metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2022-02-18 14:52:41.803827 2022-02-18 14:53:08.927498 27 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2022-02-18 14:52:42 2022-02-18 14:53:08

File Details

File name 40bffba8deebcfa89ff78591d1697290a8f8145d.bin
File size 27016 bytes
File type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
CRC32 1D3D3684
MD5 6f6a6e38715c9b3838f95e03fa0567f3
SHA1 40bffba8deebcfa89ff78591d1697290a8f8145d
SHA256 b1eab91db2cb293c153d0cb5ebf1ac3a9d50ac75d050403e8b9e1ec68881bd5f
SHA512 b1ecc5e8aff711a0ec8aa9d8415e1b26b06bc8e5607f26baba34506c30849b091e2fb3ea7051471000640c869aa9024e09749cbeac5595c16a4806d15f3221c2
Ssdeep None
PEiD None matched
Yara
  • contains_base64 (This rule finds for base64 strings)
  • IsPE32 ()
  • IsDLL ()
  • IsWindowsGUI ()
  • HasOverlay (Overlay Check)
  • HasDebugData (DebugData Check)
  • ImportTableIsBad (ImportTable Check)
  • HasRichSignature (Rich Signature Check)
VirusTotal Permalink
VirusTotal Scan Date: 2022-01-27 07:15:53
Detection Rate: 0/63 (Expand)

MetaFlows Scores

Metaflows Analysis Results (Signatures=50, Anomalies=0, PEiD=0, Yara=0, VT[1645213994]=0): Snort Events=0, AV Events=0
Total Score=50

Signatures

nolookup_communication details

Screenshots

No screenshots available.

Static Analysis

Version Infos

Sections

Resources

Strings

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

Registry Key-Read
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 480, Parent PID: 384

"C:\Windows\System32\rundll32.exe" C:\Users\HARRYD~1\AppData\Local\Temp\40bffba8deebcfa89ff78591d1697290a8f8145d.bin.dll,DllMain PID: 4036, Parent PID: 3320

Volatility

Nothing to display.