Dropped Files | ZeroBOX
Name 7676e145db131128_557343.od
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\557343.od
Size 134.0B
Processes 2648 (EXCEL.EXE)
Type ASCII text, with CRLF line terminators
MD5 4bac14773d3d4b4db362e756ba9f4ad7
SHA1 4ebcf19cff33a180ba6c48404eccc1fd652689a2
SHA256 7676e145db13112898d78590c18301d74f67718bec54969b4a7dbe77ab082e22
CRC32 5FE87673
ssdeep 3:OFrpRCMKLovyafNREalYEC9WoIk5zAajEY5RcdBjjSUvv:OKMKcaaYal9oIkkY5KZSQv
Yara None matched
VirusTotal Search for analysis
Name 3cba24dba02d5817_qdialogformattext.dll
Submit file
Filepath C:\ProgramData\qDialogFormatText.dll
Size 176.5KB
Processes 2932 (mshta.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 aae1e725e2dbfd91213be22e857f9d02
SHA1 7a2c52b1185e6024787eadaf18bd7f7ccfaa0f14
SHA256 3cba24dba02d5817a029caee6eadf1b3b4eb75ff861c62df3e4d4fbde1c349c2
CRC32 BD62FE4C
ssdeep 3072:TVadvfvemTEtQ9yoZPW/k/nklVtu77wBeZUCEQZRpdBDp57WQhdIif4:4DTyJWPd/nkdqw4/HdB77WQhdIu
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Win32_Trojan_Dridex_Gene_Zero - Win32 Trojan Dridex Gene
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis