Dropped Files | ZeroBOX
Name 9eef496942fe7166_run.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\run.dat
Size 8.0B
Processes 1808 (MSBuild.exe)
Type Non-ISO extended-ASCII text, with no line terminators
MD5 a38949d633c3c86afc1340ed94cbc4f6
SHA1 1e87e3d35c2d0c166aec595b786ba72b2bf4dd8c
SHA256 9eef496942fe7166590945edaada3cafc63880121b9299d1d2740a379de9c81f
CRC32 7BDEE3C0
ssdeep 3:7:7
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsz7CAB.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsz7CAB.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name f8098a6290118f29_settings.bin
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\settings.bin
Size 40.0B
Processes 1808 (MSBuild.exe)
Type data
MD5 4e5e92e2369688041cc82ef9650eded2
SHA1 15e44f2f3194ee232b44e9684163b6f66472c862
SHA256 f8098a6290118f2944b9e7c842bd014377d45844379f863b00d54515a8a64b48
CRC32 C6B6460B
ssdeep 3:9bzY6oRDT6P2bfVn1:RzWDT621
Yara None matched
VirusTotal Search for analysis
Name bc31315f37cd1953_tducbjope.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nse7CCB.tmp\tducbjope.dll
Size 40.0KB
Processes 1196 (vbc.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0d374c2efe222ab4d32736171ea4c259
SHA1 5b62b82306089c420dd5a627d5346685b8bcd77e
SHA256 bc31315f37cd1953df941e1b0b16f332e1c1f084422154df50ba94416e380c2e
CRC32 B1C4532A
ssdeep 768:xF8Y0OXx0Pg+6tihYts7sTHvmAm/C4962PuKnOjEzz5r5hPJaGWKhXqpOO05uZ89:ANOAOkthTRaGWKMAOzZdvG
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 5eacf2974c9bb2c2_storage.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\storage.dat
Size 416.8KB
Processes 1808 (MSBuild.exe)
Type data
MD5 963d5e2c9c0008dff05518b47c367a7f
SHA1 c183d601fabbc9ac8fbfa0a0937decc677535e74
SHA256 5eacf2974c9bb2c2e24cdc651c4840dd6f4b76a98f0e85e90279f1dbb2e6f3c0
CRC32 D1596006
ssdeep 12288:zKf137EiDsTjevgA4p0V7njXuWSvdVU7V4OC0Rr:+134i2lp67i5d8+OCg
Yara None matched
VirusTotal Search for analysis
Name 07c17e694f7464d2_cm2rb6y0wkuor462zj
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\cm2rb6y0wkuor462zj
Size 202.5KB
Processes 1196 (vbc.exe)
Type data
MD5 7b91d0b01c73040b06f4384a625da98f
SHA1 bd317a4f0392cc36c1bdf91f542e9770dd43ae53
SHA256 07c17e694f7464d22f902395c828fc8836147e0325313c8a14bb2f708cbcc6a8
CRC32 C99332AF
ssdeep 6144:+YZ1o1KxOCWGpLaVHTdctkdsYx6J7R+lYttXwUmKBPB:I1A0wUZctkyxRC7iB
Yara None matched
VirusTotal Search for analysis
Name 5347661365e7ad2c_catalog.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\catalog.dat
Size 232.0B
Processes 1808 (MSBuild.exe)
Type data
MD5 32d0aae13696ff7f8af33b2d22451028
SHA1 ef80c4e0db2ae8ef288027c9d3518e6950b583a4
SHA256 5347661365e7ad2c1acc27ab0d150ffa097d9246bb3626fca06989e976e8dd29
CRC32 36FCB1A3
ssdeep 6:X4LDAnybgCFcpJSQwP4d7ZrqJgTFwoaw+9XU4:X4LEnybgCFCtvd7ZrCgpwoaw+Z9
Yara None matched
VirusTotal Search for analysis