Dropped Files | ZeroBOX
Name 3337faf918dbf673_gfff.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\jakef\gfff.exe
Size 1.6MB
Processes 2632 (Muqpgf.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 5aaffd3bd21341aabdfdae52e487813b
SHA1 6595d33e2bc87a5866ab374bfe69b1016e0e83d6
SHA256 3337faf918dbf673268d01fc2eee9cdd5f0996a050e37114bc54e25a1d44c157
CRC32 288FE554
ssdeep 49152:A3M/kxJeXxGkdYd5ym7DZ9JrMM2QBukP5Q6l6Ka:GM/rXxfsDdrql
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis