Dropped Files | ZeroBOX
Name c61f3282d5daa06f_provisionshare.url
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\provisionshare.url
Size 128.0B
Processes 2456 (Zocymkpxeu.exe)
Type MS Windows 95 Internet shortcut text (URL=<"C:\Users\test22\AppData\Local\Temp\Zocymkpxeu.exe">), ASCII text
MD5 6f872a113e28905ef74d02d9ed2d3109
SHA1 79a24a21ef7dd3f7d1ffbc96ea955e4432422a64
SHA256 c61f3282d5daa06fbd7f96db5d745f99e0e88c01cbd0a49b32eba0e989de906a
CRC32 DB635D17
ssdeep 3:HRAbABGQFwImWxpcL4E2J5xAIaD602ryEJcWt9R86Vn:HRYFxImQpcLJ23fNryEL18+
Yara
  • url_file_format - Microsoft Windows Internet Shortcut File Format
VirusTotal Search for analysis