Dropped Files | ZeroBOX
Name 5c9b68f4ebf6a2c4_winload.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\onefile_2084_133241120670312500\WinLoad.exe
Size 32.0KB
Processes 2084 (WinLoad.exe)
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 e3a1d30c0c83df4074e0fe8dac52dcd5
SHA1 e5cc23d187a6c1948100b300260c9041330df804
SHA256 5c9b68f4ebf6a2c4414d3aa42cca2f80f3daf2f9bdfbe4f0c4dd9fc710a1418b
CRC32 E2AEF83B
ssdeep 768:mKwjdZvw4/DQLN8g9+lyY39LJGze3wh3ps2wep:STwo/omnRwhZs2wep
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis