Dropped Files | ZeroBOX
Name b17c4902a3487273_winlogson.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\winlogson.exe
Size 3.3MB
Processes 2416 (Stimulations.exe)
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 88f7552e76576a0fac58eac38afa47fa
SHA1 2024fdd162c0df4e96fde5737737faffabad0ef6
SHA256 b17c4902a348727376c5e6b7877045d9be5c7a31d5f06ae0aed89cb6a4855f97
CRC32 061118DF
ssdeep 49152:n+8fTRAQZazrbpXmtVe5x4N3BR6WbBwy3OBH0TfzcyNVn8OuEnSO1vcpgPz5tdhq:+87GF183XSBgfzcyI7OhLH3HYXCZj
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_33635812
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\__tmp_rar_sfx_access_check_33635812
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis