Dropped Files | ZeroBOX
Name 59e4c9db07adcdeb_f3zf3zbz90yh2u5u
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\f3zf3zbz90yh2u5u
Size 104.0KB
Processes 2616 (regasm2.exe)
Type DOS executable (COM)
MD5 a3c868f0fa9bf6c42a9cea15d4f3e9c8
SHA1 69bb3df707e35cff25598cae10bc58b2ea6f6352
SHA256 59e4c9db07adcdeb2dda26d049701ee3ce3e2e3b9984310ad6883b1ba779fe97
CRC32 B0F750F6
ssdeep 1536:cH4IFkbRqB4SYn75nk6mewZNswyJ8q0hNFcLM+uSPIB8KUsqKrk0gou8KRI3raKk:WrI+6SVvXyS3ULMaVKUud6lI3ralqJ21
Yara None matched
VirusTotal Search for analysis
Name 1513abd30195b874_6d6f4d.hdb
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.hdb
Size 4.0B
Processes 7680 (regasm2.exe)
Type data
MD5 faeb96cb25b5ff43b7d32cd56d71714c
SHA1 729df48d8e006f5948fa6afdfb46a48df65290d2
SHA256 1513abd30195b87453159f9abdea22c6ff0f424ddaa49ebda53de93ee86a1a5b
CRC32 6A770532
ssdeep 3:2t:K
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsdFF77.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsdFF77.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 6b86b273ff34fce1_6D6F4D.lck
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.lck
Size 1.0B
Processes 7680 (regasm2.exe)
Type very short file (no magic)
MD5 c4ca4238a0b923820dcc509a6f75849b
SHA1 356a192b7913b04c54574d18c28d46e6395428ab
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
CRC32 83DCEFB7
ssdeep 3:U:U
Yara None matched
VirusTotal Search for analysis
Name fa72f629219572d7_sgcu953rcizr.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsiFF98.tmp\sgcu953rcizr.dll
Size 4.5KB
Processes 2616 (regasm2.exe)
Type PE32 executable (DLL) (native) Intel 80386, for MS Windows
MD5 38f3b0d59b05b3177876a557d6aa7ec9
SHA1 bd7f40e08ac9cd36a2bc2261d6d2fbe7f3f564ef
SHA256 fa72f629219572d7c51e2087d08d9a817d47799f9cdc8ea94612720ba07eb5d4
CRC32 F38F636B
ssdeep 48:S+g0kXCvDJU9/Nm1bm1J8qp7xb5dBIy9fMEP:AXCvVUCcF1Iy5F
Yara
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • HasRichSignature - Rich Signature Check
VirusTotal Search for analysis
Name fed783a34972af32_r5mpf5xpkvxp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\r5mpf5xpkvxp
Size 6.5KB
Processes 2616 (regasm2.exe)
Type data
MD5 19dfa875068fc1e153a9d1a742f6f700
SHA1 a640018ccee95d3ffed261397ffbfa19ad17989d
SHA256 fed783a34972af322a548958be1b03a34f375f11271f63417d1bcd79513de48e
CRC32 2676CDE7
ssdeep 192:RnGVtqKyyn3M4W+8XuKM8uqED38LxdYWI0WAW:RGVtwqM4WxMXbDsL3/ImW
Yara None matched
VirusTotal Search for analysis