Dropped Files | ZeroBOX
Name 49c4a85bce2fb8cb_d93f411851d7c929.customDestinations-ms~RF2d2a70.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF2d2a70.TMP
Size 7.8KB
Processes 1080 (powershell.exe) 2320 (powershell.exe)
Type data
MD5 4eba3b6a4f05a26106a2d772c79da044
SHA1 45ae375ea2f305e4409aabc22803cd1471f0983e
SHA256 49c4a85bce2fb8cb6db4279591d0966cbd2fb84bc43f252ee5ad14d3d615b2b5
CRC32 2DF7F691
ssdeep 96:YtuCaGCPDXBqvsqvJCwo9tuCaGCPDXBqvsEHyqvJCworM7HwxWlUVul:YtzXo9tzbHnornxo
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 21bdb36f30fa7fde_logs.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\remcos\logs.dat
Size 148.0B
Processes 2504 (ConsoleApp19.exe)
Type data
MD5 d939f0765fecd2ab5454c02a605cecf3
SHA1 534227902bd33df0111c22f1b9b6cac0e61b016d
SHA256 21bdb36f30fa7fdef5d353450a09f39f695120248483ebf2bc8cd98dbf9744de
CRC32 F4F3765E
ssdeep 3:rklKlRlrPlJWWl5JWRal2Jl+7R0DAlBG4LNQblovDl9il:IlKR15YcIeeDAlybW/G
Yara None matched
VirusTotal Search for analysis