Dropped Files | ZeroBOX
Name 42c13fd37c6019f4_updater.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\updater.exe
Size 360.9KB
Processes 2340 (win32.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0a0110226b5ad7366daaadeea0627ee0
SHA1 d2d6977720fa869672a7432cc1b60d3547de759c
SHA256 42c13fd37c6019f420a50395c24f3f17741d45568fc248efdfce6012cc88a031
CRC32 691148F8
ssdeep 6144:SUV5d8deEgLm/j26yleaEj+PnLzYK6CeFsPD9euBN3EiC7Jg3PfcKrKywVFx:EmLAj26E/Ej+PnLzYK6Ce09egEHJAdGD
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name b8a80ef2e00f4e37_barslen.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\BARSLEN.dat
Size 134.8KB
Processes 2340 (win32.exe)
Type data
MD5 3503b6f6915504ce0693f36ed0d88c71
SHA1 7c5ae485084a10362b2be60391e2d3b2f849dff9
SHA256 b8a80ef2e00f4e371e094dccb9abb7c967026e5c048328b53d5fb9b1e365fe9e
CRC32 F6CB1C7D
ssdeep 1536:1ywfKf2LdQaQ40cUeA8t2AzIDzv6lSvDYz2ahAmpGl3iRgK:lKf2LdttoAI+YEzBhAmgox
Yara None matched
VirusTotal Search for analysis
Name ada29c3fcec212ed_wsenable.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\WSEnable.exe
Size 23.9KB
Processes 2340 (win32.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 35abb09caabc9cca9b235687fa5bd7e4
SHA1 e9d60bd52e1d7177bc5ffe603bfad63942d9ef41
SHA256 ada29c3fcec212ed2e552896764f1fb3b58d17feb9f795fd6d0479181f3b08e7
CRC32 FEE02E7C
ssdeep 384:8mRyryJoQfZBvhR3wJvNrK7Zb/rlgy2W9jYZrvDG/GhAOxNyl:8hryaQxBvhVwVNrK7Zbrlpx2DGeh9w
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 8dc562cda7217a3a_system.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsh8D5D.tmp\System.dll
Size 12.0KB
Processes 2340 (win32.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cff85c549d536f651d4fb8387f1976f2
SHA1 d41ce3a5ff609df9cf5c7e207d3b59bf8a48530e
SHA256 8dc562cda7217a3a52db898243de3e2ed68b80e62ddcb8619545ed0b4e7f65a8
CRC32 7D3D580E
ssdeep 192:Zjvco0qWTlt70m5Aj/lQ0sEWD/wtYbBHFNaDybC7y+XBz0QPi:FHQlt70mij/lQRv/9VMjzr
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name dc1d54dab6ec8c00_psget.format.ps1xml
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\PSGet.Format.ps1xml
Size 1.2KB
Processes 2340 (win32.exe)
Type HTML document, ASCII text, with CRLF line terminators
MD5 5343c1a8b203c162a3bf3870d9f50fd4
SHA1 04b5b886c20d88b57eea6d8ff882624a4ac1e51d
SHA256 dc1d54dab6ec8c00f70137927504e4f222c8395f10760b6beecfcfa94e08249f
CRC32 F66645C9
ssdeep 24:hM0mIAvy4Wvsqs1Ra7JZRGNeHX+AYcvP2wk1RjdEF3qpMk5:lmIAq1UqsziJZ+eHX+AdP2TvpMk5
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsw8B96.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsw8B96.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis