'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2017-07-10 13:45:34.130771 2017-07-10 13:46:50.483780 76 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo2 win7 Clone 2 VirtualBox 2017-07-10 13:45:34 2017-07-10 13:46:48

Errors

File Details

File name 5fecaf9a72d1d2ac1510fd1f959a188ce60a4582.zip
File size 1493 bytes
File type Zip archive data
CRC32 47D05305
MD5 5c78e58d7165a18d92a12c6860e1493f
SHA1 5fecaf9a72d1d2ac1510fd1f959a188ce60a4582
SHA256 65ea75ace62ce205e06592441452d0c2416a0281009b3a76819c390e1eceea9f
SHA512 8db74777e3646a69eb1f42e5c69a77b6fff26106f6324faf7bf8d638aec51ce45cf36b279ac4721c1e6398b90b1f7ae95e05f9f4b395410b6832829d2a4850c2
Ssdeep None
PEiD None matched
Yara
  • PM_Zip_with_js ()
VirusTotal File not found on VirusTotal

MetaFlows Scores

Metaflows Analysis Results (Signatures=0, Anomalies=0, PEiD=0, Yara=2, VT[1499708816]=0): Snort Events=0, AV Events=0
Total Score=2

File intentionally breaks sandbox processing and looks highly suspicious

Signatures

No signatures matched

Screenshots

No screenshots available.

Static Analysis

Nothing to display.

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

Behavior Summary

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 460, Parent PID: 364

Volatility

Nothing to display.