Dropped Files | ZeroBOX
Name fb7af276ef2387e5_dllhost.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\NVIDIA\dllhost.exe
Size 2.4MB
Processes 2080 (data64_3.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 819ebb36bf053ef2d41eec6fc3433e0e
SHA1 6818dd11e03b8283b3a57d02edb6329e216b4d07
SHA256 fb7af276ef2387e5886ebb03a2fb337c4e953207b125441bed9849ef53141600
CRC32 4A0D1C0B
ssdeep 49152:fdMeCL9PeqU9QWsNNHrxwYb32kR/pG1OD5TDe8EnGON:HO4qkQNNHrxwYbGkR/pKODhaDnGO
Yara
  • UPX_Zero - UPX packed file
  • Is_DotNET_EXE - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • PE_Header_Zero - PE File Signature
  • themida_packer - themida packer
  • IsPE32 - (no description)
VirusTotal Search for analysis