Dropped Files | ZeroBOX
Name 2f7f8fc05dc4fd0d_UAC.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsk33.tmp\UAC.dll
Size 14.5KB
Processes 5032 (lv.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 adb29e6b186daa765dc750128649b63d
SHA1 160cbdc4cb0ac2c142d361df138c537aa7e708c9
SHA256 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
CRC32 1FE27A66
ssdeep 192:DiF6v2imI36Op/tGZGfWxdyWHD0I53vLl7WVl8e04IpDlPjs:DGVY6ClGoWxXH75T1WVl83lLs
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 05d8cf394190f3a7_Strette.exe.com
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\Strette.exe.com
Size 921.7KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 78ba0653a340bac5ff152b21a83626cc
SHA1 b12da9cb5d024555405040e65ad89d16ae749502
SHA256 05d8cf394190f3a707abfb25fb44d7da9d5f533d7d2063b23c00cc11253c8be7
CRC32 DE918CC3
ssdeep 24576:FJs7DlG83U/hcSO3UTyYPeuZtxY+8aiB8ea:FC7hGOSPT/PxebaiO
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 69e3648bf84e9db3_Violenza.avi
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\Violenza.avi
Size 921.8KB
Processes 5192 (vpn.exe)
Type data
MD5 31145ea1e499b0b8db8db32f0a415972
SHA1 3e3c9b4bb9619d32c6023c3a97d175e07f5b2965
SHA256 69e3648bf84e9db3bec58a432d94db7c38e7f7bca32a17682019e7fe8f2a71a4
CRC32 206AC2F7
ssdeep 24576:QJs7DlG83U/hcSO3UTyYPeuZtxY+8aiB8ea:QC7hGOSPT/PxebaiO
Yara
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 4107f634ef1c182c_Dare.avi
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\Dare.avi
Size 139.0KB
Processes 5192 (vpn.exe) 8868 (Strette.exe.com)
Type data
MD5 902c230eef7e722cd1165886f3d0cf36
SHA1 0f4a4e8881476efef5a673857b69395559f98957
SHA256 4107f634ef1c182c5dd00371a11842c13130660aa28dd6c9ab468c449dae426c
CRC32 C73EBC27
ssdeep 3072:a42XJgYdG7EuJQWCtPeyRKBLmyb5Kvym9nNozfEdwNt9snBWuD:V2ZgYYAiQ7PZRKBrKKm9n+Lqot9S
Yara None matched
VirusTotal Search for analysis
Name ad9157dbb2093982_Grado.avi
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\Grado.avi
Size 398.0B
Processes 5192 (vpn.exe)
Type ASCII text, with CRLF line terminators
MD5 c6a73bded14590d9870d8576b979a691
SHA1 fd660ba8b61191ffdb478ab03f2a45508740b8a9
SHA256 ad9157dbb209398209b217482c6d3a2f3076bb8c4870ba82aa2736e9430dc87a
CRC32 C089BFE0
ssdeep 6:j7VIkq9B+df0vKHilgGiTw+dZN8lJX53/JibfxAbGd/PELmEizDwCIoUDXSLp0n:XikqW9WK5Gyw7Tp0bybN/SUXTS90n
Yara None matched
VirusTotal Search for analysis
Name 338287ddb5fdbf0f_adprovider.dll
Submit file
Filepath C:\Program Files (x86)\foler\olader\adprovider.dll
Size 48.5KB
Processes 5032 (lv.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f981199c82a40cf638d313c4498ecab9
SHA1 9f2ba1092a90b048aaf51304d139018e13144f3b
SHA256 338287ddb5fdbf0f7540dac8ae8a3f02643f7b45f3b401a9dfa6447e39043049
CRC32 BB3860CF
ssdeep 768:Amge8Q4UsMhIrA1pifdlIGHmizKO6EjjKRyGlqesRtgjEDy:AG548IrA1pifdRHmizKiWRPlqPjy
Yara
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsv23.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsv23.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name e00c16044db11343_r
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\r
Size 658.9KB
Type ASCII text, with very long lines, with CRLF, CR, LF line terminators
MD5 f4b762b9b0971f2ccae4ee84f31e0f5d
SHA1 5b7948df423d00e548c293a5dbf225e8245703e8
SHA256 e00c16044db11343383938a0d5f221efcd9e56c213b7e6d7b6b07a596ce996d6
CRC32 38E63766
ssdeep 6144:XHQpGNdws1f/BRsEDXmA/OKQRZPV06T2yx8mAPHu1Log62urMYoZnnoiMF2RQGPm:XHQQ8Kfr1b1/ARRVnsqkg6G7CMO
Yara
  • NPKI_Zero - File included NPKI
VirusTotal Search for analysis
Name 53863a0ae081ae7f_4.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\New Feature\4.exe
Size 316.5KB
Processes 5032 (lv.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 93881c3c3d456d1f8624e71e30cd1ad8
SHA1 9f9fa3cea5bef5671cdba18c9eda31c59d5e3cdf
SHA256 53863a0ae081ae7f054a03910733d5bef86d6fe6b3f5c4b41d21d6a65908fdbe
CRC32 416CD5E6
ssdeep 6144:YBPovLu0njheWdVjLzGweoXLKUyeRIV+4CKukqfQJSt:mPovLDnjheWdVFrXLKUpIV+X3km
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • Trojan_Win32_Glupteba_1_Zero - Trojan Win32 Glupteba
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 727b96dca0363f7c_acledit.dll
Submit file
Filepath C:\Program Files (x86)\foler\olader\acledit.dll
Size 8.5KB
Processes 5032 (lv.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 8d96cb171b4138f43a754317be9e982c
SHA1 3c2975e7904486f39be0455a63afaa063064a93e
SHA256 727b96dca0363f7cd5767f94bf72e0655ef1d00f44b27d496deb733eb32be12b
CRC32 1D0A1442
ssdeep 192:peH8gcV+GQqYTBBBAkvyMQ0F3OWYTWPGP:YH8gcV+GQqyAMD0WYTWPq
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 67fd3768dcc3b56e_vpn.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\New Feature\vpn.exe
Size 1.2MB
Processes 5032 (lv.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
MD5 07aa7447c3a474296c03d334fa898fc4
SHA1 5b77043a3ca12bd285b4b22c09b9ce9051319490
SHA256 67fd3768dcc3b56ee90ff2845f8987c45995650a258f6f45153983f91d0006df
CRC32 CA4BB63A
ssdeep 24576:j5LOj8gIm2F0Gd+DhlHfP+0NKrrK4XYhlVwy0H9KXjl34LqU5MdAULFh9F:j5LOjUmRGk9lsK4XYXVwV9KTlouU5MAO
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 949fd56c5a63d3f1_acppage.dll
Submit file
Filepath C:\Program Files (x86)\foler\olader\acppage.dll
Size 45.5KB
Processes 5032 (lv.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 290075961dd4856211078377d14942c8
SHA1 ad7f6dfd89a253daa70d5bbb46e819dae7eb3f61
SHA256 949fd56c5a63d3f1c20769bc2285ac5517c4ca84250c807f18247a2d93efc1a4
CRC32 9B4259D7
ssdeep 768:ppb1tuabwj1WVIlaFKuIJJPclXkxAc5J9UaXotuM5Uqw2mom:Uj1WelaFczPclwYtuM6qw2
Yara
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsPE32 - (no description)
VirusTotal Search for analysis