Dropped Files | ZeroBOX
Name d6431d5645fffd05_d93f411851d7c929.customDestinations-ms~RF1825f60.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF1825f60.TMP
Size 7.8KB
Processes 2188 (powershell.exe) 2412 (powershell.exe)
Type data
MD5 260d23ce04a8f8555a73b7d2dc15e911
SHA1 ebad746fb7de847c50f7502a44f6e35534733efd
SHA256 d6431d5645fffd05a23166d630253bc7ce8c099cf6e9c956f8ae5e1249ee8588
CRC32 11D6B213
ssdeep 96:ctuCeGCPDXBqvsqvJCwo5tuCeGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:ctvXo5tvbHnorrxQ
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 2b00fc4f541ac10c_freebl3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\freebl3.dll
Size 326.5KB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 ef12ab9d0b231b8f898067b2114b1bc0
SHA1 6d90f27b2105945f9bb77039e8b892070a5f9442
SHA256 2b00fc4f541ac10c94e3556ff28e30a801811c36422546a546a445aca3f410f7
CRC32 4DE53F71
ssdeep 6144:u8YBC2NpfYjGg7t5xb7WOBOLFwh8yGHrIrvqqDL6XPbjm:ubG7F35BVh8yIZqn6vm
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 824fae3331b95e2f_.l.DkIb.tmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\.l.DkIb.tmp
Size 40.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 41c19a9e8541fcb934c13c075bf47721
SHA1 648a7622d533d79b9a0bb31dc370134ec3a75ed7
SHA256 824fae3331b95e2f88ca60c87a6c9569086906ec76fc1db8d6dee9adddc4e80c
CRC32 560F7642
ssdeep 48:+35TqYzDGF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:Ulce7mlcwilGc7Ha3f+u
Yara None matched
VirusTotal Search for analysis
Name fb419a60305f1735_mozglue.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\mozglue.dll
Size 134.0KB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 75f8cc548cabf0cc800c25047e4d3124
SHA1 602676768f9faecd35b48c38a0632781dfbde10c
SHA256 fb419a60305f17359e2ac0510233ee80e845885eee60607715c67dd88e501ef0
CRC32 0E1302FA
ssdeep 3072:4kdWyaKm15vd/q/Py9UbfkVgxp1qt/t3PvT4UD2JJJvPBrSezRy:Fdtm15vtSfkVgxp12/t3PLxD2JJJvPQZ
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
VirusTotal Search for analysis
Name c40bb03199a2054d_vcruntime140.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\vcruntime140.dll
Size 81.8KB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 7587bf9cb4147022cd5681b015183046
SHA1 f2106306a8f6f0da5afb7fc765cfa0757ad5a628
SHA256 c40bb03199a2054dabfc7a8e01d6098e91de7193619effbd0f142a7bf031c14d
CRC32 9BB5124B
ssdeep 1536:AQXQNgAuCDeHFtg3uYQkDqiVsv39niI35kU2yecbVKHHwhbfugbZyk:AQXQNVDeHFtO5d/A39ie6yecbVKHHwJF
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • Malicious_Library_Zero - Malicious_Library
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 225700ea7b55e3d8_programs.batXstart
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\programs.bat:start
Size 80.0B
Processes 1648 (AnyDesk.exe)
Type ASCII text, with no line terminators
MD5 e7b352f577a25aac64a19dc23abd2c71
SHA1 91563e25a876b3c8884deb8b51772ba547f49415
SHA256 225700ea7b55e3d89d0dd59da04e5007c3149c62961c6550bbee0c69c67bab63
CRC32 B7507613
ssdeep 3:eGAjGJw1mWxpg9l+3dAlbVJHERMQhM:ZuGJw1mQpS0ABj
Yara None matched
VirusTotal Search for analysis
Name 1ac6a05f2fe3b95d_programs.bat
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\programs.bat
Size 141.0B
Processes 1648 (AnyDesk.exe)
Type ASCII text, with no line terminators
MD5 aafe63c0e3a10ecd523de79d0c2f2400
SHA1 b6aa19f83e8bb50461369bf51360d7ff736ccf18
SHA256 1ac6a05f2fe3b95dd31f9bbdab33222a155f3e2311f42852d993fadd0bea3f48
CRC32 2A9FF243
ssdeep 3:QwZ2vOUrKaM6eNGRjDmWxpcL4EaKC5SufyM1K/RFofD6tRQLRWLyLRHgn:QElPhxumQpcLJaZ5SuH1MUmt2FWLyS
Yara None matched
VirusTotal Search for analysis
Name 334e69ac9367f708_msvcp140.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msvcp140.dll
Size 429.8KB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 109f0f02fd37c84bfc7508d4227d7ed5
SHA1 ef7420141bb15ac334d3964082361a460bfdb975
SHA256 334e69ac9367f708ce601a6f490ff227d6c20636da5222f148b25831d22e13d4
CRC32 97BCF588
ssdeep 12288:Mlp4PwrPTlZ+/wKzY+dM+gjZ+UGhUgiW6QR7t5s03Ooc8dHkC2es9oV:Mlp4PePozGMA03Ooc8dHkC2ecI
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name a9220271c0eb79e5_d93f411851d7c929.customDestinations-ms~RF1824cb3.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF1824cb3.TMP
Size 7.8KB
Type data
MD5 b0c9ff441742f3847ea27da9dee7f2cd
SHA1 c42a1eb32ba953a0ce5d8635caabf71b5b281495
SHA256 a9220271c0eb79e5750e0d0e62058ecac560e09cdf9e82ef61aeeabada5d48a4
CRC32 0BBCAB1A
ssdeep 96:RutuCOGCPDXBqvsqvJCwo+utuCOGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:UtvXoxtvbHnorrxQ
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 78758bf7f3b3b5e3_nss3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nss3.dll
Size 1.2MB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 d7858e8449004e21b01d468e9fd04b82
SHA1 9524352071ede21c167e7e4f106e9526dc23ef4e
SHA256 78758bf7f3b3b5e3477e38354acd32d787bc1286c8bd9b873471b9c195e638db
CRC32 5E37D562
ssdeep 24576:Ab5zzlswYNYLVJAwfpeYQ1Dw/fEE8DhSJVIVfRyAkgO6S/V/jbHpls4MSRpMxkxo:+zW5ygDwnEZIYkjgWjblMSRpMqm
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name bb3ff746471116c6_softokn3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\softokn3.dll
Size 141.5KB
Processes 2292 (AnyDesk.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 471c983513694ac3002590345f2be0da
SHA1 6612b9af4ff6830fa9b7d4193078434ef72f775b
SHA256 bb3ff746471116c6ad0339fa0522aa2a44a787e33a29c7b27649a054ecd4d00f
CRC32 AEBEA9BF
ssdeep 3072:0Af6suip+d7FEk/oJz69sFaXeu9CoT2nIVFetBWPqeFYMMa:J6PbsF4CoT2OeN43Ma
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name b8fc40447cbfc774_2023-05-12_01.35.44
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft Vision\2023-05-12_01.35.44
Size 58.0B
Processes 2292 (AnyDesk.exe)
Type data
MD5 36441338c9f0d02a862f391355acff31
SHA1 fce77ebab72dcb6784b898d9925b49b665567360
SHA256 b8fc40447cbfc774b39df0462a46a1b857d2cde84f527bd52a4713ccd81350f6
CRC32 647085FB
ssdeep 3:DlIVK4loedpl4PlElTIu:Dl1oJz4e+u
Yara None matched
VirusTotal Search for analysis