Dropped Files | ZeroBOX
Name 6caf58fa33459b0c_nqvqpewj.idg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nqvqpewj.idg
Size 205.7KB
Processes 2544 (lifting.exe)
Type data
MD5 5752efc410949a75d4500c34380f8eb0
SHA1 9a19b860e2b6ade4d0101e9caa0ce0d802045018
SHA256 6caf58fa33459b0c48376683be503ae02bbaf9cabd32ac2ffbd1e0521e31e181
CRC32 B6101409
ssdeep 6144:IcYwhvrJEj+bfhHy35QuisBz9P3DEAhTiNoFCa:lNEkF2QwvqNoF
Yara None matched
VirusTotal Search for analysis
Name 77106189297cbc95_xlobkc.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\xlobkc.exe
Size 108.5KB
Processes 2544 (lifting.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4ed46141069aeea5161c922288f99acb
SHA1 1c7e9af04582e909e25ca0f96ebaaeb25c8ded70
SHA256 77106189297cbc95b0d7d0730f9ac5490c25c52f950cc37fdd3f1a1833762e3f
CRC32 622B728F
ssdeep 3072:wgke83whBLmHr9x5FKEY8Hs+k3d0Ge4NStHywRR+NbX3:wgwA0rGEY0AWRY3
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name cf54f18056ca5337_coenhi.ce
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\coenhi.ce
Size 6.0KB
Processes 2544 (lifting.exe)
Type data
MD5 ad4986885dfead16cf8bd5ee5f096ddc
SHA1 994955b97ae466ddddf7b65839978eaac27f5421
SHA256 cf54f18056ca5337a6354193238978cf6b50e2b57e867d6be1d90bb9b66d0cd6
CRC32 86AAF4A4
ssdeep 192:FarcR7LhX1ShwGjFIOepiuas4xIxvg/1cymSBQiF:JKhtepi7s0IxvT+Z
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsmEF90.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsmEF90.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis