High Risk / Review Required

Recommended action: Do not release this file without IT/security review.

Important: This report should not say a file is absolutely “safe.” A better phrase is: no obvious malicious behavior was observed in this sandbox run.

Quick Notes

File Details

File namecalc.exe
File typePE32+ executable (GUI) x86-64, for MS Windows
Size49152
MD518e5b970eab39020b7e53aa81c371287
SHA1dfaa2584f5c12a9a329e41e141dd4e8d986c620a
SHA256621ba3934afc45c35a4ee16386f4da30119f39fa243e8dc8fef3491a76f829d8

Sandbox Run Details

Task ID5
Started2026-06-11 18:33:07
Ended2026-06-11 18:37:14
Duration247
Packageexe
Routenone
Machinecuckoo1
CAPE score8.0
CAPE statusMalicious

Top CAPE Signatures

SeverityConfidenceSignatureMeaning
3100%infostealer_cookiesTouches a file containing cookies, possibly for information gathering
3100%pe_compile_timestompingBinary compilation timestomping detected
280%privilege_elevation_checkQueries process token information to check for Administrator privileges or UAC elevation status
250%creates_suspended_processCreates a process in a suspended state, likely for injection
2100%resumethread_remote_processResumed a thread in another process
2100%packer_unknown_pe_section_nameThe binary contains an unknown PE section name indicative of packing
1100%antivm_checks_available_memoryChecks available memory
1100%queries_keyboard_layoutQueries the keyboard layout
180%static_pe_pdbpathThe PE file contains a PDB path
140%antidebug_setunhandledexceptionfilterSetUnhandledExceptionFilter detected (possible anti-debug)
1100%language_check_registryChecks system language via registry key (possible geofencing)

Observed Behavior

Executed Commands / Child Processes

Registry Writes

Created Services

None observed.

Started Services

Network Activity

No network activity recorded in this report.

Generated 2026-06-15T15:24:50 from /opt/CAPEv2/storage/analyses/5/reports/report.json