Possible IOC

Disposition

Recommended action: Do not treat this as clean. Review the listed indicators, source, sender, and file hash before release.

This disposition is based only on facts present in the CAPE JSON. It is not a guarantee that a file is safe.

How This Was Determined

Malicious Indicators

No malicious indicators were identified by this script.

Possible IOC / Review Indicators

Lower-Risk Facts

Important Notes

VirusTotal

Stored CAPE result: No VirusTotal result was stored in the CAPE JSON.

Manual lookup: No SHA256 available

File Details

File name
File type
Size
MD5
SHA1
SHA256
VirusTotal lookupNo SHA256 available

Sandbox Run Details

Task ID20
Started2026-06-16 17:54:37
Ended2026-06-16 17:55:21
Duration44 seconds
Packageedge
Routeinternet
Machinecuckoo1
CAPE score0.5
CAPE statusClean

YARA / AV Indicators

SourceRule / DetectionDescription / Evidence
No YARA hits recorded.
No CAPE YARA hits recorded.
No ClamAV hits recorded.

CAPE Signatures

SeverityConfidenceSignatureDescription
1100%stealth_networkNetwork activity detected but not expressed in monitor API logs

Behavior Summary

Executed commands / child processes0
File writes0
File deletes0
Registry writes0
Created services0
Started services0
CAPE payload-like items0
CAPE extracted configs0
Dropped/related files captured0
Network indicators210

Executed Commands / Child Processes

None recorded.

File Writes

None recorded.

Registry Writes

None recorded.

Created Services

None recorded.

Started Services

None recorded.

CAPE Extracted Items

Payload-like Items

None recorded.

Extracted Configs

None recorded.

Network Activity

Network activity was recorded.

{'ip': '104.17.24.24', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': 'static.hsappstatic.net', 'inaddrarpa': '', 'ports': [443]}
{'ip': '172.66.161.212', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': 'embed.tawk.to', 'inaddrarpa': '', 'ports': [443]}
{'ip': '104.16.107.254', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': 'js.hscollectedforms.net', 'inaddrarpa': '', 'ports': [443]}
{'ip': '104.18.40.240', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': 'js.hs-banner.com', 'inaddrarpa': '', 'ports': [443]}
{'ip': '104.16.160.168', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': 'js.hs-analytics.net', 'inaddrarpa': '', 'ports': [443]}
{'domain': 'edge-consumer-static.azureedge.net', 'ip': '13.107.226.51'}
{'domain': 'www.tranquilityproducts.com', 'ip': '104.193.142.21'}
{'domain': 'tranquilityproducts.com', 'ip': '104.193.142.21'}
{'domain': 'cdn-cfoco.nitrocdn.com', 'ip': '172.64.154.105'}
{'domain': 'js.hs-scripts.com', 'ip': '104.16.140.209'}

Generated 2026-06-16T17:56:01 from /opt/CAPEv2/storage/analyses/20/reports/report.json