Dropped Files | ZeroBOX
Name e5aeb88be79f9333_unityengine.inputmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.inputmodule.dll
Size 11.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d9b590f0c8e54eb759e7c90836fd6885
SHA1 41b88161a04bfd8b18769bd72f29138f4826c585
SHA256 e5aeb88be79f93333e863c29641034963c8fd8b7b1f11f08acfa295d8c955028
CRC32 5E98BFA2
ssdeep 192:RJIS+nu1fpdV8oeVT4/UDcjOHZXNcsWT1:8RnujdPeVM/McjOHZXNcx
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ba4a7b37d5291702_unityengine.physics2dmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.physics2dmodule.dll
Size 91.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 00ec26574ca2237d88cc5f849d243461
SHA1 8b63b91faf8e80f37e44e8bdd36a2f54fdbba665
SHA256 ba4a7b37d52917025e899b4e85250bea09e0cf2930b2ed398c929a24b388dcdb
CRC32 AD37D81A
ssdeep 1536:UlsJo72iXOTNA/fh4vwx6McW++x+brX4TGIqyQrtUhHZ9c0:UlscO26wx6+LjGIqxAZ9J
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 50b79c57f46bf4e0_unityengine.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.dll
Size 70.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 56841a99d40e7d74e3c227b91384c78b
SHA1 e3e58bfc810d86b9dc703da4dba90485ffeea82a
SHA256 50b79c57f46bf4e060bb27461b6d4fac6f078e08b57e776c7a811554c4899fd6
CRC32 7E6B3596
ssdeep 1536:T5jZdqeqTEDtH0Ijp0zW/6704SxlnuF4zwa:T5eXm5Ty4z7
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 4efcf4f2108c1446_unityengine.spritemaskmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.spritemaskmodule.dll
Size 9.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 7a4dc35c8f8b48c36bd3b689ab2ac60d
SHA1 9b6f8706e11dc62bb66a77329f1a5e7fb2a6d989
SHA256 4efcf4f2108c14466b66cafb79181160650b1eab85638a6b4ab388b619cdd87e
CRC32 E9FAFCAA
ssdeep 96:J3HmlLja6sJc+cKaLcjOb7Z0cPNcs1pQ0Nu:UVPw9cDcjOHZXNcspu
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 327b1d34eab0ada7_unityengine.imguimodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.imguimodule.dll
Size 143.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 b4807a4660094a5f415cf2ca12eba944
SHA1 c3f0762046056a534bfc8f845502eb038682b12c
SHA256 327b1d34eab0ada754186a03dac40f23de627867124777ec35c6c040b210079a
CRC32 9495E669
ssdeep 3072:Ajl7FBI+t97jN/1BmvBu3Dt659XujO40UgZ9F:ApFBImRjN3eIDt6GjO449
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 51b32055e2a03c78_unityengine.uimodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.uimodule.dll
Size 21.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 9f5df5b3b80b54c095d21cdacd385e40
SHA1 7f29d9813a9f325f0b1120c5fa594c41f94f838b
SHA256 51b32055e2a03c78d3e7b2d7d8a6425ee80d415c1e07ea0ec7b1dd84eddc9f12
CRC32 076C5437
ssdeep 384:OnplxXdwI+ikGwaf/ZVvHoWDNBwtqT115BjtPcjOHZXNcK:Upzv+iD59HJDNwaBRhHZ9cK
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2bbc43f2715710c1_system.xml.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.xml.dll
Size 2.3MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2f3e3eeaa14cb440e44f4ed2cb6e0979
SHA1 8ddb3d85e002e0c9943f8367c4807a5f00ff24fc
SHA256 2bbc43f2715710c16394dbfdcee4361a3b2bbb5e40403519ccbb44049869222b
CRC32 816BBA89
ssdeep 24576:3j/y6RfS6LIqFLHAx7YEDno3CfxkvUVZl/VNnTwlh3WnIMQNtH7U/ZD:meLIqFzAxnDqWVNnTwlh3Wn6NtH7U
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name cf18ddfd660304a2_unityengine.spriteshapemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.spriteshapemodule.dll
Size 9.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e73120abfb6d0dca8942111862bd0dea
SHA1 8db749b1cea75cea32a8acf11b74adc76524c66a
SHA256 cf18ddfd660304a26800019315b57c2f877a5de4e7b42ef02274325d27074f31
CRC32 865E52BF
ssdeep 96:QGWDendYy97Ci0tGXywDRnGreLbKaLcjOb7Z0cPNcs5og00r:NY+F+GXVDRdDcjOHZXNcstr
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a11128e604a59ead_unityengine.assetbundlemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.assetbundlemodule.dll
Size 20.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 1ef2ec0c97f5d06492ba081f12857cae
SHA1 68277a572cb6b407e8182233dbc260105f544c4c
SHA256 a11128e604a59eadd61ea870f2017ea18d4c19240dd1c1b8b6d4ffb7976b569b
CRC32 A6E140B7
ssdeep 384:XO1fbtQJ2hQzoxiNF5I6+ecjOHZXNcBV:eNbt7QzAib3VhHZ9cBV
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f07d8747f7ef098b_unityengine.gridmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.gridmodule.dll
Size 13.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 bb974689c3a66fd8de986fb92c985bda
SHA1 c40fb0dd033e53325a0c2ef17c4fb2ef8bc46e4e
SHA256 f07d8747f7ef098bcec30aaa0cf0a5d901fb86e467fe06e65a344107159a3b17
CRC32 9FD76597
ssdeep 192:flQzJvDIEdJq1dgTh1wGjDcjOHZXNcsot:9QNLD0GTh1wG/cjOHZXNcR
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 6eb7c3af3d6f052c_boot.config
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\boot.config
Size 123.0B
Processes 2856 (VirbelaSetup.tmp)
Type ASCII text
MD5 3302d56ce69ae79b5745181080b88597
SHA1 65c9dcca706a436c7c89341db387c0427ffb6063
SHA256 6eb7c3af3d6f052cc5f22091454b79caf4434c551bda39a811425d116b1afde8
CRC32 BD92B1FE
ssdeep 3:49aaI4ZHWRluQIwoAIoDyzQPAIRLsJERzdYALuBY9VdLGD:kpIRljIwoA4zQ4IS4B5j9VdaD
Yara None matched
VirusTotal Search for analysis
Name 7e8afaf5fae1b65c_system.runtime.serialization.xml.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.runtime.serialization.xml.dll
Size 7.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 00b6b14a030a4f9bfb787f58ab87597a
SHA1 ffb07ec6728e720cea10961a62ac95349919d795
SHA256 7e8afaf5fae1b65ce62543d138b03c5b894a692abdf525da294360cc58b5266b
CRC32 7A7C77FF
ssdeep 192:Uni/oMH01cXAcu5H8mRixrHC0MuENeqB8:Un9MH01X18mWbzMuEHB8
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name f1a6416eeedd9d04_web.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.0\web.config
Size 18.4KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text
MD5 b127480ee9f0b8dab6a3f73ad79dd332
SHA1 7d776d730cbd253564713f36573dd8366782788c
SHA256 f1a6416eeedd9d040387fd85dcf7d6e074b6644c6829d08be220ff9fc32efb31
CRC32 46DCAC4D
ssdeep 384:lJJuAr8F1mJ1ayCk5+HK5YaW41DBWTwahst/tlLvSqwwU4FVXaS7L3nHIXYFXc//:jbpJX91Xbi
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name cee66e5b52ea5560_system.runtime.serialization.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.runtime.serialization.dll
Size 821.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 4f69cfd5b2a13bca7ae0a87c0b506cc5
SHA1 d01402084c12302da59e3e8e999b57860979d444
SHA256 cee66e5b52ea5560ec45a5fa9e7fc3eec01edb6761d51b8fe01aa4380f9089d3
CRC32 8BEAA1FF
ssdeep 12288:1T3CDaMSfk8qMQbkd3OEhuZJtfTdkyymiA7JvKL:1TESfk8ObQ3OlZJtL8A7JvKL
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name d6b6c2325ec0bc02_mono.security.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\mono.security.dll
Size 303.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 99c39a889bbe6d24d93601dfcea54d87
SHA1 e23357caf279df5407d56b14d4f7a2fe90a0f0f1
SHA256 d6b6c2325ec0bc02ebf6bd4f739abf05162aaeb00733d9bc2b7de5a8840949a8
CRC32 436A893C
ssdeep 6144:vuca+sTOwf+31OE5FXNywY1URfxAzXj5qf:HUi9kgxA
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name f8032293df2ce6d5_unityengine.coremodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.coremodule.dll
Size 828.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 02abbe3b7267dd542da5e5bcbb49c66d
SHA1 6f4680f9ac268cce6b34f0d425706d2f4e4a8a35
SHA256 f8032293df2ce6d552b2d5ecdd865b9f81459fa849103505d5acb86fb7d1a2f9
CRC32 5FA843B3
ssdeep 12288:7L5eIQi+5mc5dj5ZTqdPvhAELd+Clzt4sA:35eIQi+dG7Z+Clz+
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b7b170b7ca190ae2_unity.textmeshpro.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unity.textmeshpro.dll
Size 324.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e78ced45bbcdb597a5e6c59a5844c4a5
SHA1 89a721545a63bacdbaf221e40f9ae49c7ea64b37
SHA256 b7b170b7ca190ae20c9406026a9c0b3300c26101cb24e1c23f63e2eef0f7e4ab
CRC32 D586D064
ssdeep 6144:eD4Le8zF+6KU8SK6la4dmEP7sZTTsfpEvZICqj8ImuDwn6EyC37C:eD4L/h+6KU8SKA6RTsfpEvZICq43C
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 078c74c700594fba_unityengine.timeline.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.timeline.dll
Size 96.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 89fa7b17f22d6ed2d18ff6df9a1aaec0
SHA1 421fbf7d2f608ee6f33c19eb4354ef6e9cdaab26
SHA256 078c74c700594fba0c148129eebc431b23dbbb107d640d4a3281e5433793ca6c
CRC32 C4912683
ssdeep 1536:hW9y4p8S3smmJY0he38CbcP6cSyqKIWNHSbklqQRvNpKeQz9Hu2T:GeS8NY2S8CwPIlWsbkAv
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 7891d5f95f025a1a_unityengine.baselibmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.baselibmodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 50733356658056c61aa161fba0657bb7
SHA1 fc39ec663df55bdb443c9faf02ec5d1f27e4ce0b
SHA256 7891d5f95f025a1a0b82adb5b770f9c26cbaea70bc25de7f0afea9c41e37a606
CRC32 F82F51BE
ssdeep 96:fewVf9HXQJDKaLcjObwZ0cPNcsJ+Iw0Y/:GwV5AJDDcjOcZXNcs87/
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ce648c2314949761_unityengine.tlsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.tlsmodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 c9b17af96192d8151c4f94ef609a7a93
SHA1 24dc90733b9174e1aa20fd78f5d1301134db7a76
SHA256 ce648c2314949761db143b15b799057837a8709ddcdeaef24e5e396b6498a988
CRC32 85C69843
ssdeep 96:fSqXVf9HXQEEKaLcjObwZ0cPNcsJswG0cg5:hXV5AEEDcjOcZXNcs2U
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b557db742f350fce_system.xml.xpath.xdocument.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.xml.xpath.xdocument.dll
Size 5.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2b6bb3d73099c9376e9578a6d16706fc
SHA1 49fe7defb50abd327cca633166954e9d06e42e94
SHA256 b557db742f350fce1d4bee24999542a00960857302c5a16eb9796c06df486b03
CRC32 148B7E12
ssdeep 48:6t+laeQH3BfWYxWkxb1wfRrZ24Mvzkz+IvRkmWNlbxO38SZ44l+lmeAC5IhefV+:7efWkjxaRrk4xvXIlOLmceAi0
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name d541ffa3416bbdce_system.drawing.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.drawing.dll
Size 180.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 59ce616258d643c89f8834ce81e246c3
SHA1 39cb92f63b094d47c854221f7bb767611ae73dab
SHA256 d541ffa3416bbdce87a69ac86620f1d5a0f10c8871319a5253d1c03447130172
CRC32 0FD88AA1
ssdeep 3072:FigawrUmay+yV3XOe3QpYbh+q+FR3F7lx:s2VnOppYbh9ixl
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 4fd7dd9e0fbad0cc_unityengine.vehiclesmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.vehiclesmodule.dll
Size 11.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 825c43c8b7f4f20f249781f85eb6fad9
SHA1 8e14f268d6535c9101974687fb1fa0940d420b5d
SHA256 4fd7dd9e0fbad0cced50e52c81bc628021d99368779c2d22453a9ece2eba159d
CRC32 A1185AD8
ssdeep 192:txFUTwOF+I01OBF3voxCkDcjOcZXNcsOs:t3UTqIVvOzcjOcZXNcR
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name da4ccdbdab851b38_system.net.http.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.net.http.dll
Size 112.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 43ffb06c772ab7cca445e3d247fb4d3e
SHA1 fbd71df2c2a6f1b4efe4e45d4f10e7a82c2e1999
SHA256 da4ccdbdab851b383678b0e451027516ae11e60ecbec39c11aa461a40d72441f
CRC32 E7D97EEC
ssdeep 1536:pRfx2tSFNT2MqE17jh1hYg0CPa3sCSBjM4OeP9az/XRPb4nQ/7BY:pZZ3quXKACSBjM4Oskz/XRPb4n01Y
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 190c2304cae690cd_unityengine.tilemapmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.tilemapmodule.dll
Size 23.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 c8ced01d7240dae9fc0f235921103eb9
SHA1 aa0fd22455acd651714fa741b30b027efa40c2e3
SHA256 190c2304cae690cda31b0f2360f45f0e1e136de44a13c1d465ca06678d4aaa38
CRC32 8AE38378
ssdeep 384:V1x4IJ3UBPlSjsjgT/wd2XKtWqQaSZoBmcjOHZXNcE:V74IJ32MjEuPXgWqcZokhHZ9cE
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1b30743ab1830b9b_unityengine.imageconversionmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.imageconversionmodule.dll
Size 9.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 197c2c2bfa51bee02706238e04562f2c
SHA1 53cf074aecd466f3759ab36a1309f9c43ff3b805
SHA256 1b30743ab1830b9b45e79f88c1acefd7517eafcef4fd1a7a3eb853a07ca5bb17
CRC32 A8FB5B95
ssdeep 96:CLZzuhwedVvjXHFYyW1K5pKaLcjOb7Z0cPNcs1JP0go:uiwevrXHdW1KDDcjOHZXNcsLo
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2b7fab71b3b0192b_mscorlib.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\mscorlib.dll
Size 3.7MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 0e19d4d61f37b924bb617bcf7494dad0
SHA1 545acc77a687c39447af955d72af3a1d920e8d2c
SHA256 2b7fab71b3b0192b42bb7cf38446ad7b28d2003b60a7a2c2938b52faad29a31a
CRC32 48CDECDD
ssdeep 49152:CNc/KGOTjbg1XwQ33JuPXI9kV8MMtzxA:+GOXMFJu
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • Win_Trojan_Formbook_Zero - Used Formbook
VirusTotal Search for analysis
Name 428bcf3136d0c816_system.data.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.data.dll
Size 1.9MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 34cc95171394ff19b78c59dc055e8bea
SHA1 c3495afd367af019947f2419cf57acf1800e448e
SHA256 428bcf3136d0c81680e4558d775066e26b0bca181218254f0a5df81917f33a9e
CRC32 037D7BDC
ssdeep 24576:vetFgYwMkru3rrFdx0dkR9VUJLdaD7y7X5bLid1EB8Bo6Dpc:YFLwirZ0CUJL4f1EB8Bjp
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 6919d5af506aae0d_machine.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.0\machine.config
Size 32.9KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text, with very long lines
MD5 24c866ce8037fcdca2287234eddff637
SHA1 9245befcd116458e9619694f1a785c50fa61b58e
SHA256 6919d5af506aae0d93e91bd83418a81895a5554b9f54cf94aad20d025a4db664
CRC32 C2F58754
ssdeep 384:PbtltttttSRtNRtcRtGrRtSRtBDRp5Rt70gRt2RtTf1RDRty6ugyunHMSeuWuGR0:7Kn
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 35d33d026f0fd333_virbela open campus.lnk
Submit file
Filepath C:\Users\Public\Desktop\Virbela Open Campus.lnk
Size 1.1KB
Processes 2856 (VirbelaSetup.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Nov 2 12:52:34 2021, mtime=Tue Nov 2 12:52:34 2021, atime=Tue Dec 1 22:45:28 2020, length=639488, window=hide
MD5 dd3a588b079f4ab3aeb09a202cd1b7d9
SHA1 00df9dfde658b9b6a713d3e904bd6d98c54a9d89
SHA256 35d33d026f0fd333b2fb1625450fab39a9f042574020862dabca13a30e1a017d
CRC32 36030965
ssdeep 12:8mFCPAicGdp8DCDWFudlUcgM6CVX98jAo+XpCQbdpYCelUcbEtbdpYCelUcuBNUm:8mF6HdOEW7JnAJZXdpJRxdpJnUPPyd7f
Yara
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 7a1c7ecb7ed515ed_unityengine.windmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.windmodule.dll
Size 9.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d9b782bcfc30ca5819756e64588a20e1
SHA1 85258da3a4617acb2f7e6c40a73f818979488f8e
SHA256 7a1c7ecb7ed515ed31716c5727a62450b78b4a29c338ef5c60d99005f7c3cc37
CRC32 3779A696
ssdeep 96:ZkjselZ29noQR9OKaLcjOb7Z0cPNcslrt0Lx:+jZ26QR9ODcjOHZXNcsEx
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 40b3d590f95191f3_icsharpcode.sharpziplib.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\icsharpcode.sharpziplib.dll
Size 196.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 c8164876b6f66616d68387443621510c
SHA1 7a9df9c25d49690b6a3c451607d311a866b131f4
SHA256 40b3d590f95191f3e33e5d00e534fa40f823d9b1bb2a9afe05f139c4e0a3af8d
CRC32 D3160A1C
ssdeep 3072:hjMibqfQqFyGCDXiW9Pp/+Tl4abpuu201PB1BBXIDwtqSPVINrAfvp1:GibqI59PpOPf201/z7p
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name c3b1bc7272264c01_unityengine.unityconnectmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unityconnectmodule.dll
Size 10.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 ec6ae1aeb24c70bfd01690b7ce377904
SHA1 c81a30f76631f3d66fecea9454d7554dc25b790d
SHA256 c3b1bc7272264c01fb14af83900d800c0455e529acc0fc679ae731f03c268736
CRC32 DC7078D8
ssdeep 96:GUj3t7ciyJeZ4uB8/RuPDsCZKaLcjOb7Z0cPNcspXQW0TS:GIt7mA4uC/RQ7DcjOHZXNcsoS
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 7e952afb7907825b_unityengine.clusterrenderermodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.clusterrenderermodule.dll
Size 8.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 53ee139ab862b16560496a8edf64814c
SHA1 0f4d904b9b040b2b0b62ad3f30038692438426a4
SHA256 7e952afb7907825b004148d010eb6f12428e81daa4f97174cd89da656c891e10
CRC32 0D64729C
ssdeep 96:zxF31lCnbOsvM9mKaLcjObwZ0cPNcshN0dk0gIdH:9BDm6svQmDcjOcZXNcsCQqH
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 11f1322298424e4c_unityengine.umbramodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.umbramodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f3e0a3065197e5c898f9077c1057090c
SHA1 871c1eaabf7a469c3bc835ad510f947ed48699a1
SHA256 11f1322298424e4cb7f08c952da517b97173919fad82baa1a8d73ccd90a1b69d
CRC32 C8B0B2EF
ssdeep 96:G6sgVf9HXQG0KaLcjObwZ0cPNcsJb/0Ki:lV5AG0DcjOcZXNcsLi
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name add6c8971e3f8162_unins000.exe
Submit file
Filepath c:\program files (x86)\virbela open campus\unins000.exe
Size 2.5MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 56459493b7fb34745e672de18f93229c
SHA1 ab65d93d19bcb740bbc818ad355e76a7de0e2fa1
SHA256 add6c8971e3f816276162046df73a2b398d150b371261127f75eb86b36f4f10a
CRC32 DC549480
ssdeep 49152:KdrGT9oY0SAQ4+YI1Qb1oWGxblxZa0o8579Sh:KFGTv1QtGxHZabc6
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 7132af8370f848b0_unity.analytics.dataprivacy.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unity.analytics.dataprivacy.dll
Size 7.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 7b19f543060e840287ae3c668004ff4c
SHA1 56a72d1bb50379c22cc37df166bdfd39f9f71607
SHA256 7132af8370f848b0f9ee25760a883437f7758ec088ea5243387b7973e210f306
CRC32 E8A74427
ssdeep 96:y3ULjrQ0EnCVbjQi7hR6EmbwbgG7dVC/nKRR/7N4daR6zgDYs94LGSUt:84jrB9x0ihBmbTG7dkiRr4c0e94LG3
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name fbe6b934dfa1815e_assembly-csharp-firstpass.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\assembly-csharp-firstpass.dll
Size 4.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 a4a741abbe7a1158a8c0cb0acbe97e98
SHA1 f7468f2a441ec2687815bfa0ad4f3eaa5e009516
SHA256 fbe6b934dfa1815e892aaa50ae5a7436a854d40034cb1123c296fc9e0f43c128
CRC32 4BE81512
ssdeep 48:6fyrQol4lUcpWpe6e33OMyB5fJEiYZEuvneP2YWvB1ul3nuq:b+qTQ6e33zy7GEuvePoyFn
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name f1264de9569151aa_unityengine.unetmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unetmodule.dll
Size 75.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d01daad3aad64f3cad9c2a9a55655f42
SHA1 561140ee3d3003cfa650fa965f020d18904449fb
SHA256 f1264de9569151aa0dfb0ca107225a4027724b28e8b8c63b3b8c12e650f027a3
CRC32 B1854411
ssdeep 1536:w1sVgTbveRuiqeRZ1hbvRljinDPxdxalxfl6acmaxgbKWt+zqhHZ9cy:w1s+iRuOvRsnDPxdxalxfl6acmaxgbKE
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name fa4fa215c523156b_system.globalization.extensions.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.globalization.extensions.dll
Size 6.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 9277ad8c78b47083274c941bb9d425e9
SHA1 641d51c1c30e75e5fb77f1af67578124cdf5d950
SHA256 fa4fa215c523156bcec0208613d5b9f220a25ee6be34a86d13c09e1ed339208c
CRC32 69C9010C
ssdeep 96:L4ggaqpBVwEwAgzixv1EWeOARPtcRQKRWen0R/0c:2l3gWxKWBARPCRpRWen0R/P
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name c85ae9f64547e36a_unityengine.networking.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.networking.dll
Size 254.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 74f585bc43440c4739c7953b0397affd
SHA1 7be648dfebd8489f0224a60e066c9f33e9c49a07
SHA256 c85ae9f64547e36aba2ea0ea1782122edcc085616a07dcb3d5750bc5428c0f2d
CRC32 C2117F04
ssdeep 6144:l5sOYtOhdNxJetVHUrYQ8BHrLlsTurk4Ng/dVF5:PcOhdN/ej8dV
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 3209397fcb9631a6_unityengine.xrmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.xrmodule.dll
Size 43.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 94869bfeada38009bade2d7d9acb495d
SHA1 bf50e7ec4ce40067b28e8675a7102eaba3c2d93b
SHA256 3209397fcb9631a68bc80c5ef9dbee2bd3c658d536762bf4c3bf7ff9680eaed7
CRC32 1C414376
ssdeep 768:HnzE3e4hw0NNi84s1F1ugwmLL9kdzWFrhhHZ9cJ:Hou4hwZ84s17Uuk5grhhHZ9cJ
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8b4d80f555a1ab26_mono-2.0-bdwgc.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\embedruntime\mono-2.0-bdwgc.dll
Size 3.7MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1fc4ec823bd8f3d5ebee967985f68d2f
SHA1 20023cddecd411f6ad84671969983764967ea451
SHA256 8b4d80f555a1ab263c046cbbda0ed17ea9088ac2c614a4815356b873bf0d57c4
CRC32 62769C6C
ssdeep 98304:EKyul17viA8tnBTF9XoCb5WfcOSuE1JE41blpYVAjKQjmt/KuYMJEozXn8ez7AhC:717viA8tnBTFmQjmXVAi3ob5
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name ce1db1ad8a951207_settings.map
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.5\settings.map
Size 2.6KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text
MD5 ba17ade8a8e3ee221377534c8136f617
SHA1 8e17e2aec423a8e6fb43e8cbe6215040217bb8a3
SHA256 ce1db1ad8a9512073164e3eccdc193f7eda036e1a9733caec4635de21b2865c8
CRC32 DC24A240
ssdeep 48:cgHvHThUuGk1oN9uNtcNrPTVB/XiWy+HXr/AHMHThUuGk1oN9uNtcNrPTVB/JJio:pPlYwoTucBT7Jy+cslYwoTucBTNJLJyA
Yara None matched
VirusTotal Search for analysis
Name 982cbe19ba52aa04_unityengine.textcoremodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.textcoremodule.dll
Size 31.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 13f9f449b5bf8f44fcaa0c38db835769
SHA1 aef2858e9e55a0a27c0e1aaf82a991a2c5aa3626
SHA256 982cbe19ba52aa04d2aeecf40c60b8d585ac4be830e6f8940a9b2d7a5ffbc3b5
CRC32 8DF692F7
ssdeep 768:B7h5dZXND/xk05HaLkq6AlQ70A0AbaBTqyA+hHZ9c1C:B7hDD/a0ILM70AfaBNA+hHZ9cE
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name fb42210ac3bc7510_unityengine.audiomodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.audiomodule.dll
Size 57.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 23b934de2aa59ddb9ea13d7cff4263db
SHA1 1a74c80f735e72cd797f9e5ae09be027fbbc1dba
SHA256 fb42210ac3bc75107fed62ec1e9ef4aeee500318af14aae1a47eadb4c5fd7dd9
CRC32 7DB952CA
ssdeep 768:SSNtNVxeET26GkDnI+m397dFda2q1Eqe8/fpCjm2Ir+3/YhHZ9cW:yQnI+mba2q3eOpCX/YhHZ9cW
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 521a466ca42826a3_unityengine.jsonserializemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.jsonserializemodule.dll
Size 10.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e5ebfca57b335176f033554502ae0996
SHA1 98916d4f26b023d49168f999d6989300bd53fea8
SHA256 521a466ca42826a3f149c8f1a8b04603005ed90fd5f59b8e42f2c48136e125f4
CRC32 E16C855F
ssdeep 96:Zrr70wkKH4aikf2lIowL+mx1H0872TpKaLcjOb7Z0cPNcsR2Q20S7:ZrlH4aiAIIXLV972NDcjOHZXNcsS7
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 7b3f9eecaa164357_unityengine.gamecentermodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.gamecentermodule.dll
Size 25.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 3c714a166d829f3fdfe485b3d8bcd488
SHA1 ce83629b5ee21bc281ffdfc52b4c9957ab715bf5
SHA256 7b3f9eecaa164357951fdf726872dbee9c77ae77e7fcc4e92fd2304a5ae3f644
CRC32 AA9F0473
ssdeep 768:2yJoBvWaTfZO5J5qW+tz95KBEswEih96hHZ9c+O:2yJevTMqXz95K7wEiKhHZ9c+O
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 28cac9b6c9da5f16_unityengine.substancemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.substancemodule.dll
Size 12.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 43d7e0235281b2bc86da8bdbc34d6cf6
SHA1 13e87152ccac4e95fc9aac53535a5e58ebd98424
SHA256 28cac9b6c9da5f16481fcd655b77cc1f07b38fe695e05db657e9d25aa7f82c33
CRC32 73C6D45C
ssdeep 192:exPF+IrU6bY744F5DwKfD8pkAa7pbi5hDcjOHZXNcsXFf:++m9+7EKfD8pHaOxcjOHZXNcY
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1ad161c58cc20793_unityengine.unitywebrequestassetbundlemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitywebrequestassetbundlemodule.dll
Size 11.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 fa74caf6f576722fa2d679365e1f6ffd
SHA1 9cea9a05254d01f22011094b1aad2881948a5428
SHA256 1ad161c58cc20793a10a5efb5d1a3f1a45a3caeb897a3a2f6c9116564b10bbc1
CRC32 9A7B3DD8
ssdeep 96:yfw7DeMVhE+A+K04wBMqAcKaLcjObwZ0cPNcsBT7Y902S3:hBVhE+A+K0J9DcjOcZXNcsBz3
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 3fa424d23bc10553_resources.assets.ress
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\resources.assets.ress
Size 341.4KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 93f61e74ec89e327b33ab5152d4cc163
SHA1 e324c0c794f5561b858b14317b5eaaca91bd2b73
SHA256 3fa424d23bc10553cda628b0b5ef3dfec4276e59695579521bfc72aa757361ad
CRC32 60BE46A3
ssdeep 6144:w00000P00000900000X00000SDhTMNOaz000R0004000p000w000b000o888n88u:w00000P00000900000X00000Xz000R0Y
Yara None matched
VirusTotal Search for analysis
Name bf5533d45a17dde5_unityengine.localizationmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.localizationmodule.dll
Size 9.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 01167054325888428ac721236283e4db
SHA1 9e3ad901c1db1a780625cd6601dab636faadc353
SHA256 bf5533d45a17dde5a0a7a9da5bb771cdc3431ed6c652e8e5bb593a4ad5dc2f3c
CRC32 AA98BABF
ssdeep 96:O+ZGPswjve9PI10ThxrbuZKaLcjOb7Z0cPNcspBQXo0TQT:jQjvf0TWZDcjOHZXNcsAfQT
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 9ecd1adfbe9ae564_unityengine.physicsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.physicsmodule.dll
Size 83.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e4dea68be81b2e271c52a49c4c4ccdf8
SHA1 e191df4ca5dc7ea349a0a7fdea635c205cda4b54
SHA256 9ecd1adfbe9ae5649443b1eb5cd887203d03d23df11d22bb72aa9372baf56568
CRC32 311772A1
ssdeep 1536:QJvJgRBEGTDtTTjdzQfmErm00ROpydzYlRDVvls+w+hHZ9ch:QJEBEGF9OJDhls+ZZ9s
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 6a632401943d753d_unityengine.vrmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.vrmodule.dll
Size 28.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 7f1076de40f7d6c5bc749cbe5040985e
SHA1 4400e0812dd157189b8a84b6cde1bd49e59a07d7
SHA256 6a632401943d753dfd62573893ec938c5c89f2afb5c08a5dd61cdeda62f0d9b9
CRC32 AE66111B
ssdeep 768:cdO0Y5OHIXua2TRRadiSMQu4z9hQH0w8vcb2QVmZ/tVyt7hHZ9cz:cdo5n92FRa4SMQu47QHZ4cb2QVmZ/tVT
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 814ede6a1cc2c267_unityengine.screencapturemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.screencapturemodule.dll
Size 9.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 913f88bec47a04d6a301045da128be90
SHA1 3fd26664d23264562e358944b21de5a5717de182
SHA256 814ede6a1cc2c267e477af7510c4731f91478f3b08fad6a20b829dc817896760
CRC32 C80BFB88
ssdeep 96:KdFOcoZ9OsTy+rdfKaLcjOb7Z0cPNcsdGQc0SN:KLXoFTy+DcjOHZXNcskN
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name d93a812e8ad838fb_system.numerics.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.numerics.dll
Size 111.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 7ac82decdf0ccee417ee9c335ba36bd9
SHA1 261998eca40c2626e40683a97dbcf96565323edd
SHA256 d93a812e8ad838fbac39e1d41c170c93ccb5c5434b225201c9b466d5aaa4c05c
CRC32 A77E11B5
ssdeep 1536:1tbXi3q2X2T+jc5o9SQMhhuiVEptn+igiqW0NzN9CXI0pVzDtPrXpNPRGHLd9cW:23qKc5oEhzVKtfg7W0NXlG3tPrnQ/
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name edc5bcf685d930a6_machine.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\2.0\machine.config
Size 28.4KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text, with very long lines
MD5 cad24142abba464dd90777c3d347ef88
SHA1 d8db7111fce5a08d8b7c9a6e1e0ad2fbf34cfe12
SHA256 edc5bcf685d930a607bc097927260a3f9ac7f52dd809db68158298bfd934b7ce
CRC32 95068D9C
ssdeep 384:PbBtBtWR5RwRqrR2RN3RPfRaRvRyRaRIKbX/y4RpQXWBE43g:DuY
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name b11e9d3e72b6b429_globalgamemanagers.assets
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\globalgamemanagers.assets
Size 41.7KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 f36af285470d4bd9a7855d1bc9112ab5
SHA1 78f48ca4717cce93baa1c0f05c2dc4fa25e6e915
SHA256 b11e9d3e72b6b429e46ebc6893c3dc3cc83dd53fe756cfad7acb3b652fb0f423
CRC32 61901673
ssdeep 768:evVBVzg4gnPEyVycwcScPStSAZYeOjMjR:UVBVzg4gnGcScPStSAZYeOjMjR
Yara None matched
VirusTotal Search for analysis
Name 833a5689650f6c97_resources.assets
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\resources.assets
Size 146.2KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 2b0837257a08a1190a1f5e617ce5bd7c
SHA1 7bf561bdd867cd0257d33c5b63df5e8bdeba44f3
SHA256 833a5689650f6c9795ab0ce4dd477d7d68deb85fff0dbfaf46f221ac60b32f08
CRC32 097162D2
ssdeep 3072:iFTbi8Y+PDi8c7i8JtKgiEv1ei8mAJ3JkvSyci8YkPni8vVN83kqiZ:4e8328B8jKgiEvB8tJ3Jkvz8Fi8/80qw
Yara None matched
VirusTotal Search for analysis
Name 7e83fa9c2eb93879_system.transactions.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.transactions.dll
Size 32.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 eb8f64bd378d2a93059178714be955e7
SHA1 f193c9ea8dd1f4303d68bcc84d1a569363df8796
SHA256 7e83fa9c2eb938798c108f75feaa5a18fad4aad2c069cc10796c3eff03260da4
CRC32 5B0EA376
ssdeep 384:Zy9feF73NdxAgFDQLXzDjsG6QTWyAaL5NcX7fk57TuTepkZbIRbli3ESmMadMiio:I9feF7DMjsrQJLkXAFE8kxhZ
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 49c6160f9d54af42_settings.map
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\2.0\settings.map
Size 2.6KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text
MD5 22c818a23169e12bd3c8587b6394c731
SHA1 dd2be2dbccd34736719301aee92429d4258ea5a0
SHA256 49c6160f9d54af4270a3b4e997fc4a8301f79b9e2070118fa46ddbcbbc44f9a2
CRC32 AD5340F9
ssdeep 48:cUhThUuGk1oN9uNtcNrPTVB/XiWyuXr/0gThUuGk1oN9uNtcNrPTVB/JJikJyuXL:3YwoTucBT7JyIYwoTucBTNJLJyu
Yara None matched
VirusTotal Search for analysis
Name 6768f1986ad09618_unityengine.directormodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.directormodule.dll
Size 12.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f49b6729c84f776596423b175f35674c
SHA1 58ef4749e8b1a6ad4a6ab110ab88783b9af7b9bd
SHA256 6768f1986ad096186fe28bcad0854a096ae8065d06051f832301a6fbe97ad26d
CRC32 9D54D62F
ssdeep 192:D/GlTt9MF0dsY0ZNkEN7KMqMl/DcjOHZXNcs+l:gvdsOENKq7cjOHZXNcn
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 3c1a76a5849074b4_web.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\2.0\web.config
Size 11.4KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text
MD5 2b6303c4f12762b71051db6e947f90a4
SHA1 a4d7e05516f63d6ab67327b299d4fb2852cb840b
SHA256 3c1a76a5849074b437d297656a208a3bef6d84b982153542b9c797046c601dfc
CRC32 534A9960
ssdeep 192:wcedeaZ0sEMYaWN5bs6yyzEVkEYEG/Z1f5v6CuCCrtQzPwkP/waeKjy:wj5YaWPs6/1zwya
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 613f168095c7bc84_system.servicemodel.internals.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.servicemodel.internals.dll
Size 213.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 cd4197b09d30e623e7edda8e0ceee9bd
SHA1 b57389199898fe7f407b08a58a6a28b12906ebe8
SHA256 613f168095c7bc8413d78cc23ce5d6ee0df0649ea422bc90d639085db1ed8ec8
CRC32 E380D789
ssdeep 6144:1osVNgZFwcHCjvBd/LnGQk+wfODoWJkP:1osVWZFwcHCjvOlu
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 0388172540b2c6ea_unins000.dat
Submit file
Filepath C:\Program Files (x86)\Virbela Open Campus\unins000.dat
Size 30.9KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 691b6c8e1c66b568067ca43853aa2244
SHA1 5392f91a012c4e7a50e2f333e2cb216d66e0bde1
SHA256 0388172540b2c6ea0fce20d72f5eadc125f08f4e5f014dff1530748e2258a54e
CRC32 2BEF98B8
ssdeep 384:zCtBzXR2mjq5CkCFIWyUQdQYlrkUVGs6ZZe6e88/2TVHEbZT0ItiZk2Rwv9FKPwc:zczB2m2imlIsANF
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 762b100d367a170c_unityplayer.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\unityplayer.dll
Size 17.3MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 4255b2c7f28f12b3ee871e8ec0596855
SHA1 e892da20901db625f8bd3036210105809c1ceba6
SHA256 762b100d367a170ccc73578385a8bac155f42c6ce42fb6f18931ff0c65a12d00
CRC32 B883276A
ssdeep 196608:a7Pt6u8KmnUatIzu3OitP/hhB9/5vy//92bcUinDaNNhazOHQ2sJ:C6BnnhmzueitX5k/0bcKv1
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 34616260cffc2dfb_unityengine.hotreloadmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.hotreloadmodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 8981129cc71744dc206cd222a284122d
SHA1 5385056c3888252a21ec7738782a00994004ff9f
SHA256 34616260cffc2dfbd52928cada4da2b91217240ce5082fb7ae19d564ab337f6a
CRC32 AB98D300
ssdeep 96:3EsVf9HXQFoKaLcjObwZ0cPNcsJRVW0On:UsV5AFoDcjOcZXNcs2n
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 87f8c934456004bd_diskutilswinapi.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\plugins\diskutilswinapi.dll
Size 11.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 7b511310b2932bd1f11300048cfecbf2
SHA1 bdb30d64a1de9f92431cca490f044cecb9fdfb58
SHA256 87f8c934456004bd95609d6e44e4afb4e0e56a7957d6d14ea7d79cabd0375c1c
CRC32 98F6FEFA
ssdeep 192:9A4RXRqpy4ZED++gH74t+oajHVzR3zz3YPO3rz:9A4RBgFv+gbP/jHVVgPO3
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 15150be5e88a2675_unity default resources
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\resources\unity default resources
Size 3.5MB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 3881a048d6ca48f04fb01b5afce9cc7b
SHA1 f82ab6be14fd7d05a3414d8e9ebcb2ff9e4b9d2a
SHA256 15150be5e88a2675beec66f1217a31ecf4593628799e86689db8d4a9c43bc7e5
CRC32 466BFBC2
ssdeep 6144:jmJlKyBL6ihOt9OYWjJ9WqdJUZHgk63uyS0q6sJn:CTh26jdQuPSkIn
Yara None matched
VirusTotal Search for analysis
Name 1bf504e4df023439_unityengine.timelinemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.timelinemodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 bf1a784a942b2abcaf4f167cfdab604d
SHA1 02b48b83a3a78f1bdde0668e5a2bacda86f3ef33
SHA256 1bf504e4df023439a8ca6424d702abb9e2899835b8c9235a9eec5a1e4fd7bd47
CRC32 A19369DF
ssdeep 96:3i+Vf9HXQTVKaLcjObwZ0cPNcsJRVc0f0:S+V5ATVDcjOcZXNcsx0
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 93ad1e3a0f9d93b3_virbela.exe
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela.exe
Size 624.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6589194d11aaefb9c653f1c962dc518d
SHA1 d6d98fb39db991773a2567144406e95725d7031b
SHA256 93ad1e3a0f9d93b32169ab66d9e819f77fe6ed5ff5df7c911fdf20e3a8cfdded
CRC32 79BBB5B6
ssdeep 3072:R7Zjpo0RNfe5I883KiXrUQRvWp6edhU7vB+8EicPvElglx0OkMEmg/vPZrubJ:R7ZjpHs87mdwuiOvElgl+5t/vPZru1
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 4fafb1b24ff37a89_unityengine.vfxmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.vfxmodule.dll
Size 26.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d595912acf9707b00c83d6537f437397
SHA1 6cadeca20397dfa6c4c316dd3404c92467796fc3
SHA256 4fafb1b24ff37a89c8e051e68d6564e39e687f70d7656904f77c4598f81c6665
CRC32 FD9FDE85
ssdeep 384:MuoBjXNrf0bCfqMN16he5FspiQWQcjOHZXNcK:Wjdrf0bq1XahHZ9cK
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 751861040b69ea63_defaultwsdlhelpgenerator.aspx
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\2.0\defaultwsdlhelpgenerator.aspx
Size 59.2KB
Processes 2856 (VirbelaSetup.tmp)
Type HTML document, ASCII text
MD5 f7be9f1841ff92f9d4040aed832e0c79
SHA1 b3e4b508aab3cf201c06892713b43ddb0c43b7ae
SHA256 751861040b69ea63a3827507b7c8da9c7f549dc181c1c8af4b7ca78cc97d710a
CRC32 95F9D0B4
ssdeep 768:6CEPutHjvpMgMwP9h5Ij7khsp/6JtEZwMXVtkUI3t3CXyEyk3VbNbqDvJ4oT1y:/r6CdsCOZwMX3k5dWyklh+Dvbw
Yara None matched
VirusTotal Search for analysis
Name 048c25e25cfc403a_system.enterpriseservices.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.enterpriseservices.dll
Size 32.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f4571493296b67516851ba535bbdb24b
SHA1 4b480972db5fac03ecd841a4846733cd511330d5
SHA256 048c25e25cfc403af4ea3b9d9058af11d324629da32270ace7f5b2ee18f567e4
CRC32 2D75445B
ssdeep 768:uFDPgwXPjXVB1SeXbtjfLWifV1jmadK/wDS1ubnakQK:uRPgwXPjXVB1vXbIifbm8KoS1urakQ
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 15a2c7a9242bf54d_web.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.5\web.config
Size 18.4KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text
MD5 08101241b15b53ef0ab908f6d388881f
SHA1 ea3e2ad6d71d483c54b12852dcbdcd0baa569988
SHA256 15a2c7a9242bf54d3ccb3e07fa6d8f84ba8b303d8877243787a1103009941bdb
CRC32 C3DF527D
ssdeep 384:lJJuAr8F1mJ1ayCk5+HK5YaW41DBWTwa6st/tlLvSqwwU4FVXaS7L3nHIXYFXc//:jbpJi91Xbi
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name c5415752f4b5c977_unityengine.unityanalyticsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unityanalyticsmodule.dll
Size 23.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 3c743091a5d44f1386a4a1e1668651d5
SHA1 8f4db6b82c63356390f587892656751c9d909386
SHA256 c5415752f4b5c97720889adc92d6ca58dd109b0dff1501d04f25020cd6ce28ea
CRC32 4D8D5096
ssdeep 384:K/hGc0kb9sVFK9jMxzkm01o2RTI5Xdaf4w8Vbapd7pomcjOHZXNcL:K/ekb+TAmGo2R8W4VapdtXhHZ9cL
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8e99860b0fe1dbc7_assembly-csharp.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\assembly-csharp.dll
Size 822.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 a6607fec6cef54a1640094e7c6d75386
SHA1 f2bb82dd3222787a446ca7270f234e79bae06d5b
SHA256 8e99860b0fe1dbc7fe1dafe761a944c2d6cc8c8ffc875aeaddff3d6592f75528
CRC32 C4A94776
ssdeep 12288:uX++4YV9z9dxKZ/BdTDaxkaihIzTKwHMq:uXPz9d8/BdTDaxkiv1
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name c43b351e7aef5d8b_system.core.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.core.dll
Size 1.0MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 50a0364d2fce85c8867c660a014e950d
SHA1 8b735ee130185a9815eaf0c38eedb925785b4431
SHA256 c43b351e7aef5d8beaee8cd1f8411b8e3065bcca2eeba3d87c85a28a6b61fc7c
CRC32 E81FFE9F
ssdeep 12288:3HJ2eJWqejMiMRDm3l2fo+5HcXILaRbm57iNC/UB1658S0d5kcowul:3HFGoqCUXA0decowul
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name be989012ece28e92_app.info
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\app.info
Size 32.0B
Processes 2856 (VirbelaSetup.tmp)
Type ASCII text
MD5 c1fb6534a3e54a1fb8135178ecf71f36
SHA1 613ab80af0a795b9276ddd33a55694a6f7f426b0
SHA256 be989012ece28e921cda418e672516c8a07686210262850fd24ecd507f85e6b2
CRC32 B205628E
ssdeep 3:0AxvSxmh6W:7Sgh9
Yara None matched
VirusTotal Search for analysis
Name ac6f4ec2fe5ff755_globalgamemanagers
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\globalgamemanagers
Size 38.0KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 f3c514c6f6d49ee9008084115d4fe07f
SHA1 ae038a1ba4765070075e028fdf059e04f6158e63
SHA256 ac6f4ec2fe5ff755eec4dcd5a3b3d56ef448f493ed04d920516163ce2e5e283e
CRC32 1CEFA075
ssdeep 384:f0ZCZ4kVo1DT3xrGH9EaX9QFEIVLhEYh4Itoz95AMc9BzNr9qpcawH:EMdpEEIVWItobY9BKOH
Yara None matched
VirusTotal Search for analysis
Name b017ddeb583b8a56_unityengine.animationmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.animationmodule.dll
Size 134.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d3c6b066530004f4d105a93204339771
SHA1 760c5d5c26c82736e1de6ccf2e1a00f3c73efda6
SHA256 b017ddeb583b8a5636ff52427a1a32fe7acd03cf2274d011addf977240309da6
CRC32 318A2B1E
ssdeep 3072:uAqmiRjB1R3dufY4LnL432S9pEdFpeMZ9T:4RjB1B3snL432S9pEdd9
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name e1d8c6f6a14c57ea_unityengine.streamingmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.streamingmodule.dll
Size 8.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 17d66adbe3503303a9a24d6f7e13231a
SHA1 67c7ad829f77255c9900212f5d0b585a549318d0
SHA256 e1d8c6f6a14c57ea06c1a33e685ec1c04c9a1f446adc8e2663aee77f6bf20a28
CRC32 9ADD40F1
ssdeep 96:xZ1Tv2MOMFG8qtVYZKaLcjObwZ0cPNcsdyVU0OZ:n1TO0FDu4DcjOcZXNcsXZ
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ffa94520d8eff8b6_unityengine.aimodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.aimodule.dll
Size 41.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 76ba23f8d76d72400d7f9ef9ac3b9f56
SHA1 e31b3d93868f12e7b86e1a2615b7ea3b77dc9d15
SHA256 ffa94520d8eff8b6c021900c9b31a316a4faf757bf95d50afe598fffcf996a27
CRC32 6C919013
ssdeep 768:aOOi8KBuEqxRDV99U79VxxivcqqPMKMWMJNKkquaZhs6eKPtGu0kuhHZ9cb:HoWDPGiH4gtGu0vhHZ9cb
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2e31128abc0913ed_unityengine.terrainmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.terrainmodule.dll
Size 61.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 60bffd345ff8624545e6ebd4c0639401
SHA1 62f1bedc6ab7ea1307339888ec0547b315645f62
SHA256 2e31128abc0913ed47349de6fba7a633b7c8f831de38a1f5bc5e8607f2ab83ad
CRC32 FD3DF214
ssdeep 1536:qZdQVNMq/gpJEltI7ZE64vgPC6bnHTCmuWhpOWyuJfrtpiP02lohHZ9c7:2dQjMRpJn+64vg8muWhpOWFZ9o
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 5c72525f420b08ea_system.io.compression.filesystem.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.io.compression.filesystem.dll
Size 22.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e7ed238da93a2fad2d8d33e65edcfbf4
SHA1 68e117a1e794813c163351f94dacb0aecaac1767
SHA256 5c72525f420b08eac29c948b690e945165fa493503a524693c16c5c3ec9bf75c
CRC32 3831BA43
ssdeep 384:2930DrKcLQhPZcNgndNzytVTl0RRbli3ESmMadMMtDBEb/gYFf0B7a:m0D1Lhs6oe6
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 759accaa5fb7bddb_newtonsoft.json.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\newtonsoft.json.dll
Size 667.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d46892cc58663531b78625cf74acb439
SHA1 d4245bd8ea576c4250950b337d5d1047c12c703a
SHA256 759accaa5fb7bddb54a2ceab92a3d8ab50750333ec73b62605aea6165d1ca6dd
CRC32 7BC4AF9F
ssdeep 12288:+m76XVrdlC5KK/BGoG1wQvOFTQ2VS8N9XBBjsgV:+m7w/AAoG81gMXBBjsgV
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name ef9b9387168fd1dd_machine.config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.5\machine.config
Size 33.3KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text, with very long lines
MD5 0869544722561f5aff0eefc83fc7b001
SHA1 1e118f4b5c1c6a7b1858e3fccb1b1d1095561976
SHA256 ef9b9387168fd1dd6c996f96c134d9c44f8eb06f9587004bf997252a520182d6
CRC32 E7E2F2D3
ssdeep 384:PbtltttttSRtNRtcRtGrRtSRtTf5Rt70zDgRt2Rtuj4f1RDRty6ugyunHMSeuWuh:dkn
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 2245bc5b346025e4_system.configuration.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.configuration.dll
Size 42.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 c1a2ac27db1f58c57866a8fa189bbdf0
SHA1 c6dd022617074c73c4f79df7a2da36f021bfd106
SHA256 2245bc5b346025e468d26a73bfbe232e6ddc4b7a499b4fcca02a8ccd934dbc4b
CRC32 B45681B0
ssdeep 384:bC2yuMNMMZJN56g8mKo/hjp0r4ourMVSzciDqnjdiaFg9/Ses93HE7LDaXTSv/fY:HyP1Sm3ScrMdWgdVl93kZAarx2ZJA5
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 849ed2a6a6e6eb0a_unity_builtin_extra
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\resources\unity_builtin_extra
Size 346.8KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 714165c01d52f3a56ec77360364d943a
SHA1 64406cbf38d7399b0ea5a3feba655a0e957947ce
SHA256 849ed2a6a6e6eb0a6139dbae534edd17dd75cdd7e210ad573111e117635601c3
CRC32 2CED62CC
ssdeep 1536:0u2yz2Qxqip4qMvBu++l4sLfWkXMIFqSiYfq7gh/jCcuiQCG5piwni33iHb3k1Yw:0ch4tBb+SeWkcIrQb+17Tj
Yara None matched
VirusTotal Search for analysis
Name a88316462afcde13_unityengine.uielementsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.uielementsmodule.dll
Size 343.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 fd82e582a74b366c3b126de3e54aa00b
SHA1 882877762663315b3b0c765c4269d1dcb29f4fed
SHA256 a88316462afcde131fba2824c2755f318e1dc3e5c6aba63b9d649d837764e871
CRC32 B4F002F4
ssdeep 3072:F7JXjmN67C9pBUvRPdWHJSwdRJ138hchyEruNndXOqV65pof4rl/AajXwzyF1TbX:VtwGAruEwzyP/2XFalrFj7KhjT2kp9
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f105c561a5a05258_unityengine.particlesystemmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.particlesystemmodule.dll
Size 124.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 9782f320ff25a7a7bb33f9a530b8dbc7
SHA1 6986178c264fb3ca6b23429fcf60518f50d2708f
SHA256 f105c561a5a052584d596fc364246bb79ebdca35113092446a835d851dfb003d
CRC32 FEF145C6
ssdeep 1536:tjhEg6ESTECh6P/jxW2zBpOKtH/+XFrjk0EKmf8M88I7EDXfREgY4hHZ9c7:t1SgCh6P/FRp5W+f8ME4jfu4Z9G
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f6090bfaff55e72c_VirbelaSetup.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-77K35.tmp\VirbelaSetup.tmp
Size 2.5MB
Processes 2768 (VirbelaSetup.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4627391855e676753e63517bae15afda
SHA1 024585667effb8121f8c322b98117606ba3f1507
SHA256 f6090bfaff55e72c74ffd25bae949422a465a12fd65d72a40f0cbb4e9f5ad989
CRC32 807DCA25
ssdeep 49152:CdrGT9oY0SAQ4+YI1Qb1oWGxblxZa0o8579SK:CFGTv1QtGxHZabc7
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name f23ecc36be723349_config
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\config
Size 3.2KB
Processes 2856 (VirbelaSetup.tmp)
Type ASCII text
MD5 f668921198511d792d68c113b6ab0ab1
SHA1 fed4bb12f1995486f96683a867bd5b69f9f64757
SHA256 f23ecc36be723349a2226cbe50b92cd3587dbba52e046b96c700c0e0d5c22d58
CRC32 3438FCF7
ssdeep 96:AG21vuk5eMjuAlymlYcXzb/bVPMmUoRPV+PATsCS:oym+cNMiRto7
Yara None matched
VirusTotal Search for analysis
Name 0c56e34c69124510_config.xml
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\mconfig\config.xml
Size 25.2KB
Processes 2856 (VirbelaSetup.tmp)
Type XML 1.0 document, ASCII text, with very long lines
MD5 f34b330f20dce1bdcce9058fca287099
SHA1 936520d5bb5c00a1985d7a4c4f0ef763a9031862
SHA256 0c56e34c69124510fa8c19e7b4c2ca6c1c4ff460ae19f798dd0ca035809e396d
CRC32 80B2033A
ssdeep 192:Bt074zTxASaKp3T7pJsPpPT8B13eeaVonGdEBMmhVbeyeTfWDBzmAwdavahmhNIa:LAMDp35JyPCCu96yJwgag
Yara None matched
VirusTotal Search for analysis
Name 9ece6f5f1d122180_unityengine.textrenderingmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.textrenderingmodule.dll
Size 26.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 99f285e69b430c5c30fb7d3bd2b5b50c
SHA1 9c39ffcc9b48e29a31e4f45df41a323095387198
SHA256 9ece6f5f1d1221809aeee9c591d67a38d51cde32dc6f525719f2ae2b20bf7fac
CRC32 E107496A
ssdeep 384:rgh9vlhW9GyrqVfSVJSiswybROY2kdIPa80zJOyOQOcjOHZXNcC:W99s9ZrqVjxYPaROhHZ9cC
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name dc6369cfa16effd3_unityengine.stylesheetsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.stylesheetsmodule.dll
Size 16.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 b144e95df2819dab475558b27d76a136
SHA1 1af6f8c1e15fce1554d9d149063927a3052ee111
SHA256 dc6369cfa16effd3091796206c4a108e1c8d81c41f948597705aa437a072ceb4
CRC32 DA4AC547
ssdeep 192:o4x2EfUAECf5w52a7bbE93NG3YYYYYJHHgNmULT9y0SsrviI1xvM2yOni76lSuDb:PlKTAdKNNdSsrvMVP764uDbcjOHZXNS
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 994be039eb23da7b_netstandard.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\netstandard.dll
Size 83.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 92e14598f1f886b75f0a02bf934350b3
SHA1 7c8022fff30a45ba04940ebb7ef924a9146056e3
SHA256 994be039eb23da7b0c14fc2fa2c09b3ca2a73bb330e840275ab8275063716f0e
CRC32 EE15AEDD
ssdeep 1536:1DzF+czO/mQxvvn5W4zyH04rU5SSn5ioLlcv9rK:1CFo4zy1y2RK
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • Win_Trojan_Formbook_Zero - Used Formbook
