Dropped Files | ZeroBOX
Name a96001f92f190490_590aee7bdd69b59b.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\590aee7bdd69b59b.customdestinations-ms
Size 7.8KB
Processes 6324 (powershell.exe)
Type data
MD5 77dfc370498534a5df1fc467d3ee73ce
SHA1 5fcef2d483ab8d5d1c89c9efe50734ca29f01ec4
SHA256 a96001f92f1904904e6cc962ef38ee4a4b4f486d254ea4e10fbb8192aec33ad8
CRC32 7851B322
ssdeep 96:wtuCiGCPDXBqvsqvJCwoNtuCiGCPDXBqvsEHyqvJCwor3tDHXyGlUVul:wt7XoNt7bHnordTyY
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name 7c822b9b7bd88bb0__gorlno.vbs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\_Gorlno.vbs
Size 174.0B
Processes 3588 (ConsoleApp2.exe)
Type ASCII text, with no line terminators
MD5 8253540f19ccd6ca00247ef7d6dd9961
SHA1 0a1bf22dbd06745d5db71a040ebb25232026fa43
SHA256 7c822b9b7bd88bb0b3c914ec61e51632d24df2adf16fd51da2ec8406ff0f3456
CRC32 F4B72577
ssdeep 3:FER/n0eFHgSSJJF2uV1HeGAFddGeWLCXknRAumWxpcL4EaKC5SufyM1K/RFofD6Z:FER/lFHsCu/eGgdEYmRAumQpcLJaZ5ST
Yara None matched
VirusTotal Search for analysis