245
SHA256: bb8d68e1907c79f81f3bdf292fadcde333e90ba338848df3c56c5fdcd3a98eb2

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)

Classification

Source: classification engine Classification label: clean0.winZIP@1/0@0/0
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos