Dropped Files | ZeroBOX
Name 15129b382dfae5b2_driver.url
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Driver.url
Size 171.0B
Processes 660 (None)
Type MS Windows 95 Internet shortcut text (URL=<file:///C:\Users\test22\AppData\Roaming\Sysfiles\EasySup.exe>), ASCII text, with CRLF line terminators
MD5 fd46e07e3e5f1a133eea13271f7a1fb2
SHA1 c0a89478607c43d8a4d7b7bb52fbce98efa70a06
SHA256 15129b382dfae5b26d90f87981a51c80b496084b9aeb5a40730d6acb5d7023e5
CRC32 0A78AD94
ssdeep 3:HRAbABGQYm5uOmWxpcL4EaKC5SQnZ3h4CJ4ovstwWDmWxpcL4E2J5xAIlWc2Qh4S:HRYFVmwOmQpcLJaZ5lDJlvstwWDmQpcM
Yara
  • url_file_format - Microsoft Windows Internet Shortcut File Format
VirusTotal Search for analysis
Name 8d6abba9b216172c_driver.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Sysfiles\Driver.exe
Size 3.9MB
Processes 660 (None)
Type MS-DOS executable, MZ for MS-DOS
MD5 02569a7a91a71133d4a1023bf32aa6f4
SHA1 0f16bcb3f3f085d3d3be912195558e9f9680d574
SHA256 8d6abba9b216172cfc64b8802db0d20a1c634c96e1049f451eddba2363966bf0
CRC32 2D90BDE3
ssdeep 49152:SNDFFPJu8fBsVE6ij+RNg+UKpBvtqB3m1RC3Z:wzP88fBsnZTgOtqB3m1RC3Z
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • MPRESS_Zero - MPRESS packed file
VirusTotal Search for analysis