Dropped Files | ZeroBOX
Name d1ba03fd533eb383_explorer.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\explorer.exe
Size 440.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 754cae6c58cfb857c870d38ef49e2959
SHA1 468e173ccf9a2f3a429aa05548e03295989d278e
SHA256 d1ba03fd533eb3834a4448172fc9f792ed54096f2718a84eebf719cb22d2fa1e
CRC32 62C55D72
ssdeep 12288:9Ye6UWhaT5xnDdLv9rX+1jZJqxE/ZjEcyib:v6UWUT5xDN9IjZJsCZDyg
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
VirusTotal Search for analysis
Name 883c6520bb4593fc_install.vbs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\install.vbs
Size 534.0B
Processes 560 (explorer.exe) 1744 (wscript.exe)
Type data
MD5 fc1993a14069476937c73e9ab520ebd8
SHA1 2efb08cde8319ae2300769f403f2aa709f32fd85
SHA256 883c6520bb4593fc019751fac9fa0b45b4574e88a77dba96acefcb309c8fb627
CRC32 71107B4B
ssdeep 12:4D8o++ugypjBQMB3Ds/Q1bS9ZvFQ4lOc+UNIQSF0M/0aimi:4Dh+SMTLBS9hFNOc+sIQSF0Nait
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis