Identifying packed files and understanding import functions before jumping into the sandbox.
Mention that you are working in a isolated lab environment (like a VM) to show you follow professional safety protocols. Lab01.7z
Appears to be a dropper. Using Strings , I found references to kerne132.dll (a common spoofing tactic) and potential network activity. Lab01.7z