'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2018-08-17 18:08:20.058326 2018-08-17 18:08:44.870168 24 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2018-08-17 18:08:20 2018-08-17 18:08:44

File Details

File name cce6e761b12f42887388a273d4c5609e56a1ce38.dll
File size 530305 bytes
File type PE32 executable (console) Intel 80386, for MS Windows
CRC32 27925464
MD5 e37211b58ae7c8a669bae32dd8e3b8d1
SHA1 cce6e761b12f42887388a273d4c5609e56a1ce38
SHA256 420133fc76a2c94b09ef0ce22c77c176a5fbcbc6489e64044f35796c1a6c140c
SHA512 c155c3ee20cff72886c940fd519560375d6545fafb59880cfc25b0b1966ff6d3a051d2cd4c656a5fa84afcfb668d31cc6318e4be35aef300ee83aea86339b2d8
Ssdeep None
PEiD None matched
Yara
  • spyeye (SpyEye X.Y memory)
  • RooterStrings (Rooter Identifying Strings)
  • Rooter (Rooter)
VirusTotal Permalink
VirusTotal Scan Date: 2018-08-03 00:13:59
Detection Rate: 1/68 (Expand)

MetaFlows Scores

Metaflows Analysis Results (Signatures=75, Anomalies=0, PEiD=0, Yara=0, VT[1534543727]=0): Snort Events=0, AV Events=0
Total Score=75

Signatures

console_output details
packer_entropy details
nolookup_communication details

Screenshots

No screenshots available.

Static Analysis

Sections

Imports

Strings

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Opened
  • C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
Registry Key-Read
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language\InstallLanguageFallback
  • HKEY_CURRENT_USER\Control Panel\Desktop\PreferredUILanguages
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\en-US\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\UILanguages\en-US\AlternateCodePage
  • HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\EMPTY
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 480, Parent PID: 384

"C:\Users\Harry Dresden\AppData\Local\Temp\cce6e761b12f42887388a273d4c5609e56a1ce38.dll" PID: 1320, Parent PID: 572

Volatility

Nothing to display.