Malwagon
TXT
benign-hello.txt File Analysis · submitted Sep 7, 2026 17:07 · 201.0 B
Clean0 Completed Public
Get sample Report Sign in

Clean

0/100

Nothing scored against this sample. A run reads as suspicious from 35.

Clean0-34 Suspicious35-69 Malicious70-100

Why this verdict

Every layer that ran completed without scoring anything against this sample.

Analysis layers

Static ran no points
Dynamic not selected
Threat intel ran no points
AI ran no points

Sample

TypeFile
MIMEtext/plain

Structure

What the file is made of: headers, imports, how it was built and whether it was signed.

Signature
Format: plain text[LF]
Not packed
Identity
File
typeASCII text
size201.0 B
entropy4.1744
Packing
Not packed
The file's code is readable on disk - nothing is compressed or encrypted around it.
0/100
packer confidence
Static analysis reads this file directly Nothing is hiding the code from a static pass, so what the file contains is what the report shows.
Indicators weighed

Packer detection looks at a program's entry point, sections and entropy. This file is not a program image, so there was nothing of that kind to assess.

File content

3 lines · 201 bytes

The sample verbatim, shown as inert text - nothing here is interpreted by this page.

This file is a benign integration test artifact for Malwagon.
It contains no code and performs no action. Its only purpose is to
prove that a submission, a poll and a report retrieval work end to end.

Extracted strings

showing 3
  • This file is a benign integration test artifact for Malwagon.
  • It contains no code and performs no action. Its only purpose is to
  • prove that a submission, a poll and a report retrieval work end to end.

Stack and decoded strings were not recovered: this file format is not eligible for string emulation. Only literal strings present in the file are listed above.

Dynamic analysis was not run

This scan was submitted without the dynamic layer, so nothing was detonated. Nothing here is a statement about the sample.

Dynamic analysis was not run

This scan was submitted without the dynamic layer, so no traffic was captured. Nothing here is a statement about the sample.

Process tree

What ran during the detonation, and what each process did. Select a node to see the activity attributed to it.

No processes were captured

This run recorded no process activity. A hash lookup and a URL analysis never open a Windows VM, and a detonation that produced no telemetry says so on the report.

0Mechanisms found
90Methods in catalogue
0ATT&CK techniques
NONEHighest severity

Established mechanisms

clean

Nothing established - but nothing ran

Persistence is normally proven by watching a sample write to an auto-start location. This scan had no dynamic layer, so the 90 methods below were only checked against the file's static content.

Detection coverage

0 / 90

The auto-start methods this platform can detect, grouped by family. This scan had no dynamic layer, so none of them were watched - the rows below say what CAN be detected, not what was.

Logon & Startup 22 not watched
  • Active Setup Installed Component T1547.014 not watched
  • Explorer Delay-Load Object T1547.001 not watched
  • Explorer Run Key T1547.001 not watched
  • Explorer SharedTaskScheduler T1547.001 not watched
  • Group Policy Extension DLL T1547.004 not watched
  • Group Policy Run Key T1547.001 not watched
  • Logon Script T1037.001 not watched
  • RDP WDS Startup Program T1547.001 not watched
  • Registry Run Key T1547.001 not watched
  • Registry RunEx Key T1547.001 not watched
  • Registry RunOnce Key T1547.001 not watched
  • Registry RunOnceEx Key T1547.001 not watched
  • Registry RunServices Key T1547.001 not watched
  • Startup Folder Item T1547.001 not watched
  • Startup Folder Redirection T1547.001 not watched
  • Terminal Services Initial Program T1547.001 not watched
  • Winlogon GINA DLL T1547.004 not watched
  • Winlogon MPNotify Value T1547.004 not watched
  • Winlogon Notify Package T1547.004 not watched
  • Winlogon Shell Value T1547.004 not watched
  • Winlogon Taskman Value T1547.004 not watched
  • Winlogon Userinit Value T1547.004 not watched
Services & Tasks 9 not watched
  • BITS Job T1197 not watched
  • Print Monitor DLL T1547.010 not watched
  • Print Processor DLL T1547.012 not watched
  • Scheduled Task T1053.005 not watched
  • Scheduled Task Registry Implant T1053.005 not watched
  • Service Control Manager Security Descriptor T1574.011 not watched
  • Service DLL Hijack T1543.003 not watched
  • Time Provider DLL T1547.003 not watched
  • Windows Service Creation T1543.003 not watched
Execution Hijack 17 not watched
  • .NET Managed Debugger T1546.012 not watched
  • Accessibility Tool Hijack T1546.008 not watched
  • AeDebug Postmortem Debugger T1546.012 not watched
  • App Paths Hijack T1546.012 not watched
  • Application Shim Database T1546.011 not watched
  • Boot Verification Program T1547.002 not watched
  • Command Processor AutoRun T1546.011 not watched
  • Explorer Load Value T1547.001 not watched
  • Explorer MyComputer Tool Hijack T1546.001 not watched
  • Registry Image File Execution Options T1546.012 not watched
  • Screensaver Hijack T1546.002 not watched
  • Setup ErrorHandler Script T1546 not watched
  • Shell Open Command Hijack T1546.001 not watched
  • SilentProcessExit Monitor T1546.012 not watched
  • Telemetry Controller Command T1546.015 not watched
  • WER ReflectDebugger T1546.012 not watched
  • Windows Error Reporting Debugger T1546.012 not watched
DLL Load Order 12 not watched
  • .NET CLR Profiler DLL T1574.012 not watched
  • .NET Startup Hook DLL T1574 not watched
  • AppCert DLLs T1546.009 not watched
  • AppInit DLLs T1546.010 not watched
  • AutodialDLL Winsock Injection T1546.006 not watched
  • DLL Search-Order Hijack T1574.001 T1574.002 not watched
  • DNS Server Plugin DLL T1574.001 not watched
  • HTML Help Helper DLL T1546 not watched
  • KnownDLLs Manipulation T1574.001 not watched
  • Natural Language Platform DLL Override T1546 not watched
  • Netsh Helper DLL T1546.007 not watched
  • Winsock Layered Service Provider T1546.006 not watched
COM & Browser 6 not watched
  • Browser Extension T1176 not watched
  • Browser Helper Object T1176 not watched
  • COM Server Hijack T1546.015 not watched
  • HTML Help COM Object Hijack T1546.015 not watched
  • Shell Context Menu Handler T1546.001 not watched
  • Shell Extension Handler T1546.001 not watched
Security Providers & Accounts 11 not watched
  • Account RID Hijack T1098 not watched
  • AMSI Provider T1562.001 not watched
  • Credential Provider T1547.014 not watched
  • DSRM Admin Logon Backdoor T1556 not watched
  • Hidden Local Account T1136.001 not watched
  • LSA Authentication Package T1547.002 not watched
  • LSA Extension DLL T1547.005 not watched
  • LSA Notification Package T1547.005 not watched
  • LSA Security Package T1547.005 not watched
  • Network Provider DLL T1556.008 not watched
  • Security Support Provider T1547.005 not watched
Scripting & Applications 9 not watched
  • Netsh Port Proxy T1090.001 not watched
  • Office Add-in T1137.006 not watched
  • Office Executable Sideload T1574.002 not watched
  • Office Startup Template T1137.001 not watched
  • Office Test Key T1137.002 not watched
  • Power Automate Flow T1546 not watched
  • PowerShell Profile T1546.013 not watched
  • Windows Terminal Startup Action T1546 not watched
  • WMI Event Subscription T1546.003 not watched
Boot & Firmware 4 not watched
  • BootExecute Native Image T1547.002 not watched
  • PlatformExecute Native Image T1547.002 not watched
  • SetupExecute Native Image T1547.002 not watched
  • UEFI / Bootkit Artifact T1542.003 T1542.001 not watched

Dynamic analysis was not run

File and registry activity is recorded while the sample executes. This scan was submitted without the dynamic layer, so nothing was recorded - which says nothing about what the sample would touch.

11 answered no 12 had nothing to check
0Sources with a hit
11Sources queriedof 23 available
486.1kFeed records
0Could not answer

File reputation

7 clear
SourceChecksResultDetailFeed
MalwareBazaar File hash not found - live lookup
VirusTotal File hash not found - live lookup
filescan.io File hash no detections - live lookup
MalwareBazaar hash feed File hash clean not in feed 2,535 records
51 minutes ago
MalwareBazaar ransomware feed File hash clean not in feed 8,271 records
5 hours ago
ThreatFox hash IOCs File hash clean not in feed 1,632 records
52 minutes ago
URLhaus payload hashes File hash clean not in feed 1,474 records
51 minutes ago

Hash lookups only - the sample itself is never uploaded to any third party.

