High Risk / Review Required

Recommended action: Do not release this file without IT/security review.

Why this verdict: One or more stronger indicators were present, such as detection hits, network activity, persistence/service behavior, extracted malware config, or high-risk signatures.

Important: This report should not say a file is absolutely “safe.” A better phrase is: no obvious malicious behavior was observed in this sandbox run.

Quick Notes

Reputation / External Lookup

VirusTotal: Unavailable/error from CAPE: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

This report only uses VirusTotal detection counts if they are present in the CAPE JSON. A link alone is not the same as a local detection result.

File Details

File nametrue
File typeELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=def326b154045626150e1bac9a720de16fa2db52, for GNU/Linux 3.2.0, stripped
Size26936
MD55f3e9687fd390268d1ca33854127465e
SHA1f54c0d4f1a5b6ce11b2d926b692fccfe1a4fcd9c
SHA2564b5a5694e3c0e8b1d58fc52ac6ef076e55e72c2f53195243ac86d5ff517cc2f6
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID8
Started2026-06-15 18:02:36
Ended2026-06-15 18:07:03
Duration267 seconds
Packagegeneric
Routefalse
Machinecuckoo1
CAPE score9.0
CAPE statusMalicious
Digital signatureNo signer data found in CAPE JSON.

Top CAPE Signatures

SeverityConfidenceSignatureMeaning
3100%antivm_displayAttempts to query display device information, possibly to determine if the process is running in a virtualized environment
3100%suspicious_iocontrol_codesUses suspicious IO control codes, indicative of disk enumeration or a bootkit/wiper
3100%infostealer_cookiesTouches a file containing cookies, possibly for information gathering
3100%interprocess_comms_shared_memoryInter-process communication via named shared memory (file mappings), possibly for routing local C2 traffic or injection
280%privilege_elevation_checkQueries process token information to check for Administrator privileges or UAC elevation status
220%mountpoints_volume_discoveryQueries the mount points and then resolves volume paths to enumerate storage devices
250%creates_suspended_processCreates a process in a suspended state, likely for injection
2100%resumethread_remote_processResumed a thread in another process
2100%stealth_windowA process created a hidden window
220%discover_registry_mount_pointsQueries registry mount points to identify historical or connected removable/network drives
1100%antivm_checks_available_memoryChecks available memory
1100%queries_keyboard_layoutQueries the keyboard layout
1100%queries_locale_apiQueries the computer locale (possible geofencing)
140%antidebug_setunhandledexceptionfilterSetUnhandledExceptionFilter detected (possible anti-debug)
1100%language_check_registryChecks system language via registry key (possible geofencing)

Behavior Summary

Observed itemCount
Executed commands / child processes10
File writes2
File deletes0
Registry writes8
Created services0
Started services1
CAPE payload-like items0
CAPE extracted configs0
Dropped/related files captured0

Executed Commands / Child Processes

File Writes

Registry Writes

Created Services

None observed.

Started Services

CAPE Payloads / Extracted Items

No CAPE payload-like items were extracted.

None observed.

Network Activity

No network activity recorded in this report.

Generated 2026-06-15T18:08:01 from /opt/CAPEv2/storage/analyses/8/reports/report.json