Dropped Files | ZeroBOX
Name a95b1af74623d6d5_api-ms-win-crt-conio-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-conio-l1-1-0.dll
Size 18.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a668c5ee307457729203ae00edebb6b3
SHA1 2114d84cf3ec576785ebbe6b2184b0d634b86d71
SHA256 a95b1af74623d6d5d892760166b9bfac8926929571301921f1e62458e6d1a503
CRC32 F520332B
ssdeep 384:tW1hWv4wm0GftpBjp+m3S1ZXlndaYhpt1:k+FVib+ZvN
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name af5c9b14d811a06f_freebl3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\freebl3.dll
Size 654.4KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 96a762764215d2ddf88635970ed99ee8
SHA1 788dc89bdab7d5fec8fc2d83a67df7351a22d90e
SHA256 af5c9b14d811a06fd31d866f016f913dc1e02bfd4609c4c15c078ec9a02f40a9
CRC32 15498136
ssdeep 12288:oK/2xOWHGw3Lb3QzSa4+aSs2QsQNGV8PeaOCCk5IH7TnlapUleCNIkqnhvsS:o82jHG6s9FBnlaiUCNX+hvsS
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b5c725bbb475b5c0_api-ms-win-core-timezone-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-timezone-l1-1-0.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c9a55de62e53d747c5a7fddedef874f9
SHA1 c5c5a7a873a4d686bfe8e3da6dc70f724ce41bad
SHA256 b5c725bbb475b5c06cc6cb2a2c3c70008f229659f88fba25ccd5d5c698d06a4b
CRC32 AAFBA061
ssdeep 384:rWW1hWv4wm0GftpBjgpm3SSP9lndaYhpwe/:ReFVi02vZ
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name ff9b51aff7fbec8d_api-ms-win-core-processthreads-l1-1-1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-processthreads-l1-1-1.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 95c5b49af7f2c7d3cd0bc14b1e9efacb
SHA1 c400205c81140e60dffa8811c1906ce87c58971e
SHA256 ff9b51aff7fbec8d7fe5cc478b12492a59b38b068dc2b518324173bb3179a0e1
CRC32 0DA07FF3
ssdeep 384:NS8DfIelW1hWu4wm0GftpBjBFm3SzlJrI:NSLecfFViRTs
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name dc25a882ac454a00_api-ms-win-crt-private-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-private-l1-1-0.dll
Size 71.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3d139f57ed79d2c788e422ca26950446
SHA1 788e4fb5d1f46b0f1802761d0ae3addb8611c238
SHA256 dc25a882ac454a0071e4815b0e939dc161ba73b5c207b84afd96203c343b99c7
CRC32 231DA2AB
ssdeep 1536:g0DjXDe5c4bFE2Jy2cvxXWpD9d3334BkZnVPL9VG:XjDe5c4bFE2Jy2cvxXWpD9d3334BkZnI
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 4d0f0ea6e8478132_api-ms-win-crt-time-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-time-l1-1-0.dll
Size 20.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9b79fda359a269c63dcac69b2c81caa4
SHA1 a38c81b7a2ec158dfcfeb72cb7c04b3eb3ccc0fb
SHA256 4d0f0ea6e8478132892f9e674e27e2bc346622fc8989c704e5b2299a18c1d138
CRC32 D175B347
ssdeep 384:iUW1hWQ4wm0GftpBjddQxm3SLDlD16h1S:eRFViexn1
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 6c165000b5c1d15e_twain_32.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\twain_32.dll
Size 4.9MB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 650ef10656768f008f9b22d4ec15b81e
SHA1 943e593feb6e69e4f5db02ac23d32120d4cd6b06
SHA256 6c165000b5c1d15e35e664e8e730b6e7884862dbcb85fcfaa03b77bb75959904
CRC32 4D796BEC
ssdeep 98304:OUy4Rp4K/V5gLNVqhJVTS6ZCDH8OW1CVt07xZ1r5WFzHHSnX+/d3334g:OUyOqkJSSCDHz3oxZ19CHSnXyd3334g
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name adf1018fde3d5b8e_softokn3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\softokn3.dll
Size 237.9KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0c14687efcb63665d3ac27caa42d554d
SHA1 0fd5e609180eabac25eb5e71ecb13ae6f273f349
SHA256 adf1018fde3d5b8ecf77a3b0f2cf88121458b670a29233b1a3893d564eff50bf
CRC32 9C080203
ssdeep 6144:JZ88AUK9t6e81EsT2SayCpsjpxzTFI3OMBsYz+xnuu:JZ88AUK9tv81E2GzqxfW33iYz+xnr
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 9e6e4772050998a5_readme.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Rar$O0XlkDiS6Ei4twfJfGj1hLQFz\Files\readme.txt
Size 10.0B
Type ASCII text, with no line terminators
MD5 eb6b6c90251ab33cee784713c451e6d8
SHA1 451685e9efac4a6dc1fee73ec53ffb6b2c4c38b5
SHA256 9e6e4772050998a5c0dc3c61acf3dab0a7e594566171fa5746d6b62f9598efb6
CRC32 22598B08
ssdeep 3:IS:7
Yara None matched
VirusTotal Search for analysis
Name 340f01aafd909037_nss3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\nss3.dll
Size 1.9MB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 01596adbda40189da509305f816ba084
SHA1 cadc705e33f88f26ce4773d082e91fb884dac00e
SHA256 340f01aafd90903767bf391bbf2bddf1360ebfcc66a011e0322fe0f1487fa0bb
CRC32 A4E5BEE5
ssdeep 49152:5KOPddS6ZC+0mWLYMRW1CVt073pomZ1rPBWM:5VTS6ZCDH8OW1CVt07xZ1r5WM
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1ee8e99190cc31b1_api-ms-win-crt-runtime-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-runtime-l1-1-0.dll
Size 22.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 fb0ca6cbfff46be87ad729a1c4fde138
SHA1 2c302d1c535d5c40f31c3a75393118b40e1b2af9
SHA256 1ee8e99190cc31b104fb75e66928b8c73138902fefedbcfb54c409df50a364df
CRC32 6F7835CE
ssdeep 384:Lb7hrKkW1hW54wm0GftpBjGOm3SdWlmTwhctW:LbNrKn8FVinhZW
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 7bcab4ca00fb1f85_api-ms-win-crt-stdio-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-stdio-l1-1-0.dll
Size 23.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 d5166ab3034f0e1aa679bfa1907e5844
SHA1 851dd640cb34177c43b5f47b218a686c09fa6b4c
SHA256 7bcab4ca00fb1f85fea29dd3375f709317b984a6f3b9ba12b8cf1952f97beee5
CRC32 032AF397
ssdeep 384:/ZpFVhHW1hWxgYBm0GftpBjMm3SNlndaYhpn3p:boEVi6DBp
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 39723e61c9870303_api-ms-win-crt-math-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-math-l1-1-0.dll
Size 28.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 8da414c3524a869e5679c0678d1640c1
SHA1 60cf28792c68e9894878c31b323e68feb4676865
SHA256 39723e61c98703034b264b97ee0fe12e696c6560483d799020f9847d8a952672
CRC32 C1804F6C
ssdeep 384:jOTEmbM4Oe5grykfIgTmLmW1hWSsngm0GftpBjGm3SAlD16hX:lEMq5grxfIndCngVis5
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name ebcfd0fc3ecbf928_cock.mp4
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\cock.mp4
Size 4.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d050948cba26749ca0ae38c401cae549
SHA1 91a3471081352093d319e97abf787ecd7ecbd2d3
SHA256 ebcfd0fc3ecbf9281e9f42e858be21770fd7e3d92facd23d3dc589f01b1a1091
CRC32 6FA5B062
ssdeep 98304:Jf0gnUUlBQgyoOqHAvtgWgyuccfQ+qDh/d8:h0gUUlqHqMgyuTfQ2
Yara
  • VMProtect_Zero - VMProtect packed file
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 7e0f1c4d94b16944_Information.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Rar$O0XlkDiS6Ei4twfJfGj1hLQFz\Information.txt
Size 2.2KB
Processes 2232 (cock.mp4)
Type UTF-8 Unicode text, with CRLF line terminators
MD5 622726602fc666624baab7cad3a0bec3
SHA1 3b484ca28d52314130b03fe8ac186cea81e1970d
SHA256 7e0f1c4d94b169449e3d35d6ae21e2980bc040c8f17aaa29dd5cb86128e4c7c3
CRC32 4F74FE7F
ssdeep 48:Mhn1vBp7q9IrBhUIaF/njUD/amz+3ZrcaPEUsIWX/Rm8AuPpao8sqR2L/W/AWn3:MhtbkI17D/amzqtcaPEUsIWX/RtZxuzv
Yara None matched
VirusTotal Search for analysis
Name 675b1b82dd485cc8_api-ms-win-crt-heap-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-heap-l1-1-0.dll
Size 18.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 1776a2b85378b27825cf5e5a3a132d9a
SHA1 626f0e7f2f18f31ec304fe7a7af1a87cbbebb1df
SHA256 675b1b82dd485cc8c8a099272db9241d0d2a7f45424901f35231b79186ec47ee
CRC32 D8667874
ssdeep 384:XY3eBW1hWqvm0GftpBjtzsxm3SKulndaYhp6s:zQzViATv
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 385dd1a9abdedd4f_1.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1.exe
Size 4.1MB
Processes 2232 (cock.mp4)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4bd41881219e07bf5447ce23ee9707d1
SHA1 a965bdd8ee2b3867c0f8a391100ed2ffcb744314
SHA256 385dd1a9abdedd4fb43ea30f0a61f0b13354d487f782eaec015301323c46905a
CRC32 97F1AF87
ssdeep 98304:mEzyXcTqaJ9IyyPc2iBZ83hHla+FOuWyVO5mo8/xCVs:NzlTq742iBIHllFOhyxXwC
Yara
  • VMProtect_Zero - VMProtect packed file
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 7e6b33a4c0c84f18_api-ms-win-crt-utility-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-utility-l1-1-0.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 70e9104e743069b573ca12a3cd87ec33
SHA1 4290755b6a49212b2e969200e7a088d1713b84a2
SHA256 7e6b33a4c0c84f18f2be294ec63212245af4fd8354636804ffe5ee9a0d526d95
CRC32 2A6F241C
ssdeep 192:UfHQdurW1hWiSuDz7eCjdks/nGfe4pBjSYp2VZGW5RKTt3E2sVWQ4GWO3uDVqna9:UfVW1hWKDzDm0GftpBjYLm3Sy5lD16hC
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 707c9a384440d0b2_api-ms-win-crt-process-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-process-l1-1-0.dll
Size 18.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9d3d6f938c8672a12aea03f85d5330de
SHA1 6a7d6e84527eaf54d6f78dd1a5f20503e766a66c
SHA256 707c9a384440d0b2d067fc0335273f8851b02c3114842e17df9c54127910d7fb
CRC32 BCB83D61
ssdeep 192:hRQqjd7hW1hWif+49Cjdks/nGfe4pBjSYr+c24QLW5RKTt3E2sVWQ4GWw899qnaP:hKwW1hWZ4wm0GftpBjh24Jm3SwlUKTw2
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name b7c3ebc36c84630a_api-ms-win-crt-convert-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-convert-l1-1-0.dll
Size 21.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9ddea3cc96e0fdd3443cc60d649931b3
SHA1 af3cb7036318a8427f20b8561079e279119dca0e
SHA256 b7c3ebc36c84630a52d23d1c0e79d61012dfa44cdebdf039af31ec9e322845a5
CRC32 F47B82A5
ssdeep 384:FuyhW1hWF4wm0GftpBjErIm3StlndaYhpFeD:4cFViUIbi
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 56d8b7ee7619579a_api-ms-win-crt-environment-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-environment-l1-1-0.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 39325e5f023eb564c87d30f7e06dff23
SHA1 03dd79a7fbe3de1a29359b94ba2d554776bdd3fe
SHA256 56d8b7ee7619579a3c648eb130c9354ba1ba5b33a07a4f350370ee7b3653749a
CRC32 124E426A
ssdeep 192:4rW1hWiSu7jCjdks/nGfe4pBjSYC69poCxW5RKTt3E2sVWQ4GWmEsSC9qnajuZDW:AW1hW6am0GftpBjtBQm3SzSKlUKTT
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 8aac9dcb54d7073e_Screenshot.bmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Rar$O0XlkDiS6Ei4twfJfGj1hLQFz\Screenshot.bmp
Size 3.0MB
Processes 2232 (cock.mp4)
Type PC bitmap, Windows 3.x format, 1024 x 768 x 32
MD5 012b02cc27df10b386002725ffb4b5e8
SHA1 fc24a9ab99aca6dc15292aca84d35ecdda737eaf
SHA256 8aac9dcb54d7073ec435b75af0a0f99c95275cc593914fa4ca6a2390876a4124
CRC32 E4999F5E
ssdeep 3072:GVDpUZ4kNEjElZI9jNh0vbWpTmLzgNDNsh0p6qBAhEIjB0feAQT+:JT8xu
Yara None matched
VirusTotal Search for analysis
Name f75e9d6f86715537_sqlite3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\sqlite3.dll
Size 566.0KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 27b43fd0844dff5b07f117a9074491da
SHA1 41c132b6515c22411a9c6397f37d7e777ba7efc9
SHA256 f75e9d6f867155379740bf4b39654549661fc13c4aa58254b016f20f23c5781d
CRC32 A7AA6244
ssdeep 12288:BfAflXE9LPxGNx6Ps+FN96U0QlRSjylbFhGE8deasluruRyV+89umhtmN46jH+:BfA5E9LJGN0s+FqDQlRSjylbvGWH47Lu
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ac0cec8644340125_api-ms-win-crt-filesystem-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-filesystem-l1-1-0.dll
Size 19.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 228c6bbe1bce84315e4927392a3baee5
SHA1 ba274aa567ad1ec663a2f9284af2e3cb232698fb
SHA256 ac0cec8644340125507dd0bc9a90b1853a2d194eb60a049237fb5e752d349065
CRC32 2B6D42B0
ssdeep 384:Cq6nWm5CZW1hW9YBm0GftpBjVem3SuPvlg+0Pd:T6nWm5CIhViDeKPmd
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 73ab2161a7700835_api-ms-win-crt-string-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-string-l1-1-0.dll
Size 23.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ad99c2362f64cde7756b16f9a016a60f
SHA1 07c9a78ee658bfa81db61dab039cffc9145cc6cb
SHA256 73ab2161a7700835b2a15b7487045a695706cc18bcee283b114042570bb9c0aa
CRC32 6A049066
ssdeep 384:jiFMx0C5yguNvZ5VQgx3SbwA7yMVIkFGlbW1hWS4wm0GftpBjwwO5m3S9lJrm:j6S5yguNvZ5VQgx3SbwA71IkFhbFViWs
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name a7fa48de6c06666b_api-ms-win-core-localization-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-localization-l1-2-0.dll
Size 20.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 23bd405a6cfd1e38c74c5150eec28d0a
SHA1 1d3be98e7dfe565e297e837a7085731ecd368c7b
SHA256 a7fa48de6c06666b80184afee7e544c258e0fb11399ab3fe47d4e74667779f41
CRC32 10E45F8E
ssdeep 384:9OMw3zdp3bwjGjue9/0jCRrndb5W1hW54wm0GftpBjvTNvwm3SBMltZ2m:9OMwBprwjGjue9/0jCRrndboUFViZ2Vu
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name dc62e7f9b027f94d_zip.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\zip.dll
Size 138.0KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 7e78002f1c1c3b39309519074a91d7fe
SHA1 fac0ed3e187b4b4565bb3d2e2720993aa2c6af68
SHA256 dc62e7f9b027f94d61a6d8f5068047c7dfb4fa34e6eee98a1cd681452dc17a31
CRC32 C33C7B7C
ssdeep 3072:IYCXJHU0MZAIt4jKKfgG7h22BP0Q/bynu/vVvJb/+spfPptsm:IYcxUjZAIE9fgsA2BJbcu/vriOtsm
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8b543b1bb241f5b7_api-ms-win-crt-locale-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-locale-l1-1-0.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 034379bcea45eb99db8cdfeacbc5e281
SHA1 bbf93d82e7e306e827efeb9612e8eab2b760e2b7
SHA256 8b543b1bb241f5b773eb76f652dad7b12e3e4a09230f2e804cd6b0622e8baf65
CRC32 8D6498D0
ssdeep 192:lW1hWi6+49Cjdks/nGfe4pBjSY38yMsW5RKTt3E2sVWQ4GWbGBfqnajE49dRX3tK:lW1hWa4wm0GftpBjlWm3S7dlPptZA
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 9dc148ff7cfaf269_mozglue.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\mozglue.dll
Size 513.4KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 001e59835b6b76529be2a26d14c3be22
SHA1 eaafc2fe3e6c84afbb35e37801e36f6f5fdf7bcb
SHA256 9dc148ff7cfaf269025df8bb9ddba5a485b4326ad8726b6007bd5415e46e1d38
CRC32 5BC101B3
ssdeep 12288:pMxNugSadlFTE782doVuSRwIeQCx7WInBDuF8jcLWENVqho4YNWT:pMxNpSadlFo782cwIr9F8ACENVqhoJ4
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a6b83b764555d517_api-ms-win-crt-multibyte-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-multibyte-l1-1-0.dll
Size 25.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 19d7f2d6424c98c45702489a375d9e17
SHA1 310bc4ed49492383e7c669ac9145bda2956c7564
SHA256 a6b83b764555d517216e0e34c4945f7a7501c1b7a25308d8f85551fe353f9c15
CRC32 B2C93CC8
ssdeep 384:2y+Kr6aLPmIHJI6/CpG3t2G3t4odXLNW1hWOXRm0GftpBjVm3SKlDCEIy:2ZKrZPmIHJI6abVi/Q1Iy
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 91d05346b88d6f66_WindowsErrorReport.zip
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Rar$O0XlkDiS6Ei4twfJfGj1hLQFz\WindowsErrorReport.zip
Size 34.2KB
Processes 2232 (cock.mp4)
Type Zip archive data, at least v2.0 to extract
MD5 1ac56baaacfaf18a12125741befa55a3
SHA1 c4ebcf65e152cf9cef31754abb8e259f269748d2
SHA256 91d05346b88d6f668c513f981f2d71d66b2bdbad894c35c0ae811928acc6a8a1
CRC32 6C77E680
ssdeep 768:gOsIztGQ1Y5qcIeN1ktE4jE1V/6UNZdA39:lx7kqW1eZS/3rdA39
Yara None matched
VirusTotal Search for analysis
Name 1ecd899f18b58a79_msvcp140.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\msvcp140.dll
Size 442.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9dda681b0406c3575e666f52cbde4f80
SHA1 1951c5b2c689534cdc2fbfbc14abbf9600a66086
SHA256 1ecd899f18b58a7915069e17582b8bf9f491a907c3fdf22b1ba1cbb2727b69b3
CRC32 B7D17810
ssdeep 12288:B6Z1JFeuKLOU7oiz28hUgiW6QR7t5s03Ooc8dHkC2eskHA1:sZDF3U7oiz2b03Ooc8dHkC2e5HA1
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name ae5e73416eb64bc1_api-ms-win-core-file-l2-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l2-1-0.dll
Size 17.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3f224766fe9b090333fdb43d5a22f9ea
SHA1 548d1bb707ae7a3dfccc0c2d99908561a305f57b
SHA256 ae5e73416eb64bc18249ace99f6847024eceea7ce9c343696c84196460f3a357
CRC32 669DCF47
ssdeep 192:FZkW1hWiecvHCjdks/nGfe4pBjSYo3Vq34W5RKTt3E2sVWQ4GW2rOqnajd2siD+k:MW1hWdQim0GftpBj4VuFm3SWlg+0mw
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 7a114a9c1ca86e53_vcruntime140.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\vcruntime140.dll
Size 80.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 e79ef25890b214b13a7473e52330d0ec
SHA1 e47cbd0000a1f6132d74f5e767ad91973bd772d8
SHA256 7a114a9c1ca86e532d7f38e81c48f24ef2bfe6084f6056b3d4c3566ba43003d6
CRC32 5943CBE6
ssdeep 1536:Szref/qblSclsganbQrl1cfJfkGuJnmxhpxv5YDanecbFKQhBVh:SGf/qbl55anbnfJX+neN5fnecbFKQh7
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 9f7bda59faafc8a4_api-ms-win-core-file-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l1-2-0.dll
Size 17.8KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 79ee4a2fcbe24e9a65106de834ccda4a
SHA1 fd1ba674371af7116ea06ad42886185f98ba137b
SHA256 9f7bda59faafc8a455f98397a63a7f7d114efc4e8a41808c791256ebf33c7613
CRC32 2632B956
ssdeep 192:Y+W1hWifcvHCjdks/nGfe4pBjSYA89sX5W5RKTt3E2sVWQ4GWFuLOgVqnaj6uDp6:Y+W1hWoQim0GftpBj7sIm3SFOslD16hP
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 758a2f9ef6908b51_api-ms-win-core-synch-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-synch-l1-2-0.dll
Size 18.3KB
Processes 2232 (cock.mp4)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 6e704280d632c2f8f2cadefcae25ad85
SHA1 699c5a1c553d64d7ff3cf4fe57da72bb151caede
SHA256 758a2f9ef6908b51745db50d89610fe1de921d93b2dbea919bfdba813d5d8893
CRC32 C89ED697
ssdeep 384:DtZ3UW1hWxDzDm0GftpBjEILkm3ScrlPpU9:n0ViIQxi
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis