metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2022-06-14 16:49:18.467691 2022-06-14 16:53:14.798484 236 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2022-06-14 16:52:07 2022-06-14 16:53:14

File Details

File name 929e6009745e468f741b2cb71844ca65604d850b.exe
File size 2634584 bytes
File type PE32 executable (GUI) Intel 80386, for MS Windows
CRC32 E433953B
MD5 15f4dbcec876fe73985b98ff75b9bd57
SHA1 929e6009745e468f741b2cb71844ca65604d850b
SHA256 146d7adf8f2cf2435f65c851e08737407b99c4945b65a6d589b51fbf91da89c7
SHA512 81eb5d54d49aa245aca72e1469f647452f0151323de8c4ad60994dcf817bedf65733ad53b2729c87bd93d780b442e7ae063b1ab857e52fa462d0c1bb61d562e3
Ssdeep None
PEiD None matched
Yara
  • SEH_Save ()
  • SEH_Init ()
  • Check_OutputDebugStringA_iat ()
  • anti_dbg (Checks if being debugged)
  • win_hook (Affect hook table)
  • contains_base64 (This rule finds for base64 strings)
  • screenshot (Take screenshot)
  • keylogger (Run a keylogger)
  • win_mutex (Create or check mutex)
  • win_registry (Affect system registries)
  • win_private_profile (Affect private profile)
  • win_files_operation (Affect private profile)
  • maldoc_find_kernel32_base_method_1 ()
  • maldoc_getEIP_method_1 ()
  • IsPE32 ()
  • IsWindowsGUI ()
  • HasOverlay (Overlay Check)
  • HasDigitalSignature (DigitalSignature Check)
  • HasDebugData (DebugData Check)
  • HasRichSignature (Rich Signature Check)
  • VC8_Microsoft_Corporation ()
  • Microsoft_Visual_Cpp_8 ()
VirusTotal File not found on VirusTotal

MetaFlows Scores

Metaflows Analysis Results (Signatures=50, Anomalies=0, PEiD=0, Yara=0, VT[1655240135]=0): Snort Events=0, AV Events=0
Total Score=50

Signatures

has_pdb details
nolookup_communication details
origin_langid details

Screenshots

No screenshots available.

Static Analysis

Version Infos

Sections

Resources

Imports

Strings

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 480, Parent PID: 384

Volatility

Nothing to display.