Suspicious Packaging / Verify Source

Recommended action: Verify the download source, file hash, and digital signature. If it came from the official vendor and reputation checks are clean, it is likely acceptable.

Why this verdict: CAPE scored the file highly, but the observed indicators are mostly packaging, UI, locale, or anti-VM style checks, and the behavior side was otherwise quiet.

Important: This report should not say a file is absolutely “safe.” A better phrase is: no obvious malicious behavior was observed in this sandbox run.

Quick Notes

Reputation / External Lookup

VirusTotal: Unavailable/error from CAPE: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

This report only uses VirusTotal detection counts if they are present in the CAPE JSON. A link alone is not the same as a local detection result.

File Details

File namenotepad__.exe
File typePE32+ executable (GUI) x86-64, for MS Windows
Size8383104
MD554cc861ace958d1ff881551230e9fba9
SHA169cb2179ef777a2e1118fe43c8c67bc75ed10fda
SHA256a44e2bca325e482a65abc82ee1c8d164ca4e15e0792746876c302d0881335c76
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID7
Started2026-06-15 15:58:31
Ended2026-06-15 16:02:37
Duration246 seconds
Packageexe
Routenone
Machinecuckoo1
CAPE score7.0
CAPE statusMalicious
Digital signatureGuest signer check failed: File not found: C:\Users\IT\AppData\Local\Temp\7\notepad__.exe

Top CAPE Signatures

SeverityConfidenceSignatureMeaning
3100%antivm_displayAttempts to query display device information, possibly to determine if the process is running in a virtualized environment
2100%mouse_movement_detectChecks for mouse movement
280%privilege_elevation_checkQueries process token information to check for Administrator privileges or UAC elevation status
2100%pe_deep_entrypointThe PE entry point is located unusually far into section, indicative of an appended packer stub that jumps to the original entry point (OEP)
2100%packer_unknown_pe_section_nameThe binary contains an unknown PE section name indicative of packing
2100%packer_entropyThe binary likely contains encrypted or compressed data
2100%contains_pe_overlayThe PE file contains an overlay
1100%queries_keyboard_layoutQueries the keyboard layout
1100%queries_locale_apiQueries the computer locale (possible geofencing)
140%antidebug_setunhandledexceptionfilterSetUnhandledExceptionFilter detected (possible anti-debug)
1100%language_check_registryChecks system language via registry key (possible geofencing)

Behavior Summary

Observed itemCount
Executed commands / child processes0
File writes5
File deletes0
Registry writes0
Created services0
Started services0
CAPE payload-like items1
CAPE extracted configs0
Dropped/related files captured2

Executed Commands / Child Processes

None observed.

File Writes

Registry Writes

None observed.

Created Services

None observed.

Started Services

None observed.

CAPE Payloads / Extracted Items

CAPE extracted 1 payload-like item(s). Review if unexpected.

Network Activity

No network activity recorded in this report.

Generated 2026-06-15T16:35:55 from /opt/CAPEv2/storage/analyses/7/reports/report.json