The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.
{
"sha256": "72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a",
"verdict": "suspicious",
"confidence": 60,
"signals": [
"child-processes"
],
"attack": [
"T1059"
],
"children": [
"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\MSBuild.exe",
"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe",
"C:\\argus-vr-agent\\quarantine\\72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a_extracted\\72e3fb64a103033837ee52ff73f5c00b2a8536b363431cd1308e7ce00f26908a.exe"
]
}