Dropped Files | ZeroBOX
Name f8098a6290118f29_settings.bin
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\settings.bin
Size 40.0B
Processes 5992 (flexing.exe)
Type data
MD5 4e5e92e2369688041cc82ef9650eded2
SHA1 15e44f2f3194ee232b44e9684163b6f66472c862
SHA256 f8098a6290118f2944b9e7c842bd014377d45844379f863b00d54515a8a64b48
CRC32 C6B6460B
ssdeep 3:9bzY6oRDT6P2bfVn1:RzWDT621
Yara None matched
VirusTotal Search for analysis
Name 0bd3aac12623520c_storage.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\storage.dat
Size 319.8KB
Processes 5992 (flexing.exe)
Type data
MD5 7e8f4a764b981d5b82d1cc49d341e9c6
SHA1 d9f0685a028fb219e1a6286aefb7d6fcfc778b85
SHA256 0bd3aac12623520c4e2031c8b96b4a154702f36f97f643158e91e987d317b480
CRC32 F31C2239
ssdeep 6144:oX44S90aTiB66x3Pl6nGV4bfD6wXPIZ9iBj0UeprGm2d7Tm:LkjYGsfGUc9iB4UeprKdnm
Yara None matched
VirusTotal Search for analysis
Name dd26a49e38e825a0_tmpA0B3.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmpA0B3.tmp
Size 1.6KB
Processes 652 (flexing.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 263181a27ce8fa48b704168d246f7145
SHA1 c8c0d3fbda86d3bb249de7d9f11c821215f19388
SHA256 dd26a49e38e825a01cfef02279f33a9339947f685bd7b18186083b6f74ba1c3f
CRC32 FDB3C3BE
ssdeep 24:2dH4+SEqCH/7IlNMFQ/rlMhEMjnGpwjpIgUYODOLD9RJh7h8gKBJ/tn:cbhf7IlNQQ/rydbz9I3YODOLNdq39
Yara None matched
VirusTotal Search for analysis
Name 5347661365e7ad2c_catalog.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\catalog.dat
Size 232.0B
Processes 5992 (flexing.exe)
Type data
MD5 32d0aae13696ff7f8af33b2d22451028
SHA1 ef80c4e0db2ae8ef288027c9d3518e6950b583a4
SHA256 5347661365e7ad2c1acc27ab0d150ffa097d9246bb3626fca06989e976e8dd29
CRC32 36FCB1A3
ssdeep 6:X4LDAnybgCFcpJSQwP4d7ZrqJgTFwoaw+9XU4:X4LEnybgCFCtvd7ZrCgpwoaw+Z9
Yara None matched
VirusTotal Search for analysis
Name f2246be42316441c_run.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\run.dat
Size 8.0B
Processes 5992 (flexing.exe)
Type data
MD5 17148e63754da75a3f5ab491e0864429
SHA1 c51939a2fe5207a182867a1036c11f9314ea7d93
SHA256 f2246be42316441c2ce20f34784aeb00c3fcbc359c5952bad4ad0212cdfeca7c
CRC32 CEF25F54
ssdeep 3:Bz8n:O
Yara None matched
VirusTotal Search for analysis