VirusTotal Search for analysis
Name 8baa67f786aa8a0b_unityengine.armodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.armodule.dll
Size 12.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f776e4ab383d8d1c74ff6b3bb401e809
SHA1 c020cdf5773f5426314fd374cfa601ce87b8c80c
SHA256 8baa67f786aa8a0b9b4137a009f487870b41116276486cb664109c0a1b9b8c5a
CRC32 77767DA0
ssdeep 192:SlDLtyjv0cSe/iKs6yHxjPRXFa7CrDcjOHZXNcsLs:dvLSdH62xjPVFakcjOHZXNcq
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 4d5a3b200691420c_unityengine.clusterinputmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.clusterinputmodule.dll
Size 9.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 8ae57058ce1fd8f424ef4c7fa5355811
SHA1 fd52e725235c4749b266b7e5e357091301f162e9
SHA256 4d5a3b200691420cabc07a89b33e7e53b3395d31cd7423068dc4479e8a626394
CRC32 B034E2B4
ssdeep 192:jMBPLPKqFjUqEpGn5mcDcjOHZXNcsTeqC:jYzKqFjOG5mUcjOHZXNcueq
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2f2ce681a9a3487e_unityengine.unitywebrequestwwwmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitywebrequestwwwmodule.dll
Size 19.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2e52fbb2767c059e53c0cbac73717f19
SHA1 13327b866aa526205ee81d344e7ad15d7604a0ef
SHA256 2f2ce681a9a3487e1456c7c022922466916fd019b2045eba67ecba3f036e70fc
CRC32 E89898D2
ssdeep 384:Du/CxdH9VMeD6H3p8OGgKPXzQbIKf8GFlQ/oc1CcjOHZXNcs+:Du/CDme2XpIg2iIKxy/oc1ChHZ9cs+
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 51f6231b4a6da56c_unityengine.unitywebrequestmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitywebrequestmodule.dll
Size 41.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2b4e6f4cc7f56db7ad458109714c65c3
SHA1 21ab44ce887d568f5e67caa460bdbd1ccffd9bd0
SHA256 51f6231b4a6da56c1d2fa328a420ae0b0dae7136051d40cb3e4ca68dce284e7b
CRC32 8924979E
ssdeep 768:2ag3sygQ3p8+mM8REMCaKTgiJ8PANPZz/QhHZEce:PUx3fmM82Xp3yPmZEhHZEce
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a2c4aa36b7f95212_unityengine.ui.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.ui.dll
Size 248.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 fcae74bf21ce4fda286f38f35c4e1640
SHA1 84a1001fb590516d6b605dd6223db6baf4ca1eae
SHA256 a2c4aa36b7f952129541e40987c1960d6a62d95ca57669608a4fdfc20351b9ef
CRC32 48277422
ssdeep 6144:jnZw2R78O0ZfXo2RYfHjzl5QMn54nal/wihfNwr1V:2cIO05o20Dx
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 277c8c0c339050d0_system.componentmodel.composition.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.componentmodel.composition.dll
Size 242.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f153c4606ee5eaa766aa05fc1385c883
SHA1 81b4997a5214a7155300dd0e1adafbb583c6f95d
SHA256 277c8c0c339050d03dccc69d5c0aa3833d178f5f115e5e5d0bcf54c7ae136740
CRC32 5FBB716B
ssdeep 3072:zdpvT15KXwrqrkRixoK47Sr73v/1fLExXEGgDX/EOoRlKPW10QgFLqRRRRRqqS67:zrvTmUTTOoRlKPk5gF3HoJ0XtCea40w
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 0cebfb97a4d9f6a0_unityengine.terrainphysicsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.terrainphysicsmodule.dll
Size 8.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 06022f6a39617a6b4d154d530e171cde
SHA1 7db88e46cb5648bc579003f72f323a1917ee0771
SHA256 0cebfb97a4d9f6a07b069fc9151955c2f1ac966ef005e2d42c62e417827f98e6
CRC32 E6DF26B2
ssdeep 96:2/a4DmF+ePmBzVkDxEZsKaLcjObwZ0cPNcsldrr05p:syFF+BzODRDcjOcZXNcsip
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name c89c9233badba523_unityengine.spatialtracking.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.spatialtracking.dll
Size 11.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 a7ab291a0f40bbf407d9c13ac63ed467
SHA1 9182d0c12c0e86020e2086263097e5d9feb40c71
SHA256 c89c9233badba523ba4505dbbd47d036eb5dbd6e2a6458fa17012da09cc51e22
CRC32 7124F5AF
ssdeep 192:e7ssrl8xQ1Lbm51mNnXRnpnbF4UExeX/dsbyb98kbjEXCxmgDLn/vPHV:e/cmNnhnpnbPwKsf4/vP
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 3976202cec800bda_system.diagnostics.stacktrace.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.diagnostics.stacktrace.dll
Size 6.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 7527c5f87c15ba2d9f8fd30920aeacbf
SHA1 463d8763d79a3934046821dac63c94c0eacaf1fa
SHA256 3976202cec800bda6a3e7c2154d7859a9a1f09712d0046af9b28095210b41f2f
CRC32 83847C7F
ssdeep 96:G5SzrdBy6UFfVGJfFPlcqxvtVvPNOCua5fpbe1xa0:G5QfnUF9GBFPl9xFV8CFTe18
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 79d67071b630132a_sharedassets0.assets
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\sharedassets0.assets
Size 426.2KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 a0c83a556f5bba8568f332343385e463
SHA1 b73f5e1f78c026aee3cc61f5b25371034692515a
SHA256 79d67071b630132a181ea5242db3f70e061753fe7b5400ef1e1b60d9c4cf8f05
CRC32 403B2B07
ssdeep 12288:m8TKXbHu9f8KQ3N04kZTMgBAR5+N1X1MRb0RwhiHix+b8:mCnZTMgjm0Rz8
Yara None matched
VirusTotal Search for analysis
Name 610eb76764824391_unityengine.accessibilitymodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.accessibilitymodule.dll
Size 11.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f2debb7718db4f9aa01674afced198e0
SHA1 5c563ca3ad3a29c04108863be2d8670ed86b6ec3
SHA256 610eb767648243917cbcadef08fad657c1d7147d58248b0cae27d391d2b6510f
CRC32 F867470C
ssdeep 192:U9PpHfA0IfdnoHo0V0ZSITNGDcjOHZXNcs8L:YPy0ISHo0VCSWNycjOHZXNcx
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8396df974339ba7e_unityengine.videomodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.videomodule.dll
Size 26.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 d24fa718c4646c1e8f85da33c45e1f69
SHA1 eb5c7f8add31ec631bf4f233747a0d1c60586ade
SHA256 8396df974339ba7e8724daca87a64a0f35b0ef98daca762db28ed665e1d8ee59
CRC32 D0EFE345
ssdeep 384:YL9cM22MYqCmXrx0j+EtF3qEQ5GZLkz4VOavfiWZThJAZQ6mAJD4Fx+cjOHZXNcM:YfhtF3qEQ5GVkUVDDhQzD/hHZ9cM
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 390e7edea7c242f7_unityengine.clothmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.clothmodule.dll
Size 14.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 b134fd0a880ff817a34fc762f905b764
SHA1 e6166a09f09f0f88b085329eb292b5255523854f
SHA256 390e7edea7c242f764c4645c8582cf02bfdb3d2d86f51d4ea8d8b91ac5e57e91
CRC32 4808F5B5
ssdeep 384:iAddJGAXkz3ssQ24EDedJFR3K8xSycjOHZXNcP:9OA0PD6KShHZ9cP
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8e7f13ac37742941_system.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.dll
Size 2.0MB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 25c76583d3003c9c854bcd229d2960bd
SHA1 884e2870c483a54556866d070b53897259d2a05c
SHA256 8e7f13ac37742941d434022f8ccbc75dc442273544609184e00a22b117529a90
CRC32 E6D187E3
ssdeep 24576:K8n3706n4bMqo/yDgEV5B5gdw8yGNpnm7hNDL0576FIx3BrcnXAcdh:KQn4bho/yFgdwG14FIx3BrcnQc
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 4ddd50f31fb968f3_browscap.ini
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\browscap.ini
Size 304.7KB
Processes 2856 (VirbelaSetup.tmp)
Type ISO-8859 text
MD5 378be809df7d15aac75a175693e25fbb
SHA1 2d5454e161de8a5b65910f27bd70d9d0ad8fa476
SHA256 4ddd50f31fb968f30bedefc253a46dc3f2890192d05cdaa9e0a64a056eee807e
CRC32 CE6C0AB3
ssdeep 1536:D+dN5JLXlU4XteKJeYPMxBUm9huPj3bkeoO3cTKr0AzhjRzi0v5XfDlVlvr778BN:DYPEBOPjLkeOTA0AzhJMutEbbt0oK7M
Yara None matched
VirusTotal Search for analysis
Name 231c54d54d1b3bf0_unityengine.sharedinternalsmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.sharedinternalsmodule.dll
Size 19.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 ee638a6bd15834f9c04d64bf5885aea9
SHA1 74b25e7056fe252f492b7f65fe1af48617feec5e
SHA256 231c54d54d1b3bf002c2f2ce092174669f84f586ebf88fcc0362a381d1ba6aa5
CRC32 2640F036
ssdeep 384:JcEAf36Wgy3XOxfYUOAhVD/QtDcjOHZXNc+:JcEAf3/gyHofYUlLD/QtDhHZ9c+
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 0d7f8065b37e02f7_system.xml.linq.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.xml.linq.dll
