Clean
0/100
Nothing scored against this sample. A run reads as suspicious from 35.
Why this verdict
Every layer that ran completed without scoring anything against this sample.
Analysis layers
Structure
What the file is made of: headers, imports, how it was built and whether it was signed.
Sections & resources
How the file is laid out in memory, and what is embedded in it: section roles, access rights, entropy and every resource entry.
Signatures & packing
What matched and what is hidden: YARA rules, capa capabilities, family attribution, packer detection, unpacked payloads and recovered configuration.
Strings
The readable content: embedded secrets, flagged strings and everything extraction recovered.
Code
What the sample would execute: the emulated API call sequence, and the disassembled entry point.
Packer detection looks at a program's entry point, sections and entropy. This file is not a program image, so there was nothing of that kind to assess.
File content
3 lines · 201 bytesThe sample verbatim, shown as inert text - nothing here is interpreted by this page.
This file is a benign integration test artifact for Malwagon. It contains no code and performs no action. Its only purpose is to prove that a submission, a poll and a report retrieval work end to end.
Extracted strings
showing 3- This file is a benign integration test artifact for Malwagon.
- It contains no code and performs no action. Its only purpose is to
- prove that a submission, a poll and a report retrieval work end to end.
No strings match this filter.
Stack and decoded strings were not recovered: this file format is not eligible for string emulation. Only literal strings present in the file are listed above.
Nothing in this view
This sample produced no results for this part of the static analysis.
Dynamic analysis was not run
This scan was submitted without the dynamic layer, so nothing was detonated. Nothing here is a statement about the sample.
Dynamic analysis was not run
This scan was submitted without the dynamic layer, so no traffic was captured. Nothing here is a statement about the sample.
Process tree
What ran during the detonation, and what each process did. Select a node to see the activity attributed to it.
No processes were captured
This run recorded no process activity. A hash lookup and a URL analysis never open a Windows VM, and a detonation that produced no telemetry says so on the report.
Established mechanisms
cleanNothing established - but nothing ran
Persistence is normally proven by watching a sample write to an auto-start location. This scan had no dynamic layer, so the 90 methods below were only checked against the file's static content.
Detection coverage
0 / 90The auto-start methods this platform can detect, grouped by family. This scan had no dynamic layer, so none of them were watched - the rows below say what CAN be detected, not what was.
- Active Setup Installed Component T1547.014 not watched
- Explorer Delay-Load Object T1547.001 not watched
- Explorer Run Key T1547.001 not watched
- Explorer SharedTaskScheduler T1547.001 not watched
- Group Policy Extension DLL T1547.004 not watched
- Group Policy Run Key T1547.001 not watched
- Logon Script T1037.001 not watched
- RDP WDS Startup Program T1547.001 not watched
- Registry Run Key T1547.001 not watched
- Registry RunEx Key T1547.001 not watched
- Registry RunOnce Key T1547.001 not watched
- Registry RunOnceEx Key T1547.001 not watched
- Registry RunServices Key T1547.001 not watched
- Startup Folder Item T1547.001 not watched
- Startup Folder Redirection T1547.001 not watched
- Terminal Services Initial Program T1547.001 not watched
- Winlogon GINA DLL T1547.004 not watched
- Winlogon MPNotify Value T1547.004 not watched
- Winlogon Notify Package T1547.004 not watched
- Winlogon Shell Value T1547.004 not watched
- Winlogon Taskman Value T1547.004 not watched
- Winlogon Userinit Value T1547.004 not watched
- BITS Job T1197 not watched
- Print Monitor DLL T1547.010 not watched
- Print Processor DLL T1547.012 not watched
- Scheduled Task T1053.005 not watched
- Scheduled Task Registry Implant T1053.005 not watched
- Service Control Manager Security Descriptor T1574.011 not watched
- Service DLL Hijack T1543.003 not watched
- Time Provider DLL T1547.003 not watched
- Windows Service Creation T1543.003 not watched
- .NET Managed Debugger T1546.012 not watched
- Accessibility Tool Hijack T1546.008 not watched
- AeDebug Postmortem Debugger T1546.012 not watched
- App Paths Hijack T1546.012 not watched
- Application Shim Database T1546.011 not watched
- Boot Verification Program T1547.002 not watched
- Command Processor AutoRun T1546.011 not watched
- Explorer Load Value T1547.001 not watched
- Explorer MyComputer Tool Hijack T1546.001 not watched
- Registry Image File Execution Options T1546.012 not watched
- Screensaver Hijack T1546.002 not watched
- Setup ErrorHandler Script T1546 not watched
- Shell Open Command Hijack T1546.001 not watched
- SilentProcessExit Monitor T1546.012 not watched
- Telemetry Controller Command T1546.015 not watched
- WER ReflectDebugger T1546.012 not watched
- Windows Error Reporting Debugger T1546.012 not watched
- .NET CLR Profiler DLL T1574.012 not watched
- .NET Startup Hook DLL T1574 not watched
- AppCert DLLs T1546.009 not watched
- AppInit DLLs T1546.010 not watched
- AutodialDLL Winsock Injection T1546.006 not watched
- DLL Search-Order Hijack T1574.001 T1574.002 not watched
- DNS Server Plugin DLL T1574.001 not watched
- HTML Help Helper DLL T1546 not watched
- KnownDLLs Manipulation T1574.001 not watched
- Natural Language Platform DLL Override T1546 not watched
- Netsh Helper DLL T1546.007 not watched
- Winsock Layered Service Provider T1546.006 not watched
- Browser Extension T1176 not watched
- Browser Helper Object T1176 not watched
- COM Server Hijack T1546.015 not watched
- HTML Help COM Object Hijack T1546.015 not watched
- Shell Context Menu Handler T1546.001 not watched
- Shell Extension Handler T1546.001 not watched
- Account RID Hijack T1098 not watched
- AMSI Provider T1562.001 not watched
- Credential Provider T1547.014 not watched
- DSRM Admin Logon Backdoor T1556 not watched
- Hidden Local Account T1136.001 not watched
- LSA Authentication Package T1547.002 not watched
- LSA Extension DLL T1547.005 not watched
- LSA Notification Package T1547.005 not watched
- LSA Security Package T1547.005 not watched
- Network Provider DLL T1556.008 not watched
- Security Support Provider T1547.005 not watched
- Netsh Port Proxy T1090.001 not watched
- Office Add-in T1137.006 not watched
- Office Executable Sideload T1574.002 not watched
- Office Startup Template T1137.001 not watched
- Office Test Key T1137.002 not watched
- Power Automate Flow T1546 not watched
- PowerShell Profile T1546.013 not watched
- Windows Terminal Startup Action T1546 not watched
- WMI Event Subscription T1546.003 not watched
- BootExecute Native Image T1547.002 not watched
- PlatformExecute Native Image T1547.002 not watched
- SetupExecute Native Image T1547.002 not watched
- UEFI / Bootkit Artifact T1542.003 T1542.001 not watched
Dynamic analysis was not run
File and registry activity is recorded while the sample executes. This scan was submitted without the dynamic layer, so nothing was recorded - which says nothing about what the sample would touch.
File reputation
7 clear| Source | Checks | Result | Detail | Feed |
|---|---|---|---|---|
| MalwareBazaar | File hash | not found | - | live lookup |
| VirusTotal | File hash | not found | - | live lookup |
| filescan.io | File hash | no detections | - | live lookup |
| MalwareBazaar hash feed | File hash | clean | not in feed | 2,535 records 51 minutes ago |
| MalwareBazaar ransomware feed | File hash | clean | not in feed | 8,271 records 5 hours ago |
| ThreatFox hash IOCs | File hash | clean | not in feed | 1,632 records 52 minutes ago |
| URLhaus payload hashes | File hash | clean | not in feed | 1,474 records 51 minutes ago |
Hash lookups only - the sample itself is never uploaded to any third party.
