Dropped Files | ZeroBOX
Name bf7c9b2af58aff0d_dllhost.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\NVIDIA\dllhost.exe
Size 2.7MB
Processes 1648 (data64_3.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 799c6629928f0b945662d787d85a60e6
SHA1 357ea36c557a9f397c3ef49084b83795c28c272c
SHA256 bf7c9b2af58aff0d7ee0c677ae8fdc106452f3a7eae437cc47dcb0ae36a9134b
CRC32 D77D49BF
ssdeep 49152:hkX17LLS6pLnlbv0l8jcsD0fFav+VPGHXsh6b95hBky5T3Pw7R4HL77:hSRWglb+8jcUV+VwX4e9nB15z0Q
Yara
  • UPX_Zero - UPX packed file
  • themida_packer - themida packer
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis