Dropped Files | ZeroBOX
Name c22f8232e50a9edd_a.ps1
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a.ps1
Size 1.7MB
Processes 2540 (powershell.exe)
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF line terminators
MD5 52adf1f0d6440cc8040669959aa51d8c
SHA1 040016e396cf40202c2dacd793a811331494908d
SHA256 c22f8232e50a9edda34c402bd636e251f636b66f3a7bbe0b200cd71afbe9cad6
CRC32 C6671A64
ssdeep 1536:MtRm+igK1+Z3DQhKvLI7CkBn2+oXR51Fdyvrlw9u5BVL+jtffDD2FP+Xl6UlipUm:4ra+h7ARWUt
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name b7c225ef3cc3e875_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2540 (powershell.exe)
Type data
MD5 81ca4510272caf505e8091e9a28cb716
SHA1 71414aeec9f1e4a6f5a461b01700cc9cc992cd9e
SHA256 b7c225ef3cc3e87506150eb140e7b9cc127a3469c50a808854acac71a53d98bf
CRC32 FC31E90F
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:EtCgXoRtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis