Is SMTC-Bridge-v1.0.0.zip safe?
No antivirus engine detected the archive, but one sandbox mapped process injection, LSASS-related activity, defense evasion, and unresolved direct-IP communication.
All 74 antivirus engines returned no detection, including 17 tier-1 engines, and no malicious child or external-intelligence match was found. However, one sandbox recorded potentially offensive techniques and LSASS-related activity, while the contacted IP received no completed reputation check, so execution should be deferred pending source verification.
429dae6322cfdc48cd…6817467cbe68c4Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no detection, including 17 tier-1 engines, and no malicious child or external-intelligence match was found. However, one sandbox recorded potentially offensive techniques and LSASS-related activity, while the contacted IP received no completed reputation check, so execution should be deferred pending source verification.
The archive received no malicious or suspicious detections from 74 antivirus engines, including 17 tier-1 engines. One completed sandbox run nevertheless mapped activity to T1055, T1486, and T1562.001 and surfaced an LSASS-related heuristic. These mappings are concerning but do not prove the precise operation performed, and the sandbox itself produced no malicious verdict. Ten extracted children were inspected without a malicious child, although each child remains unclassified rather than confirmed benign. The observed IP address was not covered by a completed host-reputation check, leaving an important network signal unresolved.
What We Detected
The archive produced 0 detections across 74 antivirus engines, with all 17 tier-1 engines reporting no detection. Research feeds also returned no MalwareBazaar, CIRCL, or YARAify match, and no named malware family was identified.
Threat Behavior
One sandbox run mapped execution to T1055 (Process Injection), T1486 (Data Encrypted for Impact), and T1562.001 (Impair Defenses), while a separate heuristic associated process activity with LSASS. These are material warning signs, but the saved evidence does not establish the exact injection, credential-access, or encryption action, and the sandbox did not issue a malicious verdict. The sample contacted 162.159.36.2 directly; because contactedHosts is unavailable, no complete reputation conclusion can be made for that address. Ten extracted children were inspected without a malicious result, but all remain unclassified.
What To Do Now
Do not run the archive on a production or personal system until its download source and expected publisher are independently verified. Keep endpoint protection enabled, and if testing is necessary, use an isolated disposable environment with network monitoring and obtain deeper analysis of the embedded executable.
Where this verdict could be wrong4 caveats
- The complete 0/74 detection result, including 17 tier-1 engines without detections, weighs strongly against the concerning behavioural mappings.
- behaviour.hasMaliciousSandboxVerdict=false, so the single sandbox did not independently conclude that the execution was malware.
- The T1055 and LSASS heuristics are based on mapped process evidence and do not establish the exact access or injection method.
- No YARAify, MalwareBazaar, or CIRCL hit corroborates the runtime concerns.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a detection.
- All 17 tier-1 engines reported no detection.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false across 10 inspected children.
- No MalwareBazaar, CIRCL, or YARAify match was found.
- One sandbox mapped possible process injection to MITRE T1055.
- LSASS-related process activity triggered a credential-dumper heuristic.
- Runtime mappings include T1486 and T1562.001.
- Direct communication with 162.159.36.2 lacks a completed host-reputation check.
- All 10 extracted children remain unclassified.
- The archive is only 15 days old and has limited submission history.
Verify the archive against an official release source and checksum before use, and keep endpoint protection enabled. Avoid normal-system execution until the embedded executable and unresolved network contact receive deeper review.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 11MITRE ATT&CK techniques
- 13spawned processes
- 1network contacts
- 18filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Encrypted files or data, behaviour commonly associated with ransomware.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
SMTC-Bridge-v1.0.0.zip
429dae6322cfdc48cdf14fab1201d33ada78c046700cef145b6817467cbe68c4
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\SMTC-Bridge.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\cmd.exe /c "ver"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
_avif.cp312-win_amd64.pyd
C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_avif.cp312-win_amd64.pyd
04Isolated runtime analysis - Written fileObserved
_imaging.cp312-win_amd64.pyd
C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imaging.cp312-win_amd64.pyd
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_avif.cp312-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imaging.cp312-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imagingcms.cp312-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imagingmath.cp312-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imagingtk.cp312-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\ssqh5a5u
- C:\Users\<USER>\AppData\Local\Temp\tmple1os8g8.ico
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- d2b82cc3750bb0cd40c0…04bd81Never scannednever seen before
- eae99889a71a12d4b529…7ce5feNever scannednever seen before
- 6af926fd1a58f3912b6f…7d4f71Never scannednever seen before
- 37622ca591fb8e45a894…9247e3Never scannednever seen before
- 847e2b2c69ca623e0f96…6c4bbcNever scannednever seen before
- ab2d0f9637b9209bafb0…7c67a5Never scannednever seen before
- 6db47157030960e7106c…1d1afeNever scannednever seen before
- 69e6228a0d35958183cc…68d6c9Never scannednever seen before
- 3afe87a1dd2463fc3a9b…f06657Never scannednever seen before
- 1b68144734c4b66791f2…4d88dbNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 0 / 74engines flagged
- 29sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 74 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 30 times from 29 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: SMTC-Bridge-v1.0.0.zip — 429dae6322cfdc48cdf14fab1201d33ada78c046700cef145b6817467cbe68c4
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\SMTC-Bridge.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\cmd.exe /c "ver"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: _avif.cp312-win_amd64.pyd — C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_avif.cp312-win_amd64.pyd
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: _imaging.cp312-win_amd64.pyd — C:\Users\<USER>\AppData\Local\Temp\_MEI54682\PIL\_imaging.cp312-win_amd64.pyd
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- SMTC-Bridge-v1.0.0.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 33.4 MB
- Last analyzed
- Sep 22, 2026, 7:13 PM UTC
429dae6322cfdc48cdf14fab1201d33ada78c046700cef145b6817467cbe68c4Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is SMTC-Bridge-v1.0.0.zip safe, or is it malware?
What is SMTC-Bridge-v1.0.0.zip?
How many antivirus engines detected SMTC-Bridge-v1.0.0.zip?
What should I do if I already opened or extracted SMTC-Bridge-v1.0.0.zip?
How do I remove SMTC-Bridge-v1.0.0.zip?
What is the SHA-256 hash of SMTC-Bridge-v1.0.0.zip?
How up to date is this analysis of SMTC-Bridge-v1.0.0.zip?
Community
Member reviews and reports for this exact file hash.