Dropped Files | ZeroBOX
Name 8bad231472ce99bb_oynbz.zxh
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\oynbz.zxh
Size 266.3KB
Processes 1460 (maya.exe)
Type data
MD5 1800de52920159770f15dfa35893893e
SHA1 8d3b7e82ceafdb0b3560e02033f24900194117e3
SHA256 8bad231472ce99bbe48777d8c381b7563587e137bba62d88e08d218d849bbf92
CRC32 6F51414D
ssdeep 6144:4RTgLRtnAJQPlsKny2UKu7t0brVW3kEcSu+l+nbxYdldP:lL3Blsgy27QT30SdQnbxYdlh
Yara None matched
VirusTotal Search for analysis
Name 0b8607fdf72f3e65_cookies.sqlite
Submit file
Filepath C:\Users\test22\AppData\Roaming\dgm51wdn.gbc\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite
Size 96.0KB
Type SQLite 3.x database, user version 12, last written using SQLite version 3038003
MD5 d367ddfda80fdcf578726bc3b0bc3e3c
SHA1 23fcd5e4e0e5e296bee7e5224a8404ecd92cf671
SHA256 0b8607fdf72f3e651a2a8b0ac7be171b4cb44909d76bb8d6c47393b8ea3d84a0
CRC32 842B3569
ssdeep 12:DQAwfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAwff32mNVpP965Ra8KN0MG/lO
Yara None matched
VirusTotal Search for analysis
Name 417c63ba2b158baf_xfzbh.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\xfzbh.exe
Size 361.5KB
Processes 1460 (maya.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2051a52d6c8e148e037dcf09d9df7015
SHA1 04c5cd0d1cafed7af3474379d9b774e6953c416e
SHA256 417c63ba2b158bafde49f36255b5a28456adfd11b7912178393a40eb3c248839
CRC32 09080CB6
ssdeep 6144:DWYtu0D9bhoKSoj/QED03mc8+z1zQpb+g40eMF:DWYI0D9bhoK1j/HD03n1zvwF
Yara
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name edb006e05cfa8501_Cookies
Submit file
Filepath C:\Users\test22\AppData\Roaming\dgm51wdn.gbc\Chrome\Default\Cookies
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 3f5ca3e29b1b60e298aeca0a32164c03
SHA1 f9b5ee59c31a3b06a6b8e476b22d2d7cf1fa8b66
SHA256 edb006e05cfa85015aa76c758d6298c279fd318cff0dbb286927c7ad45105488
CRC32 E1ACA097
ssdeep 24:TL2C0RlPbXaFpEO5bNmISHdL6UwcOxvo5:TYLOpEO5J/KdGU1Eo5
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsuBF82.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsuBF82.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 0c21aa1cda8ef133_jspemy.qt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\jspemy.qt
Size 7.4KB
Processes 1460 (maya.exe)
Type data
MD5 3926773019a3f2ab0834d45972870963
SHA1 8ac86237a1bf4d5d37e1aa48a467a470ef714508
SHA256 0c21aa1cda8ef133d18784c245f7fa318ce17b9dc68229a4f750a05ad891c802
CRC32 94377DB0
ssdeep 192:darcitQvArWiPvApMb9NudSJlFB1likwaZG1D7:uCYrNPvA4+Sj1likrGx7
Yara None matched
VirusTotal Search for analysis
Name 88f9dc0b9a633e43_cookies.sqlite
Submit file
Filepath C:\Users\test22\AppData\Roaming\dgm51wdn.gbc\Thunderbird\Profiles\g8t0pe67.default-release\cookies.sqlite
Size 512.0KB
Type SQLite 3.x database, user version 11, last written using SQLite version 3031001
MD5 dd47ebe6866ad2ab59d0caa1de28d09e
SHA1 afdf6eb7a01bb7ef4c9d768b65abbbeae5ba2663
SHA256 88f9dc0b9a633e43c6d2c6fae136e782c15aa38c1601dcff948987f1c2a391c3
CRC32 8DEE9EEA
ssdeep 24:DQHtJl32mNVpP965hKN0MG/lZpNjCKRIaU5BnCMOkC0JCpL3FYay:DQfrbWTTTqtStLm
Yara None matched
VirusTotal Search for analysis