Malicious

Disposition

Recommended action: Do not release this file. Escalate or handle according to your malware process.

This disposition is based only on facts present in the CAPE JSON. It is not a guarantee that a file is safe.

How This Was Determined

Malicious Indicators

Possible IOC / Review Indicators

Lower-Risk Facts

Important Notes

VirusTotal

Stored CAPE result: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

File Details

File nameDocRecord_Desktop.exe
File typePE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Size385056
MD5271a8499e58fd6d75de606af4733a3a7
SHA1478d12feb5ecc499d1ddd9ca3b726b59d3650084
SHA25688866b914181c798be6908e5e48e69a8b86a92bcf33e34d736ab5e5bb2b4191e
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID23
Started2026-06-17 19:49:19
Ended2026-06-17 19:50:44
Duration85 seconds
Packageexe
Routeinternet
Machinecuckoo1
CAPE score2.2
CAPE statusClean

YARA / AV Indicators

SourceRule / DetectionDescription / Evidence
YARAINDICATOR_EXE_Packed_SmartAssemblyDetects executables packed with SmartAssembly
No CAPE YARA hits recorded.
No ClamAV hits recorded.

CAPE Signatures

SeverityConfidenceSignatureDescription
380%binary_yaraBinary file triggered YARA rule
3100%pe_deep_entrypointThe PE entry point is located unusually far into section, indicative of an appended packer stub that jumps to the original entry point (OEP)
280%registers_vectored_exception_handlerRegisters a vectored exception handler (VEH), possibly to hijack execution flow
2100%contains_pe_overlayThe PE file contains an overlay
250%injection_rwxCreates RWX memory
1100%stealth_networkNetwork activity detected but not expressed in monitor API logs
1100%antivm_checks_available_memoryChecks available memory
140%antidebug_setunhandledexceptionfilterSetUnhandledExceptionFilter detected (possible anti-debug)
140%stealth_timeoutPossible date expiration check, exits too soon after checking local time
1100%language_check_registryChecks system language via registry key (possible geofencing)

Behavior Summary

Executed commands / child processes0
File writes0
File deletes0
Registry writes0
Created services0
Started services0
CAPE payload-like items2
CAPE extracted configs0
Dropped/related files captured0
Network indicators27

Executed Commands / Child Processes

None recorded.

File Writes

None recorded.

Registry Writes

None recorded.

Created Services

None recorded.

Started Services

None recorded.

CAPE Extracted Items

Payload-like Items

/opt/CAPEv2/storage/analyses/23/CAPE/910b8907c800d66f31c52485c45d9bf7caf11b3d3f67cdf7f149211ec0c2a398
/opt/CAPEv2/storage/analyses/23/CAPE/ef8aa40fb1449f0889516baf8f325f591a5f472b2344087684525fe6ab2e95d6

Extracted Configs

None recorded.

Network Activity

Network activity was recorded.

{'ip': '20.184.175.8', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '184.31.114.99', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [80]}
{'ip': '23.50.37.248', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '23.65.16.228', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '23.15.3.76', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'domain': 'edge-consumer-static.azureedge.net', 'ip': '150.171.110.209'}
edge-consumer-static.azureedge.net
40.126.29.14
150.171.28.11
204.79.197.203

Generated 2026-06-17T19:51:01 from /opt/CAPEv2/storage/analyses/23/reports/report.json