Creating report…

Connecting to server

Dr.Web CureIt!

Dr.Web vxCube determined the file as malicious. Creating Dr.Web CureIt! to neutralize the threat.

Dr.Web CureIt! utility is ready. Run it on your computer to neutralize detected threat.

Failed to create Dr.Web CureIt! utility. Please try to create the utility again or contact the service administrator.

Error occurred while creating Dr.Web CureIt! utility. Please try to create the utility again.

The previously created Dr.Web CureIt! utility has been removed. Please try to create the utility again.

Cannot create the Dr.Web CureIt! utility. The original file is too small.

Report is not available

Report retention period has expired.
To generate a report, analyze the original file again.

Analysis error

File name
corelrepack.1
SHA1
c7bcf36eb18341357b9d941492ed2b75b0f68ecc

Your file is queued

0 %

File name
corelrepack.1
Size
208.7 KB
Format
exe
SHA1
c7bcf36eb18341357b9d941492ed2b75b0f68ecc
Analysis started
1663422167721.219
corelrepack.1
Estimated result
Clean
Malware
Threat
Trojan.Hosts.50372
Detected
Tags
Size
208.7 KB
Format
exe
SHA1
c7bcf36eb18341357b9d941492ed2b75b0f68ecc
Comment

Analysis started
1663422167721.219
Use of VNC
Sample run time
1 minute
Total analysis time
Command to run the file
Not specified
Sample name
corelrepack.exe
Connection type
vpn://
Monitor all processes if VNC is used
No
Total size limit for drops
64 MB
Enable auto clicker
No
Сopy full raw hypervisor log
No
Flex sample time
No
Forward the specified ports from guest VM
get *.lib files and raw dumps
No
Maximum number of triggered breakpoints
Lifetime of processes in seconds
Start user batch script before sample
Set system date
Dump browsers modules
Yes
Dump memory-mapped files (only after execution)
Yes
Dump SSDT
Yes
Dump processes (only after execution)
Yes
Get all allocs and drops
No
Size of Crypto API buffers limit in Mb
Injects count limit
WriteFile buffers limit in Mb

Manifest

  • Package: ccc.sss
  • App name: Ecok
  • Version code: 825
  • Version name: 13.8.88
No data
Name Maliciousness Tags

MITRE ATT&CK Matrix

No data
Threat Identifiers
Severity
Operation
Technique Information
ID
Tactics
Platforms

Process graph

Description

No data
Path SHA1 Detected
File name SHA1 PID Detected
show all
Time Process Event Arguments

Network activity

less than 5 connections
5-10 connections
more than 10 connections

Time Protocol Source Destination Information
Please wait…

Dr.Web vxCube 1.6.0

Dr.Web vxCube inspects suspicious files and detects threats. After the analysis, you get detailed information and a video report on the file behavior.

The Dr.Web vxCube software contains a knowledge base from MITRE ATT&CK®. This knowledge base is available for use under license from The MITRE Corporation.

© 2025 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

The MITRE ATT&CK® terms of use are located at https://attack.mitre.org/resources/legal-and-branding/terms-of-use/.

Version:  1.6.0.202604220