Dropped Files | ZeroBOX
Name 24a53033a2e89acf_db.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\db.dll
Size 52.0KB
Processes 2656 (lish.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1b20e998d058e813dfc515867d31124f
SHA1 c9dc9c42a748af18ae1a8c882b90a2b9e3313e6f
SHA256 24a53033a2e89acf65f6a5e60d35cb223585817032635e81bf31264eb7dabd00
CRC32 05945495
ssdeep 384:XehpWSsdMRgTh4QPt0RaYaGCp9FclU2sSadM7yjR+Lcuczw0RoR/5rdy7olDJfUw:ipW6+grtlU2v7yGLwwouflpZ2tVtkTF
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 07b7dbc6e80247ce_db.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\db.dat
Size 557.9KB
Processes 2656 (lish.exe)
Type data
MD5 b15c9612f747a2c7d6c429275c853b23
SHA1 46b5013dcc6677feabafb3c35d8aec6e79e1e6d3
SHA256 07b7dbc6e80247cee12695bc386079435ec90d0228f799ff884330b9f4e3c2d5
CRC32 D2B13F12
ssdeep 12288:rUd0UAQgTkZYxdNLCjIqJYCTKTZmF5zRn5cxhP:rUddADm/jpOTZmF5zRGf
Yara None matched
VirusTotal Search for analysis