Malicious

Disposition

Recommended action: Do not release this file. Escalate or handle according to your malware process.

This disposition is based only on facts present in the CAPE JSON. It is not a guarantee that a file is safe.

How This Was Determined

Malicious Indicators

Possible IOC / Review Indicators

Lower-Risk Facts

Important Notes

VirusTotal

Stored CAPE result: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

File Details

File namegenerate_tech_report.py
File typeGeneric INItialization configuration [value]
Size20137
MD5bf29f6c6079c87479b130c61c426ebe3
SHA1b2e2a790c6741cf720369e54cda5682a9899ee91
SHA25603844a48c75bf9b9af8ed89e26ab8681c9ea2d5bf85782ead9623a8509db54ed
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID25
Started2026-06-18 11:54:18
Ended2026-06-18 11:56:48
Duration150 seconds
Packagepython
Routeinternet
Machinecuckoo1
CAPE score1.4
CAPE status

YARA / AV Indicators

SourceRule / DetectionDescription / Evidence
No YARA hits recorded.
No CAPE YARA hits recorded.
No ClamAV hits recorded.

CAPE Signatures

SeverityConfidenceSignatureDescription
1100%stealth_networkNetwork activity detected but not expressed in monitor API logs
140%antidebug_setunhandledexceptionfilterSetUnhandledExceptionFilter detected (possible anti-debug)
140%stealth_timeoutPossible date expiration check, exits too soon after checking local time
1100%language_check_registryChecks system language via registry key (possible geofencing)

Behavior Summary

Executed commands / child processes1
File writes0
File deletes0
Registry writes0
Created services0
Started services0
CAPE payload-like items0
CAPE extracted configs0
Dropped/related files captured0
Network indicators8

Executed Commands / Child Processes

C:\Users\IT\AppData\Local\Programs\Python\Python313\python.exe C:\Users\IT\AppData\Local\Temp\generate_tech_report.py

File Writes

None recorded.

Registry Writes

None recorded.

Created Services

None recorded.

Started Services

None recorded.

CAPE Extracted Items

Payload-like Items

None recorded.

Extracted Configs

None recorded.

Network Activity

Network activity was recorded.

{'ip': '20.59.87.227', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
10.10.69.139
20.59.87.227
192.168.122.1
224.0.0.251

Generated 2026-06-18T11:57:01 from /opt/CAPEv2/storage/analyses/25/reports/report.json