Dropped Files | ZeroBOX
Name 3086d914f6b23268_tmpD06A.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmpD06A.tmp
Size 1.3KB
Processes 2400 (RegSvcs.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 8cad1b41587ced0f1e74396794f31d58
SHA1 11054bf74fcf5e8e412768035e4dae43aa7b710f
SHA256 3086d914f6b23268f8a12cb1a05516cd5465c2577e1d1e449f1b45c8e5e8f83c
CRC32 49853FE8
ssdeep 24:2dH4+S/4oL600QlMhEMjn5pwjVLUYODOLG9RJh7h8gK0mXxtn:cbk4oL600QydbQxIYODOLedq3ZXj
Yara None matched
VirusTotal Search for analysis
Name f8098a6290118f29_settings.bin
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\settings.bin
Size 40.0B
Processes 2400 (RegSvcs.exe)
Type data
MD5 4e5e92e2369688041cc82ef9650eded2
SHA1 15e44f2f3194ee232b44e9684163b6f66472c862
SHA256 f8098a6290118f2944b9e7c842bd014377d45844379f863b00d54515a8a64b48
CRC32 C6B6460B
ssdeep 3:9bzY6oRDT6P2bfVn1:RzWDT621
Yara None matched
VirusTotal Search for analysis
Name bb9181b3935b8681_tmpD1A4.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmpD1A4.tmp
Size 1.3KB
Processes 2400 (RegSvcs.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 be81f72fa4dbc827132836ee2af92c96
SHA1 fe5ded04ab4932dea6cf414e9e4428f43da70d03
SHA256 bb9181b3935b8681a71b578f8166883e61380de6181df82d05f14829323fbf0f
CRC32 7AA438E3
ssdeep 24:2dH4+S/4oL600QlMhEMjn5pwjVLUYODOLG9RJh7h8gK0Rb5xtn:cbk4oL600QydbQxIYODOLedq3Sb5j
Yara None matched
VirusTotal Search for analysis
Name 0bd3aac12623520c_storage.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\storage.dat
Size 319.8KB
Processes 2400 (RegSvcs.exe)
Type data
MD5 7e8f4a764b981d5b82d1cc49d341e9c6
SHA1 d9f0685a028fb219e1a6286aefb7d6fcfc778b85
SHA256 0bd3aac12623520c4e2031c8b96b4a154702f36f97f643158e91e987d317b480
CRC32 F31C2239
ssdeep 6144:oX44S90aTiB66x3Pl6nGV4bfD6wXPIZ9iBj0UeprGm2d7Tm:LkjYGsfGUc9iB4UeprKdnm
Yara None matched
VirusTotal Search for analysis
Name 60bae92e8c75771d_run.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\run.dat
Size 8.0B
Processes 2400 (RegSvcs.exe)
Type data
MD5 56fa072c71d13cbe07b347f49b941ec6
SHA1 35b7355ab613ae6f845704c48bcf3540913172c4
SHA256 60bae92e8c75771d2d7e78ad6b83b7872081baf0a1dc8bc20704531b368cc498
CRC32 1266BF24
ssdeep 3:LIq8t:A
Yara None matched
VirusTotal Search for analysis
Name d46e34924067eb07_task.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\task.dat
Size 57.0B
Processes 2400 (RegSvcs.exe)
Type ASCII text, with no line terminators
MD5 08e799e8e9b4fda648f2500a40a11933
SHA1 ac76b5e20ded247803448a2f586731ed7d84b9f3
SHA256 d46e34924067eb071d1f031c0bc015f4b711edce64d8ae00f24f29e73ecb71db
CRC32 EEF8DB45
ssdeep 3:oMty8WddSWA1KMNn:oMLW6WA1j
Yara None matched
VirusTotal Search for analysis
Name 13ea51306da74982_tmpCD2E.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmpCD2E.tmp
Size 1.6KB
Processes 2504 (UFC~0398763535603876534536789.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 3632723257d9411f9f2d53e249fd5937
SHA1 1ab9c1fe47ecaae6ca8f243006181a8d5967900a
SHA256 13ea51306da7498265b4088131105eb188db09495788421acb8cd42032405c49
CRC32 B33249AE
ssdeep 24:2dH4+SEqCH/7IlNMFQ/rlMhEMjnGpwjpIgUYODOLD9RJh7h8gKB2tn:cbhf7IlNQQ/rydbz9I3YODOLNdq3W
Yara None matched
VirusTotal Search for analysis
Name 5347661365e7ad2c_catalog.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\017BD04F-B3BF-45B6-8167-9E8F41FF87BF\catalog.dat
Size 232.0B
Processes 2400 (RegSvcs.exe)
Type data
MD5 32d0aae13696ff7f8af33b2d22451028
SHA1 ef80c4e0db2ae8ef288027c9d3518e6950b583a4
SHA256 5347661365e7ad2c1acc27ab0d150ffa097d9246bb3626fca06989e976e8dd29
CRC32 36FCB1A3
ssdeep 6:X4LDAnybgCFcpJSQwP4d7ZrqJgTFwoaw+9XU4:X4LEnybgCFCtvd7ZrCgpwoaw+Z9
Yara None matched
VirusTotal Search for analysis