File verdict·Decided by the MT AI Engine
Our call

Safe

Clean ZIP archive containing a user theme with zero malicious detections and benign sandbox behaviour.

Trust score85High trust
MT AI confidence · 90%
Whitedust_miuithemer.com.mtz.zip
12.2 MB
bd4063c1beec640e05333916cb8b
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 10mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

90%Confidence
Very high
Reasoning

Zero engine detections combined with clean tier-1 consensus and no sandbox malice provide high confidence the archive is benign. The single offensive MITRE technique is explained by the sandbox's own process monitoring rather than malicious intent. Age and low submission count are typical for niche customization files rather than widespread malware.

Key signals · 4

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0 malicious out of 66 reporting with 17 tier-1 clean verdicts

  2. behaviour.offensiveTechniques: ["T1543.002"] but hasMaliciousSandboxVerdict=false

  3. prevalence.classification: rare_old with firstSeen 278 days ago

  4. filenameAnalysis.looksLikePortable=true and no externalIntel hits

Points in its favour
  • Zero malicious detections across 66 engines
  • No malicious sandbox verdict or host contacts
  • Long observation window with no reputation issues
What to do

The file can be considered safe for normal use as a device theme archive.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
4

Adversary techniques mapped to the MITRE ATT&CK framework.

T1064T1518.001T1543.002T1564.001
Spawned processes
12
$(unnamed)
/usr/bin/exo-open exo-open /tmp/Whitedust_HyperOSThemes.com.mtz
$(unnamed)
/usr/bin/dbus-launch dbus-launch --autolaunch=a39eb3ed78b7401fb6809ed0c562a5b1 --binary-syntax --close-stderr
$(unnamed)
/usr/bin/exo-open -
$(unnamed)
/usr/bin/engrampa engrampa /tmp/Whitedust_HyperOSThemes.com.mtz
$(unnamed)
/usr/lib/p7zip/7z l -slt -bd -y -- /tmp/Whitedust_HyperOSThemes.com.mtz
$(unnamed)
/bin/sh sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
$(unnamed)
/usr/lib/rsyslog/rsyslog-rotate
$(unnamed)
/usr/bin/systemctl systemctl kill -s HUP rsyslog.service
+4 more processes captured.
Filesystem & mutexes
1
Files written1
  • /root/.cache/dconf/user
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash bd4063c1beec… cross-referenced against 76 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.

Rare & old
Unique uploaders
3
Very few people have ever uploaded this — rare.
Total submissions
3
Includes repeat uploads by the same source.
First seen by VT
10mo ago
Aug 12, 2025
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
here
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
8/12/2025, 5:30:25 AM
First seen (MalwareBazaar)
Last analysis (VT)
8/12/2025, 5:30:25 AM
Scanned here
5/17/2026, 9:28:57 AM
File name
Whitedust_miuithemer.com.mtz.zip
Size
12.16 MB
MIME type
(unknown)
Detected type
ZIP
SHA-256
bd4063c1beec640e0556e3516531676cab68cb039917b8cff16554333916cb8b
MD5
21276be44e382440d0722f8fc366a8a2
SHA-1
caf36bdc1c223fe2da54c8c12f0cc37fd9b43344
First seen (VT)
8/12/2025, 5:30:25 AM
Last analysis (VT)
8/12/2025, 5:30:25 AM
First scan (MalwareTips)
5/17/2026, 9:28:57 AM
Last scan (MalwareTips)
5/17/2026, 9:28:57 AM
Behavior tags
zipsets-process-namedetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.