Dropped Files | ZeroBOX
Name a2ce3a0fa7d2a833_e0f5c59f9fa661f6f4c50b87fef3a15a
Submit file
Filepath C:\Users\test22\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
Size 893.0B
Processes 2552 (powershell.exe)
Type data
MD5 d4ae187b4574036c2d76b6df8a8c1a30
SHA1 b06f409fa14bab33cbaf4a37811b8740b624d9e5
SHA256 a2ce3a0fa7d2a833d1801e01ec48e35b70d84f3467cc9f8fab370386e13879c7
CRC32 1C31685D
ssdeep 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x
Yara None matched
VirusTotal Search for analysis
Name caa5405f654d266e_debug.vbs
Submit file
Filepath C:\Windows\Temp\Debug.vbs
Size 332.6KB
Processes 2884 (curl.exe)
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 a6113c3b4f3bb50df9586993ae28c5c3
SHA1 c831fea9ae4c3f5ea7178c3a59df44066ffe2def
SHA256 caa5405f654d266e079f1cda1e3c8e9c05fddb7264da52a8dbc43648a832a455
CRC32 C82D2FFA
ssdeep 1536:LdddddguoSI5E8jn/1EEb5EE/ELl9ryMjDm9fj3UkrJHnNEEEEmrqhM3KEd4UnPW:OkflMDMakT6kBPMzMakclqiDHtl
Yara None matched
VirusTotal Search for analysis
Name 3d827e0bd4303d5a_e0f5c59f9fa661f6f4c50b87fef3a15a
Submit file
Filepath C:\Users\test22\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
Size 252.0B
Processes 2552 (powershell.exe)
Type data
MD5 ccbee2569216c9c0783ee7370971befc
SHA1 ec6b0c6e96223dc8f9ca9b3b8e290b0220f7a00d
SHA256 3d827e0bd4303d5a001be867c48fd5104c2327ae084486ae5b5f187c7c6643d4
CRC32 2F9BE75A
ssdeep 3:kkFkl9gm8M/tfllXlE/zwEkhlHllPlzRkwWBARLNDU+ZMlKlBkvclcMlVHblB8V6:kKXm8sqwrlXliBAIdQZV7IpAhx
Yara None matched
VirusTotal Search for analysis
Name d63e28b604dc564f_f8e6f8667760784c.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\f8e6f8667760784c.customdestinations-ms
Size 5.2KB
Processes 2672 (powershell.exe)
Type data
MD5 7ed1c84dd2a18009cf6b3d4c322d492d
SHA1 366aaa94de16c8cff476056d411858fe705d5a02
SHA256 d63e28b604dc564f00f6a04fa8b0cd974fcc1b377c0cb0d73608d7a5f3272bcd
CRC32 B0B7BABC
ssdeep 48:kp/qsHlRVlpREbfp/qsHlRVlpRbEHjrb9buM4b3+SogZolxwUQlUVul:mrADrrEHjn9j47HwxGlUVul
Yara None matched
VirusTotal Search for analysis
Name b7c225ef3cc3e875_d93f411851d7c929.customDestinations-ms~RFef2744.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RFef2744.TMP
Size 7.8KB
Processes 2808 (powershell.exe) 320 (powershell.exe)
Type data
MD5 81ca4510272caf505e8091e9a28cb716
SHA1 71414aeec9f1e4a6f5a461b01700cc9cc992cd9e
SHA256 b7c225ef3cc3e87506150eb140e7b9cc127a3469c50a808854acac71a53d98bf
CRC32 FC31E90F
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:EtCgXoRtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis