metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2022-11-24 13:21:06.668012 2022-11-24 13:21:32.548357 25 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2022-11-24 13:21:07 2022-11-24 13:21:32

File Details

File name 85a14613cfb9fb8b13d9c7bcd2b8fb6aa73d0b96.exe
File size 939560 bytes
File type PE32+ executable (GUI) x86-64, for MS Windows
CRC32 675927BA
MD5 2cbebe2799f12effb1c953b01ba9aefc
SHA1 85a14613cfb9fb8b13d9c7bcd2b8fb6aa73d0b96
SHA256 3f28b1bc371dee659e5637556948bde42de7a1398e5dc65373135714ae6d88b8
SHA512 acebf157b76ab4c5f54b70486dbe0e71eb37d292aac0bad40b5d2eed185d88913f1764b4e96bd1c442fa69ff01f1013d07c45fb438d55ec1117fae79329b73c6
Ssdeep None
PEiD None matched
Yara
  • contains_base64 (This rule finds for base64 strings)
  • win_registry (Affect system registries)
  • win_token (Affect system token)
  • win_files_operation (Affect private profile)
  • IsPE64 ()
  • IsWindowsGUI ()
  • IsPacked (Entropy Check)
  • HasOverlay (Overlay Check)
  • HasDebugData (DebugData Check)
VirusTotal File not found on VirusTotal

MetaFlows Scores

Metaflows Analysis Results (Signatures=50, Anomalies=0, PEiD=0, Yara=0, VT[1669314100]=0): Snort Events=0, AV Events=0
Total Score=50

Signatures

has_pdb details
antivm_memory_available details
pe_features details
nolookup_communication details
packer_entropy details

Screenshots

No screenshots available.

Static Analysis

Version Infos

Sections

Resources

Imports

Strings

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Written
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp\CHROME_PATCH.PACKED.7Z
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp\SETUP_PATCH.PACKED.7Z
File-Opened
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp\CHROME_PATCH.PACKED.7Z
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp\
  • C:\
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp\SETUP_PATCH.PACKED.7Z
Directory-Created
  • C:\Users\Harry Dresden\AppData\Local\Temp\CR_983DA.tmp
Registry Key-Opened
  • HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
  • HKEY_CURRENT_USER\Software\Google
Registry Key-Read
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\MaxRpcSize
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\ComputerName

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 480, Parent PID: 384

"C:\Users\Harry Dresden\AppData\Local\Temp\85a14613cfb9fb8b13d9c7bcd2b8fb6aa73d0b96.exe" PID: 4084, Parent PID: 2664

Volatility

Nothing to display.