Dropped Files | ZeroBOX
Name 6987f229daf0e954_downflsetup999.exe
Submit file
Filepath C:\Program Files (x86)\Company\NewProduct\DownFlSetup999.exe
Size 60.5KB
Processes 2020 (Setup12.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 17f6f3213a5a5d2fb1ef8793081c5ddd
SHA1 4601bd223fd7c52b12bc186ec9a0eb94167aaebb
SHA256 6987f229daf0e954b67d5dbf779150b3b5c8dc3e69f66fe7c41f875be7725994
CRC32 4D282478
ssdeep 768:cjzm0ipsb7LDGRzZj4N8RM0jMzYT8suhDVnWUGUtE2KME1qSJV4XQL5eEgqpRMEd:w5qE7UZjTjMzAuZ9WUGp5BEoM1Z
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_EXE - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name a32e0a83001d2c5d_2.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$inst\2.tmp
Size 36.0B
Processes 2020 (Setup12.exe)
Type Microsoft Cabinet archive data, 36 bytes
MD5 8708699d2c73bed30a0a08d80f96d6d7
SHA1 684cb9d317146553e8c5269c8afb1539565f4f78
SHA256 a32e0a83001d2c5d41649063217923dac167809cab50ec5784078e41c9ec0f0f
CRC32 EAB67334
ssdeep 3:wDl:wDl
Yara None matched
VirusTotal Search for analysis
Name 403e45bc0d7f60e1_cm3.exe
Submit file
Filepath C:\Program Files (x86)\Company\NewProduct\cm3.exe
Size 1.4MB
Processes 2020 (Setup12.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 8e4e250394d303668ff165ba900fd344
SHA1 0022a4ab40567fe1356e9cd5bd994de3a22a7fa0
SHA256 403e45bc0d7f60e162971a54a68192df875c1cec2334de2399b637981ee8cb6e
CRC32 17454E43
ssdeep 24576:hbcW3FS7tXBZGCVX2GM7a5HnTzQ/O+1qgqSn44Guvqs:hbJsJXPGGX2GeahQW+/dGzs
Yara
  • ASPack_Zero - ASPack packed file
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 858c061538dfc44b_temp_0.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$inst\temp_0.tmp
Size 798.7KB
Processes 2020 (Setup12.exe)
Type Microsoft Cabinet archive data, 817870 bytes, 4 files
MD5 3366e03e90d1b8e9c6520918daadf4a0
SHA1 8425a191a444b78bf59e2efee70d9e7fae666e25
SHA256 858c061538dfc44b5a619439f2f1218eb240a29cd133d376e461f85af1e497cb
CRC32 7E4487BA
ssdeep 12288:+jMvQBJ5RpL3EbGCS5xInDjAfCxGSBBcSxRiQAPlCa/ylQe/q2k6GTc4Wy6NMXgv:9aRh0ShqDCXrSOIjQywT/W1Nmgd4t+/
Yara None matched
VirusTotal Search for analysis
Name d3d0b963d898bf3c_inst002.exe
Submit file
Filepath C:\Program Files (x86)\Company\NewProduct\inst002.exe
Size 213.0KB
Processes 2020 (Setup12.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 765e53b7873cf667a9ba7e3b4e0f4edf
SHA1 1ef4929386dcbdbc0c3b46e391b6ca77bbdec7be
SHA256 d3d0b963d898bf3c5413ea1b3a25a11930a033a9533d113afdca78b00256f245
CRC32 A1A924A1
ssdeep 3072:7DOjBLxoC9PZUFfYS3azG0CG0jOMrqwsQwEFHO4LjH9YOAVF7NHJuMoVi:7aj1Sf7oQzjOM3SkLjH9YOCSM/
Yara
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name ca5cc8dfca152301_uninstall.ini
Submit file
Filepath C:\Program Files (x86)\Company\NewProduct\Uninstall.ini
Size 2.5KB
Processes 2020 (Setup12.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 6690fa3abac0ad4885ac0940a8a13c48
SHA1 562c4439cfddb09d97400a50d6281ea6a0f0dfb3
SHA256 ca5cc8dfca1523017b6d5f9645c8c219a279756081f2bd00a7b662e791918bf5
CRC32 F3B92DEA
ssdeep 48:RP7Rij9z39zH9394989zC9r9x9399L9f9/9u9G9G17eHdGVydsJWM0qK1PY6Eh:sxBNW6AxzN9RFloBxNVJJWqwPm
Yara None matched
VirusTotal Search for analysis
Name b3a3c03a2b140d4f_uninstall.exe
Submit file
Filepath C:\Program Files (x86)\Company\NewProduct\Uninstall.exe
Size 97.6KB
Processes 2020 (Setup12.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 56b3225c7b1d6f05b4ba4ba7b4ce2202
SHA1 27c0ed1a6d25a68a48950a7ede29d87e1f2b1461
SHA256 b3a3c03a2b140d4fbe9bac4416866210d014da4c64355b395715f2d4c2506c46
CRC32 6DE3DA1A
ssdeep 1536:zO/z6hPABUjO/Zd1716EoLiL4l1HdIaqQPDm0xK8i6f0Zn9PRVW8sW45o75M:kzgjO/Zd1RePDmZ8tf05iW4u1M
Yara
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis