Dropped Files | ZeroBOX
Name 116afa6b8f4213f6_sihost64.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Libs\sihost64.exe
Size 7.5KB
Processes 2872 (services64.exe)
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 5a9eee34a0fdce1056388e807726a03c
SHA1 c6b401b54e262651c2b70f7c9093c7ac3e57456b
SHA256 116afa6b8f4213f676cc6aab6b5aec7b6547ae53cd38df09974ea1462ce41954
CRC32 33E7B5D2
ssdeep 96:5zPLdRFVIn/9jddvBbjDN792+jj0PuK1QSA4ruGoNbcTIoDzgkPWwOgzNt:Rd6jjVnF92+jj0PuKBA4yGPBg0Wu
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 81eccb7c63167508_f2_prot.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\f2_prot.exe
Size 1.4MB
Processes 2412 (svchost.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 a21c6db90ee62cc05755c7aba5bfb33b
SHA1 0a39285f50527fd028eb81016f20a0a597afa24b
SHA256 81eccb7c63167508f91b8e2ea24d9437a9579411edd0f6f666bda1051a4cd9ee
CRC32 D41CA9F8
ssdeep 24576:wNACyXb/4rU+y8qjPQym9wQj4CUr8K0wxKRcrO6IWshct+9:kAC24r8pPbmyQjgr8K0wxYD3WsGt
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 201582c2837f6d4f_sihost32.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Telemetry\sihost32.exe
Size 8.0KB
Processes 2480 (services32.exe)
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 ef1d47ed149037d47b6fea6dad01950b
SHA1 df39278003c6a9bb3c8e8c420f39faf2aa953f07
SHA256 201582c2837f6d4f8100fb3bf7fca50914cbe90a1a9c674641f1b353e18f7359
CRC32 3C7F6646
ssdeep 96:9MnMBVe9VUUcNARbjXO792+jSHXTDtxQuETIoDZ2HPWwOgzNt:cUUVj492+jSHjDXP+r2vWu
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name 334576e834d0516e_f1_prot.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\f1_prot.exe
Size 1.4MB
Processes 2412 (svchost.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 b9bedc94ab68cf2423606bab657fe343
SHA1 f9d3fe51e13db292ba1954cfb9238973de62beea
SHA256 334576e834d0516e3ee15f1ebe5fe454c6617066f1becb047df8ad6cc47bd479
CRC32 8AC71F4C
ssdeep 24576:VwD0IElinmuPn+YENrWZyx5jvlktXsj5+3/HtR7pmV7aw2o6kBo8WqI+hF18aknf:O0KnmuP+LrWyv2q9e/H7pmVWw2qC9qIS
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 11bd2c9f9e2397c9_wr64.sys
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Libs\WR64.sys
Size 14.2KB
Processes 2872 (services64.exe)
Type PE32+ executable (native) x86-64, for MS Windows
MD5 0c0195c48b6b8582fa6f6373032118da
SHA1 d25340ae8e92a6d29f599fef426a2bc1b5217299
SHA256 11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5
CRC32 6B0323EB
ssdeep 192:nqjKhp+GQvzj3i+5T9oGYJh1wAoxhSF6OOoe068jSJUbueq1H2PIP0:qjKL+v/y+5TWGYOf2OJ06dUb+pQ
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_12036156
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_12036156
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 7c8fa5b5781aeb82_sihost64.log
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Libs\sihost64.log
Size 2.1MB
Processes 2872 (services64.exe)
Type data
MD5 ddfddc934646c6e605173ca0fa243bdd
SHA1 b67b45ca2b9f11c10559c7e8ff1a35a4cb360dea
SHA256 7c8fa5b5781aeb828e0494c947af7bf9a691495f111cfbf68e9f2e28c4304b09
CRC32 BFDC900F
ssdeep 49152:NtePYNns+nNXPFbsZD+btK212nlS7kfymzrDv0m6r7Mfphsz:NK/oNXCZAH7AygrKXY4
Yara None matched
VirusTotal Search for analysis