Dropped Files | ZeroBOX
Name bd41a06c930c471a_windows update.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Windows Update.exe
Size 140.0KB
Processes 112 (Handlour.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d9350714f20b7d66cf6ea1938da7016d
SHA1 565d60c1ef7ce8953897d7bf38536f67235f956e
SHA256 bd41a06c930c471a6f26073337cd3c49594eebac347704f765df1719fb53001a
CRC32 89B29174
ssdeep 3072:jQkH0rCKLsQKiUkTUT5DCfhXXscSgvj9XiJjYyWNLPQh8B6RxXF:AsQKEsQXXtYj3WVYWgR
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 5caac962de01bd76_security.config.cch
Submit file
Filepath c:\windows\microsoft.net\framework64\v2.0.50727\config\security.config.cch
Size 430.0B
Processes 2724 (Windows Update.exe)
Type data
MD5 768dfc1e8e7cb5c166092cea17d3de30
SHA1 6019ee4b0ec74bcfa3004dc32cc94fc3f8c24220
SHA256 5caac962de01bd762743916f4efd66c45650e683c98f5298edbc4ac80ca0e670
CRC32 5C55B900
ssdeep 12:s6WfKKtHaK+wTUBmQHJkcL5nQa1Q2cL5BKh:0plh+cUfGcLWb2cLb
Yara None matched
VirusTotal Search for analysis
Name 8a0d5d6c5ab131ba_windows update.exe.config
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Windows Update.exe.config
Size 1.8KB
Processes 112 (Handlour.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 a2ebf843442988ee2d667e9c7fc28ce1
SHA1 7f24c475bb217c448090dce593abee8957b7b1d4
SHA256 8a0d5d6c5ab131bab9c8a29a7bcc81d6470ec515f2e4bca977a4fe62fd156acc
CRC32 F40991DE
ssdeep 24:2dZmhW3aXfygeOygjOgC5XgtXdXkBHnUdQzFDWby2GpyI:cccAfyge7gjOgCNgBRkBHUdQzqQ
Yara None matched
VirusTotal Search for analysis