Dropped Files | ZeroBOX
Name e3b0c44298fc1c14_nskED4E.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nskED4E.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 8dc562cda7217a3a_System.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nskEDEB.tmp\System.dll
Size 12.0KB
Processes 2216 (sistem.exe_11849.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cff85c549d536f651d4fb8387f1976f2
SHA1 d41ce3a5ff609df9cf5c7e207d3b59bf8a48530e
SHA256 8dc562cda7217a3a52db898243de3e2ed68b80e62ddcb8619545ed0b4e7f65a8
CRC32 7D3D580E
ssdeep 192:Zjvco0qWTlt70m5Aj/lQ0sEWD/wtYbBHFNaDybC7y+XBz0QPi:FHQlt70mij/lQRv/9VMjzr
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
VirusTotal Search for analysis
Name 2564f9720bf77cb8_wplugin.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nskEDEB.tmp\wplugin.dll
Size 252.1KB
Processes 2216 (sistem.exe_11849.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 734a6e95705c0b7e7427fe560c0c425e
SHA1 4bb22e96ff3b4236b62e2c28c664a64cfabb8e78
SHA256 2564f9720bf77cb8a26ef4db7a73ff5df9c32cf3d611d22d212ac80c79de5141
CRC32 E11E9FFB
ssdeep 3072:+mhZoIUHVz90RGJb3K3+2f1D+JxemFDDF7ie:+mhZo9HBL13y1+yoH1ie
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis