Safe
Clean ZIP archive containing a user theme with zero malicious detections and benign sandbox behaviour.
bd4063c1beec640e05…333916cb8bThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero engine detections combined with clean tier-1 consensus and no sandbox malice provide high confidence the archive is benign. The single offensive MITRE technique is explained by the sandbox's own process monitoring rather than malicious intent. Age and low submission count are typical for niche customization files rather than widespread malware.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0 malicious out of 66 reporting with 17 tier-1 clean verdicts
behaviour.offensiveTechniques: ["T1543.002"] but hasMaliciousSandboxVerdict=false
prevalence.classification: rare_old with firstSeen 278 days ago
filenameAnalysis.looksLikePortable=true and no externalIntel hits
- Zero malicious detections across 66 engines
- No malicious sandbox verdict or host contacts
- Long observation window with no reputation issues
The file can be considered safe for normal use as a device theme archive.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- /root/.cache/dconf/user
0 detections across 76 engines
How often this file shows up in the wild
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Forensic fingerprint
- File name
- Whitedust_miuithemer.com.mtz.zip
- Size
- 12.16 MB
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- bd4063c1beec640e0556e3516531676cab68cb039917b8cff16554333916cb8b
- MD5
- 21276be44e382440d0722f8fc366a8a2
- SHA-1
- caf36bdc1c223fe2da54c8c12f0cc37fd9b43344
- First seen (VT)
- 8/12/2025, 5:30:25 AM
- Last analysis (VT)
- 8/12/2025, 5:30:25 AM
- First scan (MalwareTips)
- 5/17/2026, 9:28:57 AM
- Last scan (MalwareTips)
- 5/17/2026, 9:28:57 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.