Dropped Files | ZeroBOX
Name 8fda5f8eb663bc62_lljwdi.qa
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\lljwdi.qa
Size 7.9KB
Processes 2556 (obinna.exe)
Type data
MD5 4e7bc824802cb6a328f33ee5e0ecabe7
SHA1 580822976fdca519a1b28a6854d301b9c02fc0b3
SHA256 8fda5f8eb663bc62af1373c781f0122651e219a73e98134fa7bec4c29afe2fbd
CRC32 ED1909FC
ssdeep 192:darcitQvArWiPv1Anb9nyj0cQsXvnFtScJDd24S4xw1sNI:uCYrNPv1AbsdQsXvnFFDdTS4Qs+
Yara None matched
VirusTotal Search for analysis
Name 0c1a15e1cc5ea221_ktdyienw.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\soxhdmvrbvfo\ktdyienw.exe
Size 52.5KB
Processes 2656 (rbptobi.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4f9678c879b1ffe1f9fe858c178e340e
SHA1 eb03f28d56536ba7ef2cbc92290475f83e0572f1
SHA256 0c1a15e1cc5ea22195cacadc80e98a67f18f349e29256a2a2639d753ae866414
CRC32 6D5D8DAC
ssdeep 768:bInbnZTRSqFeviCOBQiNhhGtVd/1fVy3ReMyPNfmRQPBwEDbAntRZ/6qzB:b+ZlkviCOBDzotVd/oURdRPBStR9
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nssEC82.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nssEC82.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name f14e0898434040ac_zfiflbom.nc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\zfiflbom.nc
Size 263.2KB
Processes 2556 (obinna.exe)
Type data
MD5 81d9fcf449061d9dbdde16cf9117ae4a
SHA1 f995b2b2b208f0a6ad5386b6e732fdbb5afe22eb
SHA256 f14e0898434040ac49ab0d9ec44c8ef5877ba54b1a753a5db7f44fa270845f14
CRC32 21297617
ssdeep 6144:sTv5gxcN2Id4npWpbl3bAXx2BHeYSXqIqMoi39Rt6ZredBXS:exgxqzd4n0Hre9qE9ROadE
Yara None matched
VirusTotal Search for analysis