Dropped Files | ZeroBOX
Name e3b0c44298fc1c14_cer589A.tmp
Empty file or file not found
Filepath C:\Windows\cer589A.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 59a0b32c22c79e7e_mxfhejj3c3gzzwrja.vbs
Submit file
Filepath C:\Users\test22\Links\MXFhejJ3c3gzZWRjA.vbs
Size 189.0B
Processes 3036 (certutil.exe)
Type ASCII text, with CRLF line terminators
MD5 149a6639da7897a928b6f96c0f80612d
SHA1 bd7527b2809ea227ff5f4107d3aecfd00809c1b6
SHA256 59a0b32c22c79e7e48614add0e5cdf846f50d38d46201077309534a093a723ac
CRC32 C623E287
ssdeep 3:9cNAWdgUdr3Em8jtyHIT9tHhRmLDB72f2pjKK4VIrVQIEAMiWAxAdRM:9cNAWdgUZN08HIHHGh7e2pjXrmj+ATM
Yara None matched
VirusTotal Search for analysis
Name cc24c06880ca2545_mxfhejj3c3gzzwrja.dat
Submit file
Filepath C:\Users\test22\Links\MXFhejJ3c3gzZWRjA.dat
Size 256.0B
Processes 2972 (cmd.exe)
Type ASCII text, with CRLF line terminators
MD5 90fdce7926232fafa31e2f24b260873c
SHA1 532b8e04db16a38334f609d6b015e9d2f6353f50
SHA256 cc24c06880ca25456d40bf829475a5df77f55549075a3e66e9b2b8d5f40fb2ef
CRC32 DAA8CE17
ssdeep 6:y9xs6lppwhHVCoJRC8C4vZjSY7BgpG5Q4T0I1dplXGnB:y9q6tc1JRi4hccT3dplXiB
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis