Dropped Burrfers | ZeroBOX
Name 9984d91e532cb0dc8aae39bed4e5c4b2a3b87069
Size 96.0KB
Type data
MD5 830bca5ebc67b6607f6227a1a2e34f20
SHA1 9984d91e532cb0dc8aae39bed4e5c4b2a3b87069
SHA256 e1e01c050dfb1b954f06163766f18d14e7c84036de0c9b90fe25ef3d273bdbd2
CRC32 24096F7D
ssdeep 1536:zm386AEAxluBFKNmVRoib22SNSWQzf27Agbue7vhu3NyAsdtHi1xQeTEuG6WAaod:zi86AdLwhjWQzOR3hu9yddYsvs
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • Generic_Malware_Zero - Generic Malware
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 2a93f76004d3aed29c5af01aafe79a0ef22cd8f3
Size 4.9MB
Type ASCII text, with very long lines, with no line terminators
MD5 86f0af8a176a3036654b8cd02f43d078
SHA1 2a93f76004d3aed29c5af01aafe79a0ef22cd8f3
SHA256 d3629b8a1d9b4644b55eaf5fcb70058490525720072d391858d93db702b9c134
CRC32 2280E149
ssdeep 49152:6rDNH2VTPZi2dfmMqjf026aBzpX7rS3s2rtLPzratp6aiWFcHfhXhS4q6Jev4Cgs:e
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • NPKI_Zero - File included NPKI
VirusTotal Search for analysis
Name 9e2321218e0cb185860b5380d8816f44348eb56a
Size 112.0KB
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2efa9dff17dabe83b5c51d9a29baadbc
SHA1 9e2321218e0cb185860b5380d8816f44348eb56a
SHA256 ddbaba63652c0bc885150868b54a0056176c973dcf7b002056633a247255b4ad
CRC32 B3E27BA1
ssdeep 3072:Q71y9ujo3vmg2ZnEQ0O++zS7n7qidfoJc8kFRR:So3vvZT+61dfqc8E
Yara
  • IsDLL - (no description)
  • Is_DotNET_DLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 9c84ae6fae4fd9d6ce85ae0670869eaccb2fc5ef
Size 4.0KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 38186d09ff8b56847ab11e41a5cdd4fa
SHA1 9c84ae6fae4fd9d6ce85ae0670869eaccb2fc5ef
SHA256 aca71f1b7acbcfc356e659c026c73643a7980f17575ae16fe7bda2419b5fb27e
CRC32 97EB2DBD
ssdeep 48:1Iu+9Sj+eM8gVZOYZMVYZUkVYZUnVYxYZb1VYZfVYZ4NVYZwVYZjVYZPVYZVVYZD:1Iu8SZMfaKAwsGUmFIHg6Pf6/WD
Yara None matched
VirusTotal Search for analysis
Name 3630b3b52e0e1f9afae8f5e1a235750507de7ada
Size 4.9MB
Type ASCII text, with very long lines, with no line terminators
MD5 166d8c04e8c82fb2c17ed1b53f290090
SHA1 3630b3b52e0e1f9afae8f5e1a235750507de7ada
SHA256 c9a230e16e250f03d6e4be4937e9ca9030248b900a0bf824874799b4339097ce
CRC32 4256BEE0
ssdeep 49152:trDNH2VTPZi2dfmMqjf026aBzpX7rS3s2rtLPzratp6aiWFcHfhXhS4q6Jev4CgT:W
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • NPKI_Zero - File included NPKI
VirusTotal Search for analysis