Dropped Files | ZeroBOX
Name 9371617131e1527b_wiryca.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nssEDDC.tmp\wiryca.dll
Size 244.5KB
Processes 2548 (festkon2.1.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 97e8e67903cf231aa5a21fe6a265a46f
SHA1 6a126a56659cddde7aa51d74b9a71a5513c103df
SHA256 9371617131e1527b811bc6364bc4a5c1938cb7ce4167dff6a5413b5d5b728f30
CRC32 83EA7B01
ssdeep 6144:wQp828khuhuRS5uEpmpC39kPIB8oYT9i3K:wQpb8khuhuRS5uEpmpC39kPoY
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name eb443a8b61b28c93_sypsymkz.ssg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\sypsymkz.ssg
Size 5.7KB
Processes 2548 (festkon2.1.exe)
Type data
MD5 0cfad56e0ce398dea064ef622df1c1dc
SHA1 1bbaf69b1257198c00c3b5b396421f2a53d7e3ee
SHA256 eb443a8b61b28c93adfb35ede922ecb0992342e1eac2c29b17bbaa54f95eda4b
CRC32 51C6401B
ssdeep 96:8UfTtXiAlVO0atHiL+moONW3Z2w6vMCsVnRtelbbCBwPnqsDISeqrnoSdz:tTtXiA3RmavMpVRm8wPnqKproS1
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nscED7C.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nscED7C.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name baf72d7a5e4feb7d_euxzvq.f
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\euxzvq.f
Size 205.2KB
Processes 2548 (festkon2.1.exe)
Type data
MD5 fcb732c6844926f2156f0f50047c8366
SHA1 1177552b9a4494c1e496b6a57b0eb3c2136df0a3
SHA256 baf72d7a5e4feb7debbc67c7855bcded6b7f99ba7e9fbbde316faea744907f65
CRC32 4664DD70
ssdeep 6144:dVUGdn1tUby4V3oMRwyrZjEQ4czNgxCDhqzgm4:k4n1tt4V3Fwyr8c0C/
Yara None matched
VirusTotal Search for analysis