Dropped Files | ZeroBOX
Name 40681937c243262b_zqsexr.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nscF08C.tmp\zqsexr.dll
Size 11.5KB
Processes 2552 (csrssfs.exe)
Type PE32 executable (DLL) (native) Intel 80386, for MS Windows
MD5 1ab65a4fc6b47ce4ee3c3a2bc1ba91a5
SHA1 c205dcb78b7b150cb52d075eab3f5aa1d859c07c
SHA256 40681937c243262b919b7c6c20a55102d327c17afacfc55345e98ee124ba4dfe
CRC32 E969A180
ssdeep 192:JIZ7O78X37mVE8X3pETtXiA3Fh7xe3VjASPtqKprCDS:JK7Gj28ETtBT7oDP5CDS
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nshF00D.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nshF00D.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 48a54424b7ae5e83_opjlfvroz.ga
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\opjlfvroz.ga
Size 211.4KB
Processes 2552 (csrssfs.exe)
Type data
MD5 bd1f2740c4de3c8fed4b10cb3307722c
SHA1 ee728b07bcc2a74c6e37dabf24cbf850220fd375
SHA256 48a54424b7ae5e8345a81ae94f8abab2e7c2be62e8e99957244979f70ab5abaa
CRC32 F8D95D0A
ssdeep 6144:nvPEkRYjeFHGFip5GVSxvYEqW6HjW2cff4:nnHdFmF2iSxwWqTcfA
Yara None matched
VirusTotal Search for analysis