Dropped Files | ZeroBOX
Name 5ccfb6be14d5f0bc_nznbdbgkdqms
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nznbdbgkdqms
Size 45.1KB
Processes 112 (blem.exe)
Type data
MD5 b300f6604bee3d0e10105190fee8c89e
SHA1 17a6973fa8fd7114f176ed547f548ed6fb9fad1f
SHA256 5ccfb6be14d5f0bc57cbd01ea541f35be53c974e2fab14a5b2464c06a16e6e24
CRC32 A22CE709
ssdeep 768:o6Ygs7jkV3cgwxh29BodaUimi6/grfxYazvhuruwXZOWeYC6:Wgs7IIxh28YUibbf6ovh2unW/
Yara None matched
VirusTotal Search for analysis
Name 1cda7ff9a05d0a90_gkuilyhj38eiko57
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\gkuilyhj38eiko57
Size 104.0KB
Processes 112 (blem.exe)
Type data
MD5 24703f1ee3f10ebb6215e38ee4073ae5
SHA1 41fe0625d3f26d2bc4c8078039f06949d7f31915
SHA256 1cda7ff9a05d0a90a0fd20668468d5c354546f49555182fde313feec74830a4c
CRC32 ECE78180
ssdeep 1536:ULth/HpM/vzAE20dFrrsm6nvp6qFyGODNeFAtAIwrYM2A8EsUd2kQPOTCG8Ym8gZ:UziUy9qvf8DNqi9I8Et2/OTAYm8SwFa
Yara None matched
VirusTotal Search for analysis
Name 6b86b273ff34fce1_6D6F4D.lck
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.lck
Size 1.0B
Processes 2228 (blem.exe)
Type very short file (no magic)
MD5 c4ca4238a0b923820dcc509a6f75849b
SHA1 356a192b7913b04c54574d18c28d46e6395428ab
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
CRC32 83DCEFB7
ssdeep 3:U:U
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsw6450.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsw6450.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 852ddea984bc2f77_2greoikoq.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2GReoikOq.txt
Size 722.0B
Processes 112 (blem.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 12c1aa799a1d19ca68bad90834659be6
SHA1 9f7bc9724c097ac71ef340850929de316f642fdc
SHA256 852ddea984bc2f774dfc8d4f75abed36d87909ee038aec8909f28fa5e960c7de
CRC32 D1866A7F
ssdeep 12:zG8zDsR0UevQzQSspot72VlEU+tGYOc5nhzJGkYEcHEarkwU2ix2+HoLzShIs:68/2tevoeEg3+0YOc5+l3kbH1
Yara None matched
VirusTotal Search for analysis
Name 3de5dd963e6aaae9_2qkidcc.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2qKiDCC.doc
Size 18.5KB
Processes 112 (blem.exe)
Type Microsoft Word 2007+
MD5 29e0c22a8d346a92652a6be25d8f2884
SHA1 4ddef593f73d0624e4f14552bfbfa4e37242c65b
SHA256 3de5dd963e6aaae92913297570e7f7702ed9da4aacb67366c7ae545c76fe98eb
CRC32 91F0DBBD
ssdeep 384:fRdzZyRJJ0HYr/Nz5SVM27qNxt/ZtNN34LFfILiPZiO11y8AqenE:b26YrdUrExllN34LtILiPMtqp
Yara None matched
VirusTotal Search for analysis
Name dc58d8ad81cacb0c_system.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsr6480.tmp\System.dll
Size 11.0KB
Processes 112 (blem.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c17103ae9072a06da581dec998343fc1
SHA1 b72148c6bdfaada8b8c3f950e610ee7cf1da1f8d
SHA256 dc58d8ad81cacb0c1ed72e33bff8f23ea40b5252b5bb55d393a0903e6819ae2f
CRC32 BFEE9B1E
ssdeep 192:7DKnJZCv6VmbJQC+tFiUdK7ckD4gRXKQx+LQ2CSF:7ViJrtFRdbmXK8+PCw
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis