Dropped Files | ZeroBOX
Name 876aa4026138bbff_o7wua5wfleil
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\o7wua5wfleil
Size 6.5KB
Processes 2088 (regasm3.exe)
Type data
MD5 46615e82c3e8010cd5840607c3827e10
SHA1 b41a4abbd45dd053562494eb1505aaac2ee9640e
SHA256 876aa4026138bbff2ca87b62fae21a1951b1de40257dc7845c602e1b3cebaca4
CRC32 E233C62A
ssdeep 96:BPGsIa9yWu6iCDmxCN6VgoNs5fW0P7Jren0r3auzK234MlK/BlhkLu8nPxXqO0e:Es98WFMWQ0VenWKy34MlKPhkLnpse
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsk6356.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsk6356.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 6b86b273ff34fce1_6D6F4D.lck
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.lck
Size 1.0B
Processes 2384 (regasm3.exe)
Type very short file (no magic)
MD5 c4ca4238a0b923820dcc509a6f75849b
SHA1 356a192b7913b04c54574d18c28d46e6395428ab
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
CRC32 83DCEFB7
ssdeep 3:U:U
Yara None matched
VirusTotal Search for analysis
Name f1360d4412ff458c_39610blglnoae4s9lg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\39610blglnoae4s9lg
Size 104.0KB
Processes 2088 (regasm3.exe)
Type data
MD5 6862ec91c278cb23e73074d908cc53c3
SHA1 26ffc626f33db03b222dc68b0194dfdefc8a8091
SHA256 f1360d4412ff458c0c8e0cc2cf6f9eff544c9bbeacbaefa74744e6e615e28e02
CRC32 53F96ACD
ssdeep 3072:Hb/HIxpqrvvovSsobMO2G4DPM+itP+jd5hdfqLTizdS:HbvXrvUSP/2Gcitwd5hdfqCzc
Yara None matched
VirusTotal Search for analysis
Name 4858f7fb27844ed5_dmp1lokjn.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsq6378.tmp\dmp1lokjn.dll
Size 4.5KB
Processes 2088 (regasm3.exe)
Type PE32 executable (DLL) (native) Intel 80386, for MS Windows
MD5 f5fa18d26fa054c8c664cc9a045d317e
SHA1 4cd2638726c18d722c83eb71540474120ec00906
SHA256 4858f7fb27844ed576239fb72d96a1557aba42dbe731d9d9f0634ae132378d92
CRC32 573B5151
ssdeep 48:S90iXCi8FUSAtpum1bm1J8qp7xb5dBIy9fJde:KXCi4UT5cF1IyJq
Yara
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • HasRichSignature - Rich Signature Check
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
VirusTotal Search for analysis