Dropped Files | ZeroBOX
Name ec60e96dc49a9fc5_xwaahew.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nstD0C.tmp\xwaahew.dll
Size 38.5KB
Processes 2524 (vbc.exe)
Type PE32 executable (DLL) (native) Intel 80386, for MS Windows
MD5 1792a656868a4d2689ed3d4b577d7426
SHA1 bb62d812490c8d3154b9f34d72d75b9c0239d820
SHA256 ec60e96dc49a9fc57aabe1a6c6fcd58bab85010916de0b299a95af44ef332dd1
CRC32 E8FC0804
ssdeep 384:r2dM1LnbVduWnX4qFTrtR1836QFlqIknaqRCz+704JzYp/mca/aPGZA6KG:rLPVduW/FTJ7arFlRko2zYp/caPGKtG
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 4a2776ccd67ea903_2arlffne3duvo5f7f
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2arlffne3duvo5f7f
Size 204.0KB
Processes 2524 (vbc.exe)
Type data
MD5 4819576afbe9678998d19b9d69f2938f
SHA1 685b63b2f32d1a032bbf39751501d24e068c0bb5
SHA256 4a2776ccd67ea9039e34382f43aaf59c89c8652ad0986e628cb0121fa159b4e5
CRC32 35603230
ssdeep 6144:DsbkoSWvPpAx3jMRTfKV3n8Ay5NfWfRho:qOWvPpGTM1I38Ay2Jho
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsdCFB.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsdCFB.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis