Dropped Files | ZeroBOX
Name 0af038a51b667ec9_work.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\work.exe
Size 1.9MB
Processes 2536 (wdagad.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 636373768d83d47a8469e19e7c364cba
SHA1 9a0af5c6a5af766c45d2d318727843f4909bf35f
SHA256 0af038a51b667ec95cac7ebd4a4c04b5011c451e211c34cb1c918891e955268a
CRC32 3570A9A1
ssdeep 49152:ABRkM7NZ/lkhTOUGZhQkUfImTlDRDiH1ocB:auqRkBOUGZh1UfF9Diis
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 065d2b17ad499587_1.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\1.bat
Size 35.0B
Processes 2536 (wdagad.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 ff59d999beb970447667695ce3273f75
SHA1 316fa09f467ba90ac34a054daf2e92e6e2854ff8
SHA256 065d2b17ad499587dc9de7ee9ecda4938b45da1df388bc72e6627dff220f64d2
CRC32 4B410F4B
ssdeep 3:mKDDFRK58FoXMMH:h08Foc2
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_34860921
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_34860921
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name a44f44323d3188fd_driver.url
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Driver.url
Size 173.0B
Processes 2828 (None)
Type MS Windows 95 Internet shortcut text (URL=<file:///C:\Users\test22\AppData\Roaming\Sysfiles\fesa.exe>), ASCII text, with CRLF line terminators
MD5 3f33899223297845b68314df58be5571
SHA1 dd2d6ba3397728408277a7975249fc74d5420b4d
SHA256 a44f44323d3188fd503e92b0bcbb87f81c1324c34546c067f91f9fcd1b641357
CRC32 C8A45F94
ssdeep 3:HRAbABGQYm5uOmWxpcL4EaKC5SQnELAdNvQJ4ovstwWDmWxpcL4E2J5xAIkjdcH9:HRYFVmwOmQpcLJaZ5lEk9QJlvstwWDmM
Yara None matched
VirusTotal Search for analysis
Name 3a48d4a5106dd9ba_fesa.exe
Submit file
Filepath c:\users\test22\appdata\roaming\sysfiles\fesa.exe
Size 4.0MB
Processes 2692 (work.exe) 2828 (None)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 33b4baef7b0a6ad57a7d30af324c4efd
SHA1 b169a559615a8448d7ed7da56d36a6850d2092e2
SHA256 3a48d4a5106dd9ba74e5fccfe58bf65581ee894d7f3ca1b15e6680fc912cd150
CRC32 167D47A8
ssdeep 49152:ENDFFPJu8fBsVE6ij+RNg+UKpBvtqB3m1RC3:SzP88fBsnZTgOtqB3m1RC3
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Is_DotNET_EXE - (no description)
  • MPRESS_Zero - MPRESS packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 8d6abba9b216172c_driver.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Sysfiles\Driver.exe
Size 3.9MB
Processes 2828 (None)
Type MS-DOS executable, MZ for MS-DOS
MD5 02569a7a91a71133d4a1023bf32aa6f4
SHA1 0f16bcb3f3f085d3d3be912195558e9f9680d574
SHA256 8d6abba9b216172cfc64b8802db0d20a1c634c96e1049f451eddba2363966bf0
CRC32 2D90BDE3
ssdeep 49152:SNDFFPJu8fBsVE6ij+RNg+UKpBvtqB3m1RC3Z:wzP88fBsnZTgOtqB3m1RC3Z
Yara
  • IsPE64 - (no description)
  • MPRESS_Zero - MPRESS packed file
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis