Possible IOC

Disposition

Recommended action: Do not treat this as clean. Review the listed indicators, source, sender, and file hash before release.

This disposition is based only on facts present in the CAPE JSON. It is not a guarantee that a file is safe.

How This Was Determined

Malicious Indicators

No malicious indicators were identified by this script.

Possible IOC / Review Indicators

Lower-Risk Facts

Important Notes

VirusTotal

Stored CAPE result: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

File Details

File nameARen.exe
File typePE32+ executable (GUI) x86-64, for MS Windows
Size11508920
MD58e0b355d0606cc5c3f9886623321ee51
SHA1c65d7c89658f8465a1b283be71e1dc460ecd84f3
SHA256596ab1b3afe47f5b55cf002d7cc94233b56d74d4dafb5969b11e77dcaa05fda5
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID14
Started2026-06-16 13:01:38
Ended2026-06-16 13:02:35
Duration57 seconds
Packageexe
Routenone
Machinecuckoo1
CAPE score1.0
CAPE statusClean

YARA / AV Indicators

SourceRule / DetectionDescription / Evidence
No YARA hits recorded.
No CAPE YARA hits recorded.
No ClamAV hits recorded.

CAPE Signatures

SeverityConfidenceSignatureDescription
3100%pe_deep_entrypointThe PE entry point is located unusually far into section, indicative of an appended packer stub that jumps to the original entry point (OEP)
2100%antianalysis_tls_sectionContains .tls (Thread Local Storage) section
2100%packer_unknown_pe_section_nameThe binary contains an unknown PE section name indicative of packing
2100%contains_pe_overlayThe PE file contains an overlay

Behavior Summary

Executed commands / child processes0
File writes0
File deletes0
Registry writes0
Created services0
Started services0
CAPE payload-like items0
CAPE extracted configs0
Dropped/related files captured0
Network indicators0

Executed Commands / Child Processes

None recorded.

File Writes

None recorded.

Registry Writes

None recorded.

Created Services

None recorded.

Started Services

None recorded.

CAPE Extracted Items

Payload-like Items

None recorded.

Extracted Configs

None recorded.

Network Activity

No network activity was recorded.

No network examples recorded.

Generated 2026-06-16T13:03:01 from /opt/CAPEv2/storage/analyses/14/reports/report.json