Network indicators
0 clear| Source | Checks | Result | Detail | Feed |
|---|---|---|---|---|
| blocklist.de | IP / domain / URL | not checked | no IP, domain or URL observed to check | 24.5k records 51 minutes ago |
| CINS Army | IP / domain / URL | not checked | no IP, domain or URL observed to check | 15k records 51 minutes ago |
| Emerging Threats | IP / domain / URL | not checked | no IP, domain or URL observed to check | 580 records 51 minutes ago |
| Feodo Tracker | IP / domain / URL | not checked | no IP, domain or URL observed to check | 5 records 52 minutes ago |
| IPsum | IP / domain / URL | not checked | no IP, domain or URL observed to check | 17.7k records 51 minutes ago |
| Phishing.Database | IP / domain / URL | not checked | no IP, domain or URL observed to check | 391.1k records 5 hours ago |
| ThreatFox | IP / domain / URL | not checked | no IP, domain or URL observed to check | 1,632 records 52 minutes ago |
| URLhaus | IP / domain / URL | not checked | no IP, domain or URL observed to check | 5,155 records 51 minutes ago |
TLS fingerprints
0 clear| Source | Checks | Result | Detail | Feed |
|---|---|---|---|---|
| abuse.ch JA3 blocklist | JA3 / JA4 | not checked | no TLS client fingerprint observed | 97 records 17 hours ago |
| SSL blocklist | JA3 / JA4 | not checked | no TLS client fingerprint observed | 10.7k records 52 minutes ago |
Detection rules
1 clear| Source | Checks | Result | Detail | Feed |
|---|---|---|---|---|
| YARA rules | Sample content | clean | no rule matched | 110 records 52 minutes ago |
| Sigma rules | Behavior log | not checked | no behavior log to match | 2,275 records 23 hours ago |
Tooling catalogs
3 clear| Source | Checks | Result | Detail | Feed |
|---|---|---|---|---|
| LOLBootloaders | File hash | clean | not a known vulnerable bootloader | 520 records 51 minutes ago |
| LOLDrivers | File hash | clean | not a known vulnerable driver | 2,306 records 52 minutes ago |
| LOLRMM | Names and domains | clean | 1 name/domain indicator checked, no remote-management tooling | 322 records 51 minutes ago |
| LOLBAS | Process image paths | not checked | no process image path observed to check | 244 records 52 minutes ago |
Analyst narrative
The analysis indicates that the sandbox environment did not execute the sample, as evidenced by the `run_integrity.failed` being true and `run_integrity.reached_sample` being false. This means that the analysis agent never started, and therefore, no behavior or capabilities could be observed from the file. As a result, there is no evidence to support any conclusions regarding the file's potential malicious activity or its characteristics. The verdict is that the run is not evidence about the file.
Evasion analysis
No evasive checkpoints detected.
File indicators
2| Severity | Type | Indicator | Description |
|---|---|---|---|
| info | sample_sha256 | e36ee351fe280124ef9fb009364bb32ec7996e38f1dc6df4c192b6e3af631851 | Submitted sample (SHA256) |
| info | sample_md5 | 0eedf68983768ae2d8a36880c8042cd9 | Submitted sample (MD5) |
Generated rules
YARA: auto_file_2366_yara
Auto-generatedrule auto_file_2366_yara
{
meta:
description = "Auto-generated from scan 2366"
author = "sandbox auto-generator"
anchors = "3 independent regions"
strings:
$s0 = "prove that a submission, a poll and a report retrieval work end to end." ascii fullword
$s1 = "This file is a benign integration test artifact for Malwagon." ascii fullword
$s2 = "It contains no code and performs no action. Its only purpose is to" ascii fullword
condition:
filesize < 65536 and all of them
}Extracted files
What came out of the sample: unpacked payloads, carved objects and captured memory. Each one is stored by content hash, so the same object extracted twice is the same row.
No extracted files
Nothing was unpacked or carved out of this sample. Packed samples, documents with embedded objects and installers are the ones that usually produce artifacts here.
Export & download
/s/2366The report downloads - PCAP and the SIEM/TIP exports - are a paid-plan feature. Sign in with a paid plan to export this report.
AI analysis report
An enterprise report with an AI-written executive summary, threat assessment, kill chain, and recommendations, plus the derived evidence (verdict, MITRE ATT&CK, network, file modifications, dropped files, IOCs) and screenshots. The AI narrative is built from derived analysis data only, so the raw sample never leaves the host (no-upload and AI-boundary preserved).
Headers
Body
Headers
Body
You are about to download the raw, live sample. It is real, potentially destructive malware and can harm your machine if opened or run. Only handle it inside an isolated analysis environment.
Delivered as a ZIP encrypted with the password infected so the bytes are never handled unprotected.
Report this analysis
Analysis reports are produced automatically from files, addresses and text submitted by visitors. If this one publishes your material, identifies you, or should not be public for any other reason, tell us why and an administrator will review it.
Public analyses of this file
1 run| Submitted | Environment | Verdict | Score |
|---|---|---|---|
| 2026-09-07 17:07 Shown below | Static analysis | Clean | 0/100 |