Dropped Files | ZeroBOX
Name 72c40c5c5ae362bf_d9e1c3_0ec2df3125b34e10ad269f8b3dd4e71d.txt.ps1
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\d9e1c3_0ec2df3125b34e10ad269f8b3dd4e71d.txt.ps1
Size 5.2MB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 5e63744a4fad5be640aa0a7a2e444a3d
SHA1 cdb23ae0279212d3c04f3237843dba84a6c63282
SHA256 72c40c5c5ae362bfa5b37be9d7d4305bd0ecbf549f9ed087126ac4f2c66ff5e2
CRC32 096E7DE0
ssdeep 384:NROOOOOWCOOraJOOOOOvL5OeOhyz5OOqOO0OOyOOhOOW+jOOZaOOBKOOqSOOCOOD:Nrq+pU7hqtF0B
Yara None matched
VirusTotal Search for analysis
Name b7c225ef3cc3e875_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2552 (powershell.exe)
Type data
MD5 81ca4510272caf505e8091e9a28cb716
SHA1 71414aeec9f1e4a6f5a461b01700cc9cc992cd9e
SHA256 b7c225ef3cc3e87506150eb140e7b9cc127a3469c50a808854acac71a53d98bf
CRC32 FC31E90F
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:EtCgXoRtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 03e74538b8642563_kamasutrakim.~!!@#!!!!!!!!!!!!!!!~
Submit file
Filepath C:\ProgramData\MINGALIES\KAMASUTRAKIM.~!!@#!!!!!!!!!!!!!!!~
Size 5.2MB
Processes 2552 (powershell.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 5b9cb1593b52e93a32be1a1863355b2c
SHA1 03864875488f822d4c8d7ce9f6a328cfa95dca4e
SHA256 03e74538b864256353625619770d4d10fa3e3c5d83ad09823907b2ed31c3e41f
CRC32 6072325E
ssdeep 384:uOOOOOWCOOraJOOOOOvL5OeOhyz5OOqOO0OOyOOhOOW+jOOZaOOBKOOqSOOCOORW:qq+pU79qt/
Yara None matched
VirusTotal Search for analysis