Network indicators

0 clear
SourceChecksResultDetailFeed
blocklist.de IP / domain / URL not checked no IP, domain or URL observed to check 24.5k records
51 minutes ago
CINS Army IP / domain / URL not checked no IP, domain or URL observed to check 15k records
51 minutes ago
Emerging Threats IP / domain / URL not checked no IP, domain or URL observed to check 580 records
51 minutes ago
Feodo Tracker IP / domain / URL not checked no IP, domain or URL observed to check 5 records
52 minutes ago
IPsum IP / domain / URL not checked no IP, domain or URL observed to check 17.7k records
51 minutes ago
Phishing.Database IP / domain / URL not checked no IP, domain or URL observed to check 391.1k records
5 hours ago
ThreatFox IP / domain / URL not checked no IP, domain or URL observed to check 1,632 records
52 minutes ago
URLhaus IP / domain / URL not checked no IP, domain or URL observed to check 5,155 records
51 minutes ago

TLS fingerprints

0 clear
SourceChecksResultDetailFeed
abuse.ch JA3 blocklist JA3 / JA4 not checked no TLS client fingerprint observed 97 records
17 hours ago
SSL blocklist JA3 / JA4 not checked no TLS client fingerprint observed 10.7k records
52 minutes ago

Detection rules

1 clear
SourceChecksResultDetailFeed
YARA rules Sample content clean no rule matched 110 records
52 minutes ago
Sigma rules Behavior log not checked no behavior log to match 2,275 records
23 hours ago

Tooling catalogs

3 clear
SourceChecksResultDetailFeed
LOLBootloaders File hash clean not a known vulnerable bootloader 520 records
51 minutes ago
LOLDrivers File hash clean not a known vulnerable driver 2,306 records
52 minutes ago
LOLRMM Names and domains clean 1 name/domain indicator checked, no remote-management tooling 322 records
51 minutes ago
LOLBAS Process image paths not checked no process image path observed to check 244 records
52 minutes ago

Analyst narrative

The analysis indicates that the sandbox environment did not execute the sample, as evidenced by the `run_integrity.failed` being true and `run_integrity.reached_sample` being false. This means that the analysis agent never started, and therefore, no behavior or capabilities could be observed from the file. As a result, there is no evidence to support any conclusions regarding the file's potential malicious activity or its characteristics. The verdict is that the run is not evidence about the file.

Evasion analysis

No evasive checkpoints detected.

0 malicious 0 suspicious 2 info

File indicators

2
SeverityTypeIndicatorDescription
info sample_sha256 e36ee351fe280124ef9fb009364bb32ec7996e38f1dc6df4c192b6e3af631851 Submitted sample (SHA256)
info sample_md5 0eedf68983768ae2d8a36880c8042cd9 Submitted sample (MD5)

Generated rules

YARA: auto_file_2366_yara

Auto-generated
rule auto_file_2366_yara
{
    meta:
        description = "Auto-generated from scan 2366"
        author = "sandbox auto-generator"
        anchors = "3 independent regions"
    strings:
        $s0 = "prove that a submission, a poll and a report retrieval work end to end." ascii fullword
        $s1 = "This file is a benign integration test artifact for Malwagon." ascii fullword
        $s2 = "It contains no code and performs no action. Its only purpose is to" ascii fullword
    condition:
        filesize < 65536 and all of them
}

Extracted files

What came out of the sample: unpacked payloads, carved objects and captured memory. Each one is stored by content hash, so the same object extracted twice is the same row.

No extracted files

Nothing was unpacked or carved out of this sample. Packed samples, documents with embedded objects and installers are the ones that usually produce artifacts here.

Export & download

/s/2366

The report downloads - PCAP and the SIEM/TIP exports - are a paid-plan feature. Sign in with a paid plan to export this report.

AI analysis report

An enterprise report with an AI-written executive summary, threat assessment, kill chain, and recommendations, plus the derived evidence (verdict, MITRE ATT&CK, network, file modifications, dropped files, IOCs) and screenshots. The AI narrative is built from derived analysis data only, so the raw sample never leaves the host (no-upload and AI-boundary preserved).

Public analyses of this file

1 run
SubmittedEnvironmentVerdictScore
2026-09-07 17:07 Shown below Static analysis Clean 0/100