Dropped Files | ZeroBOX
Name b75188fc81ab9a94_69ddcba757bf72f7d36c464c71f42baab150b2b9
Submit file
Filepath C:\Sandbox\test22\69ddcba757bf72f7d36c464c71f42baab150b2b9
Size 263.0B
Processes 1908 (Stub.exe)
Type ASCII text, with no line terminators
MD5 467db299a59de27ef6c4a23bf975162a
SHA1 6785b23548a8df9142bb24c706abe8341dad6f89
SHA256 b75188fc81ab9a949e01175a5e9509a23c610197383450bd09ac0eb22972d2ce
CRC32 11C4CEB8
ssdeep 6:KNfzpb0P+TnkQoydGxkUIXkDpw64hAdAf5o5W/:s7ptCxa0FJdAf0W/
Yara None matched
VirusTotal Search for analysis
Name 1865e70e22d4879d_4c9b855c10082cab3681da47ee89f85cd2ccde5f
Submit file
Filepath C:\PerfLogs\Admin\4c9b855c10082cab3681da47ee89f85cd2ccde5f
Size 434.0B
Processes 1908 (Stub.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 b83219d42684b0e790402b82bfc97a69
SHA1 48ff9deef4d750d7be403140834936862e6fc922
SHA256 1865e70e22d4879d73993d7e6710b0d050010645de4200b8c0cb912e25a2d586
CRC32 8B32C0EF
ssdeep 12:K3gXlVHK8srRi8NprCEx7afFRJCHEziiUaiPtotV1C:bOrRfCEx7KFzEGNcotG
Yara None matched
VirusTotal Search for analysis
Name adc5dc994409adac_24dbde2999530ef5fd907494bc374d663924116c
Submit file
Filepath C:\Users\Default\24dbde2999530ef5fd907494bc374d663924116c
Size 43.0B
Processes 1908 (Stub.exe)
Type ASCII text, with no line terminators
MD5 def88f67b60a69ee0757a402db52f938
SHA1 90d4418e908268a50b436a96ec698340fbc057b4
SHA256 adc5dc994409adacfeb83fa27be1792e043a4875f4968ebb3ccc1a9ae1a1c963
CRC32 02A94120
ssdeep 3:Zgkgfcb38:iTg38
Yara None matched
VirusTotal Search for analysis
Name 48e0e1764926eb40_oezDT0taNW.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\oezDT0taNW.bat
Size 203.0B
Processes 1908 (Stub.exe) 2740 (cmd.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 94ce6408d8bb0c0e9d966fe468487c2d
SHA1 c83ec126173c4edddb182cacec3ca44ae5ce96f9
SHA256 48e0e1764926eb40ec5f724e4b4c7c53c12671cc9a73ecb0f80a0fcfee4fb294
CRC32 C0653A6D
ssdeep 6:hCijTg3Nou11r+DECf4vKOZG1mQpcLJ23fZxVRCyoh:HTg9YDECXOLMFPG
Yara None matched
VirusTotal Search for analysis
Name 329e980cf42a15d0_drivergraphdevicea.exe
Submit file
Filepath C:\ProgramData\DriverGraphDevicea.exe
Size 7.4MB
Processes 2624 (smss.exe)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 8cd485bd4d8ae4ba147f49b5f132ccac
SHA1 b5b5592ad598fed52a5ca4ee86160b1773cdc6bb
SHA256 329e980cf42a15d055146226d1e0ad1cf8063c70934eb960892e5b9b28462c70
CRC32 D3279984
ssdeep 196608:upXfZvsxcjjAdgJoqWjSUmoseNwvihSAtFI4L:u9lsxcgdKoqWjieNwvAT3
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer
VirusTotal Search for analysis
Name 3f35fff489899366_f45ZUHsRi7
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\f45ZUHsRi7
Size 25.0B
Processes 1908 (Stub.exe)
Type ASCII text, with no line terminators
MD5 e6189d31680916fc5962cf6bcb199a91
SHA1 a9fa92b946342f5351a562db7edde0ee9ea2a56c
SHA256 3f35fff4898993661f6698718f38386e8a1bd1f7a61d81d116864a0e57800671
CRC32 EB85F307
ssdeep 3:9r2nKeln:hEKel
Yara None matched
VirusTotal Search for analysis
Name a18018160fa55e9e_ad905248ae8915310f4f54ea4fdbd093383798d1
Submit file
Filepath C:\Python27\NEWS\ad905248ae8915310f4f54ea4fdbd093383798d1
Size 510.0B
Processes 1908 (Stub.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 f4b17ed121c7120d8b4bca76301bbfc7
SHA1 636aaaaa0fdc912643777353fa37618d816b136a
SHA256 a18018160fa55e9e5ac10b55f1b699e2cf8533963e34df13c401c11b83734d31
CRC32 D74FC46E
ssdeep 12:U2OWhlJRb6s+P75P9U9xG9spl8XFuX2qdDpF:vjhlb6s+91kxGi1F
Yara None matched
VirusTotal Search for analysis
Name b25faea90c6b4a43_e8aa3d0a77e909b354881c464e4c4a775ddb75b2
Submit file
Filepath C:\Windows\System32\sensrsvc\e8aa3d0a77e909b354881c464e4c4a775ddb75b2
Size 726.0B
Processes 1908 (Stub.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 af22e312c7ddb6e33175508e8a346736
SHA1 e4f8194baf1544274d306eead87e0dc767ef64db
SHA256 b25faea90c6b4a437f078eaef878a3aa25f953adbc697cff225743dedbb22d58
CRC32 C96CC86D
ssdeep 12:KWXjevYeeOcug0jS4OR4HQS8mYTSP+kOFLsBl/c6qOqRPtGAG7kDiyDIjHiUZafO:KWKXcf/omT6O9ss3OqR9GGSae
Yara None matched
VirusTotal Search for analysis