Dropped Files | ZeroBOX
Name 0fc1724f4a6bb0b1_tallerkenrkkers.ini
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tallerkenrkkers.ini
Size 42.0B
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type ASCII text, with CRLF line terminators
MD5 85597fe5d84d5a7baf802fa2fec5a46b
SHA1 4e675014898a79859033450bddf70f1782474cfd
SHA256 0fc1724f4a6bb0b13ea976c7ce4dac0bf3eec44d9f3a3787ed230996cb2c265a
CRC32 A0D7B3B9
ssdeep 3:fbsRLByMdnJKt+iov:jt+iov
Yara None matched
VirusTotal Search for analysis
Name 353589e4cee1ce06_englante.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Englante.bin
Size 202.2KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type data
MD5 1c4e550660f9099e50b4401928330d0c
SHA1 cfecf93f4b5bbb208534d6806efbe83181c8af33
SHA256 353589e4cee1ce068b61e08d06bf0ea0b419004057614a1ea6153b7387a3cf51
CRC32 8AAF0763
ssdeep 3072:ymHwjwsJ2ZpPzphU0gN+9oe7Z8+bH2t6mhFWrfj8nL2bs:mjjkZzpKd+Se+I2tTHUfj8nibs
Yara None matched
VirusTotal Search for analysis
Name 83e849c8b6766db6_system.runtime.serialization.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\System.Runtime.Serialization.dll
Size 17.1KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 99156404006678cb1e23415cbce56e16
SHA1 11f2b0447f9fbd29d5b8125df0ebbb09624e2444
SHA256 83e849c8b6766db6ca76748e364a36e83afd6f5842aa2c3b18ce8f73fb11e7ee
CRC32 144736E6
ssdeep 384:wpEvDj8NN2j7dLWg04BHWqlU/uPHRN7QoYWF//dJR9ztzH:wpEvDj8NAZP04BzlwMQoYWF//dj9zpH
Yara
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 7f68de78fe29278d_face-surprise-symbolic.svg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\face-surprise-symbolic.svg
Size 425.0B
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type SVG Scalable Vector Graphics image
MD5 2cb330e4c068dd9ac07118f2ed992cdb
SHA1 21b8eb3e3f511ee486c7fa75950a9d5629dd7f5e
SHA256 7f68de78fe29278d69d9a71b2db5908fa7ed5ffcfd456ed3ae3358d18f98a40c
CRC32 D697E2EB
ssdeep 6:tI9mc4slzcWER4FZPpXETnPMMQePkQdvkTnILjJRSi5fh/KnLJtL0tgDLpSkBWRW:t4CDqLmkQddLjfdhynL31XgkBW6T9A0/
Yara None matched
VirusTotal Search for analysis
Name 57d1ab127a01a29c_license.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\License.txt
Size 3.9KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type ASCII text, with CRLF line terminators
MD5 de83a54fa6d43ac15aa945616a05ad31
SHA1 dfbff06eacb61841125a145771a3cd662474e711
SHA256 57d1ab127a01a29c2ef7a956a3d0df3cb74ca3391a679d337aa92d42c80ec5d6
CRC32 3F093797
ssdeep 96:dLlTu+xS0jaXU9zBOrYJ2rYJk9n3O3zOrTmxz0NxrVwA:/TuoS0gUTOrs2rsQn3O3SvmxQN7wA
Yara None matched
VirusTotal Search for analysis
Name d11386c4556c8dad_weather-few-clouds-symbolic.symbolic.png
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\weather-few-clouds-symbolic.symbolic.png
Size 293.0B
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 fa97182db54dbe05ddcd873575d28f5e
SHA1 98aebbcac2404501b99cc01af33cf21b43977b3d
SHA256 d11386c4556c8dad0c7c368a8fbca65baf340b282253f470e1b4a86b82833e69
CRC32 CA108872
ssdeep 6:6v/lhPysjhB5HYNB+HwaY9MmrI3kV/OlsH3IiQ4sZ8AQpTcRh3Ssr3HRb9IVRK8c:6v/7DV4yB5UlOy5Hw8FpTcRhi4hWVRs
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 9a1de06c12d0a9a9_ipc.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\ipc.dll
Size 33.6KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 f2ac95e2d557b8a76f399eae34044d19
SHA1 1835ac6a06600ae759bf8db48b7de8ec6cd3191c
SHA256 9a1de06c12d0a9a948832d042871d5109005c0e6db16736dd56f96afffdb2ce3
CRC32 C23A31CF
ssdeep 384:eeoBN23/0InniyehBzBSddM9iwQGFBqm5g9Hg00lCCX4xsOlsybCWx15sa0eMD1:93//iKdM9m2Bb5g9jVsOlsyb7tq
Yara
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
VirusTotal Search for analysis
Name 8dc562cda7217a3a_system.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nstEF15.tmp\System.dll
Size 12.0KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cff85c549d536f651d4fb8387f1976f2
SHA1 d41ce3a5ff609df9cf5c7e207d3b59bf8a48530e
SHA256 8dc562cda7217a3a52db898243de3e2ed68b80e62ddcb8619545ed0b4e7f65a8
CRC32 7D3D580E
ssdeep 192:Zjvco0qWTlt70m5Aj/lQ0sEWD/wtYbBHFNaDybC7y+XBz0QPi:FHQlt70mij/lQRv/9VMjzr
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 55514d9bb54b741a_x-office-presentation-template.png
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\x-office-presentation-template.png
Size 462.0B
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PNG image data, 16 x 16, 8-bit colormap, non-interlaced
MD5 4bff465b1cd1c7f0490b08e292859852
SHA1 6673c0c7cbba1ec3b58507e1c4b2b22d357fd8c4
SHA256 55514d9bb54b741a9de3740bc2532bfd8b309cb9bd181e51c287223c44ae57f7
CRC32 FB3151FE
ssdeep 12:6v/7X0ZAVGkarWgo/xsDxEEd1IkPpayR5VAgqlzjwF+vN:C0WVGkMWgopUxT11p7R5KgqZfvN
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nscECE0.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nscECE0.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 0053c52def74d610_network-wireless-signal-none-symbolic.symbolic.png
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\network-wireless-signal-none-symbolic.symbolic.png
Size 300.0B
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 36d33d6cbe73d097a720264d05a52293
SHA1 a50adcbd4d31ad48c0cccc262ae75b5c5f086d21
SHA256 0053c52def74d610b2d543b68826a34eb7191b18ecda9013d91bcb72a87b22f9
CRC32 EE2A2A91
ssdeep 6:6v/lhPysHA0eLWDyLuRPCJmUn40jWHXxRH2XQTmtpcXkOLF7up:6v/7n7Ae5RKJmC4x3qXoUSXk27c
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8c09a2ceb8cf10cc_green_leaves_23.bmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Green_Leaves_23.bmp
Size 210.4KB
Processes 2136 (Delivery Note DHL AWB NO0023445667 MAY 2022.exe)
Type JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1920x1080, frames 3
MD5 99c02c0b1265392ed2b9bb310f0dd602
SHA1 3f6b95127f08778580c0a804bcf38cc0ca8da257
SHA256 8c09a2ceb8cf10cc480bae134f17a04e751c93408723ac3a7ab3b90666547fda
CRC32 B1B06191
ssdeep 6144:DSZFgJB8Q/EBoyyY8d0e99HubHmGuLVOlc3C:DSXgDB/EWBNd0e9967uclc3C
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis