Dropped Files | ZeroBOX
Name d9d0991bb2879169_deep.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-V66SG.tmp\deep.exe
Size 4.3MB
Processes 2636 (RedGiant Activation Service Unlocker 2023.2.1.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 81f0a145df9880035e990e01dabd384a
SHA1 ad2bef80f02b5b0a9f53fca494c33bd4ac492aaf
SHA256 d9d0991bb287916944a8860e9f4e196a1fcb8deb5d478641e6ef3a8f243d26e5
CRC32 A71033C5
ssdeep 98304:MkLKpGcx/S8sZwlMn7MIBj54erL4mfQju5uFo:rKlxpselM7MojmerLZYMuFo
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • mzp_file_format - MZP(Delphi) file format
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 95cebcc405540fdf_deep.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-LU16A.tmp\deep.tmp
Size 3.0MB
Processes 148 (deep.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 477c6f63cc670107dc6e58badfdc5845
SHA1 33aefd815f84dbd6fdc70238e733f8285263de8c
SHA256 95cebcc405540fdfe59fe4ec0b86d809c31109bc13dacb7f83fc8e1f423cda40
CRC32 7E93138A
ssdeep 49152:EWGtLBcXqFpBR6SVb8kq4pgquLMMji4NYxtJpkxhGjIHTbE333ey:QtLutqgwh4NYxtJpkxhGn333/
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • mzp_file_format - MZP(Delphi) file format
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 63931d59b463ceca_vr.lic
Submit file
Filepath c:\programdata\maxon\rlm\vr.lic
Size 116.0B
Processes 2636 (RedGiant Activation Service Unlocker 2023.2.1.tmp)
Type ASCII text, with no line terminators
MD5 683896c6a48196b6597116aa99823530
SHA1 0f7854f50bb10fa9987484a8fea9c58b7681308c
SHA256 63931d59b463ceca304853de2e6c68526f975d6b530efb17a98801896c412f56
CRC32 6677B39D
ssdeep 3:sfI0F/Ec6La/DCY6v+w3ykpkpkpkpkpkpkpkpkpkpkpkpkpkn:gmzm/6v+6ykpkpkpkpkpkpkpkpkpkpka
Yara None matched
VirusTotal Search for analysis
Name afb134cdf3a3d342_red giant service.exe
Submit file
Filepath c:\program files\red giant\services\red giant service.exe
Size 8.6MB
Processes 2236 (deep.tmp)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 ac3f9af7109d3ec3ce5c008601c5016c
SHA1 414cb0637adea2390794c574303db64428dd6540
SHA256 afb134cdf3a3d34235ad7c5ea5fa27b7c9184c16cc5626db0e930edc51a079bf
CRC32 896E88B7
ssdeep 98304:B2++A/cnCZ+yy3M+H8QexrxWvlB8CNJ6CysWSKDj:wqbUy5s+sz8CH6C7WSKDj
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 2f6294f9aa09f59a__iscrypt.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-S19HO.tmp\_isetup\_iscrypt.dll
Size 2.5KB
Processes 2236 (deep.tmp)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 a69559718ab506675e907fe49deb71e9
SHA1 bc8f404ffdb1960b50c12ff9413c893b56f2e36f
SHA256 2f6294f9aa09f59a574b5dcd33be54e16b39377984f3d5658cda44950fa0f8fc
CRC32 FB05FA3A
ssdeep 24:e1GSgDIX566lIB6SXvVmMPUjvhBrDsqZ:SgDKRlVImgUNBsG
Yara
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 388a796580234efc__setup64.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-S19HO.tmp\_isetup\_setup64.tmp
Size 6.0KB
Processes 2236 (deep.tmp)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
CRC32 2CDCC338
ssdeep 96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
Yara
  • UPX_Zero - UPX packed file
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis