Dropped Files | ZeroBOX
Name 2f7a99389b477937_run.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\run.dat
Size 8.0B
Processes 2592 (InstallUtil.exe)
Type ISO-8859 text, with no line terminators
MD5 b420fbbdd8ba3aef9fbe99ec2a316482
SHA1 186f6c1cbb4d370d4ccfa1dfb85753e804c769c9
SHA256 2f7a99389b4779373399c43d125ce0bc2f04cfcfbd184080992cc2f8f7c8e8c8
CRC32 4C13AE53
ssdeep 3:n8:n8
Yara None matched
VirusTotal Search for analysis
Name e3fa1ef18094694c_tmp4CBC.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmp4CBC.tmp
Size 1.3KB
Processes 2592 (InstallUtil.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 4386ac3d9bca272121bfea60023b104a
SHA1 99704cc6316d4d8548b8f2024e27e006d5b35a18
SHA256 e3fa1ef18094694c18d7c2e0292619d8d47b6f5f951711481a7d2e4192b5da3d
CRC32 C45CE82C
ssdeep 24:2dH4+S/4oL600QlMhEMjn5pwjVLUYODOLG9RJh7h8gK0ZKxtn:cbk4oL600QydbQxIYODOLedq3YKj
Yara None matched
VirusTotal Search for analysis
Name 49c4a85bce2fb8cb_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2848 (powershell.exe)
Type data
MD5 4eba3b6a4f05a26106a2d772c79da044
SHA1 45ae375ea2f305e4409aabc22803cd1471f0983e
SHA256 49c4a85bce2fb8cb6db4279591d0966cbd2fb84bc43f252ee5ad14d3d615b2b5
CRC32 2DF7F691
ssdeep 96:YtuCaGCPDXBqvsqvJCwo9tuCaGCPDXBqvsEHyqvJCworM7HwxWlUVul:YtzXo9tzbHnornxo
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name c492babfd9a1e676_task.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\task.dat
Size 50.0B
Processes 2592 (InstallUtil.exe)
Type ASCII text, with no line terminators
MD5 a891b64e388cfff7d0f64c25bb06897f
SHA1 768afb095e85c1bbf7a250ebcbcd2283dfbeff2f
SHA256 c492babfd9a1e6767e001e936206c55f5f7952d3cefd603e171277856dbbee33
CRC32 3EFD409B
ssdeep 3:oNmWxpcL4E2J5xAIOWRxRI0dAn:oNmQpcLJ23f5RndA
Yara None matched
VirusTotal Search for analysis