Size 116.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 5da06902d1e04b4bbe9e755e1db4a1a1
SHA1 861c16cf678bfa108291d58a5739a4187c77a9ef
SHA256 0d7f8065b37e02f793ef2a2e6bec933c33e185e1dfe3c3712eebeedc3df2c0a4
CRC32 8601062F
ssdeep 3072:ONU5ioEWuB91Z0S44VPRN5qaYf81tVZhz2:QB+iPRGih
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 818a14bff04595a8_unityengine.unitywebrequestaudiomodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitywebrequestaudiomodule.dll
Size 10.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 383544d976bbfde9eaffc29ea506feaa
SHA1 37573bd88467d51941b472561464b467566c1979
SHA256 818a14bff04595a8623d1a5746c786d2fa2103db0601369348b35fa595c4c01f
CRC32 047E997A
ssdeep 192:21eMQWWaHcsZaql6Th2lWDcjOHZXNcsm9:EQW9HcsZaqETh2lCcjOHZXNcn
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 6820d9924cc3b305_unityengine.crashreportingmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.crashreportingmodule.dll
Size 9.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 75e5c3aef54e0c70978c01853fc335ac
SHA1 22d07826bbf7c84566517916c11b22cbd0916bea
SHA256 6820d9924cc3b305ef9a8721146b6f1cba393520748689ab0ee839b3d9345f80
CRC32 7DA52AF4
ssdeep 96:/ATdPjhFFs31D9BIGKaLcjOb7Z0cPNcsxArz005I/:adPjhfsZ9DcjOHZXNcswe
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8a1082057ac5681d_compat.browser
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\etc\mono\4.5\browsers\compat.browser
Size 1.6KB
Processes 2856 (VirbelaSetup.tmp)
Type exported SGML document, ASCII text, with CRLF, LF line terminators
MD5 0d831c1264b5b32a39fa347de368fe48
SHA1 187dff516f9448e63ea5078190b3347922c4b3eb
SHA256 8a1082057ac5681dcd4e9c227ed7fb8eb42ac1618963b5de3b65739dd77e2741
CRC32 2E178A0B
ssdeep 24:27wkBllNBT0kzgWN92ComG60GQVj+5pO2mdN0khkANcsZnDNoZNOlTn:2w6ln0ALGCG6P5PFs
Yara None matched
VirusTotal Search for analysis
Name 70c4c421e7c061e8_system.io.compression.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\system.io.compression.dll
Size 96.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 c45f6bd18b4376496f2aa73f232d3d94
SHA1 999208d66ed3eaa70205d8f261ea33af271bc6cc
SHA256 70c4c421e7c061e8ec2b5e3520bda954362807fc36ed3d061a71f7623f029fd1
CRC32 EE5D3147
ssdeep 1536:tVYlTkwzl46ORXHNopHEJo5JK1/E9ITZOBLOTX8YHujjHs67b:tVYZH5460XNopgo5JK1s9NCTXlHuXTP
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name cbf8e83a86910600_virbela open campus.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virbela Open Campus.lnk
Size 1.1KB
Processes 2856 (VirbelaSetup.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Nov 2 12:52:34 2021, mtime=Tue Nov 2 12:52:34 2021, atime=Tue Dec 1 22:45:28 2020, length=639488, window=hide
MD5 57a74cbf3cd4d02875b31b2379543cd8
SHA1 00938f688034506dbede27a2adbf91f47c53b2a2
SHA256 cbf8e83a86910600b8d4a7a9865a1630938983fde7f83f5ae975036f007b8aae
CRC32 C36B8891
ssdeep 12:8mFCPAicGdp8DCDWFudlUcgM6CVX98jAo+XpCObdpYCelUcbEtbdpYCelUcuBNUm:8mF6HdOEW7JnAJZpdpJRxdpJnUPPyd7f
Yara
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 19e187e1e369cf19_output_log.txt
Submit file
Filepath C:\Users\test22\AppData\LocalLow\Virbela, LLC\Virbela Open Campus\output_log.txt
Size 663.0B
Processes 3024 (virbela.exe)
Type ASCII text, with CRLF, CR line terminators
MD5 7b359e027e2146843e5802d931594df0
SHA1 4398875aadbaf8688f53e5881c105c56ae4fd8e6
SHA256 19e187e1e369cf19aea3e8f27491d8ddd195cf54e2c5b07546fb2ef41eee6c34
CRC32 875AC226
ssdeep 12:U+B4QO5WjV6sBI/F+Y/BYWWbKy/SxpkkyTxRTBo5kav6LnaeewogKc8t32AgsFbK:U+BQtgI/F+YxjCSxJyNRTi5kG6FogB2m
Yara None matched
VirusTotal Search for analysis
Name a18d0e7552b0da14_sharedassets0.assets.ress
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\sharedassets0.assets.ress
Size 2.3MB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 292efb4899bd6ce35dc0fd01944091c7
SHA1 c8b3356bc25bf96a8df6f09b67286aa02d61bcd1
SHA256 a18d0e7552b0da1476618fea3cfc3dac2570b1d36b088f6fd1dc305784b86bd2
CRC32 0942F9FC
ssdeep 12288:9DLbZvywF8yy5u/A9G6AoXc2yIa5bEx454+sbUlNeT0AcHPNN4/BdpABLamj:RhP8X5u/A9Gxo2Ia2+54+eTe1l3
Yara None matched
VirusTotal Search for analysis
Name 21e67f739db31057_unityengine.profilermodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.profilermodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e1a334fcafd1facd736a9e5f3643b51a
SHA1 d679a10df066e912db21a895d38cb01e51e6c394
SHA256 21e67f739db310572c0ee698cdf2c51f675057c7896bdfc590b2b6329f51b1fd
CRC32 61DC9379
ssdeep 96:3i+Vf9HXQw2f6KaLcjObwZ0cPNcsJRVS0fq:S+V5ABSDcjOcZXNcs7q
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 388a796580234efc__setup64.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-U75R0.tmp\_isetup\_setup64.tmp
Size 6.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
CRC32 2CDCC338
ssdeep 96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8fd22751e16f489c_unityengine.filesystemhttpmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.filesystemhttpmodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 3c11aebc52fc073ab2068e191fb8afab
SHA1 df45d95b8fb505dfdec9f8563f3fc747b8f20088
SHA256 8fd22751e16f489c0f210ef1ab2fa9d261b8190c0ef713074981bd05c245bbff
CRC32 D751D9E6
ssdeep 96:iGcVf9HXQFxjuKaLcjObwZ0cPNcsJXrCn0530:OV5AFxKDcjOcZXNcs4230
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b8946a33d2378315_unityengine.performancereportingmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.performancereportingmodule.dll
Size 8.5KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f49757b72874c604ab0f391fb72e6f9e
SHA1 cc4d403b442ff16ca2827dbeb102aa00c3d2b7d4
SHA256 b8946a33d23783156538d206ee3b003fe1485285b5e580e662581613b3385784
CRC32 9FEF6E17
ssdeep 96:rKYb8KP5xUUYklA/4KaLcjOb7Z0cPNcsxwH07r:T55SUYklAADcjOHZXNcs5r
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 3036d49e8d764f13_monoposixhelper.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\monobleedingedge\embedruntime\monoposixhelper.dll
Size 598.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 8b1c78e7ae72fc69d63b3ab1df678f15
SHA1 a323d3c38d8e1b42ceb6e5f45eecf759aa6ada8b
SHA256 3036d49e8d764f1335d6c9501ed97438a3be21394c2286b36e595eacaac4b10a
CRC32 599C5CED
ssdeep 12288:/UUtPcgVN+wdBbuMEiyvA5t3ggKTJmP7:RtEu75tBKTK7
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name d28d659ad5f1a643_unityengine.unitywebrequesttexturemodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitywebrequesttexturemodule.dll
Size 10.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 fc2013e72b6513852e77029acf988119
SHA1 a8bfc18009703fd993ca41dea26ab97f6b360d27
SHA256 d28d659ad5f1a643f22436712dc62a41fd3bd9dd2c129e6e3e134e1a81ae5971
CRC32 41A93A97
ssdeep 192:CJjhGeBEsbmg11kP0VDcjOHZXNcs3QHC:Ogg11kP0lcjOHZXNc+QH
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1e7a9f310c16acdf_level0
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\level0
Size 26.7KB
Processes 2856 (VirbelaSetup.tmp)
Type data
MD5 f4ad27570066864b81bc33f155bc5b14
SHA1 a4c26a494074f09c47ba1e65bf8b29554b50208d
SHA256 1e7a9f310c16acdf60a87a4bb398a8bd51a171cd6d81d207b1623303bcaec583
CRC32 2B34F734
ssdeep 192:Vd3YCG4NHEJpM8zbn0LMQasyXilQXSuMYrzKpMg31Xjh2CEekF/:VvNkJ5n0LMXttmeOTh/
Yara None matched
VirusTotal Search for analysis
Name 16b5813caa40dd1c_unityengine.unitytestprotocolmodule.dll
Submit file
Filepath c:\program files (x86)\virbela open campus\virbela_data\managed\unityengine.unitytestprotocolmodule.dll
Size 8.0KB
Processes 2856 (VirbelaSetup.tmp)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 1ce8d7bb8d746b1a356a5a393453d012
SHA1 e9185cf08bf4be1b3ee77203245d8a5f91e26a92
SHA256 16b5813caa40dd1c4cf814af933b3d9a5e9f720bcdc30941e05f783db693fa86
CRC32 3B0534AE
ssdeep 96:aRVf9HXQaqKaLcjObwZ0cPNcsJBE2N0G4:0V5AaqDcjOcZXNcsjES4
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis