Dropped Files | ZeroBOX
Name cb260ed2c164b437_arzawa110.oml
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Arzawa110.oml
Size 397.3KB
Processes 2648 (wlanext.exe)
Type data
MD5 fc0c9e74ac3d89b3af3f10d2db70337b
SHA1 b5a4f0f980029960f9f08791192593126b4ab508
SHA256 cb260ed2c164b43733e08aaf9c93b485ba21cc470f8fee5f36d1d8bfd0eed35e
CRC32 4D7B0211
ssdeep 768:tljlpo9ESFhlIhAOgkot7jTaH/RvAbLloKeADBPQ76sFAZoNuPu7JF6+jYh8M/21:vUtt3eYD1AUZ4rZefl
Yara None matched
VirusTotal Search for analysis
Name b4f840ed3b64b096_landsretssagfrerens2.bed
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Landsretssagfrerens2.bed
Size 345.5KB
Processes 2648 (wlanext.exe)
Type data
MD5 694112c16d0e1cc3a6941db2327bc64f
SHA1 a5f6a9143d86cccf20c3f51d6ff659cecda60c21
SHA256 b4f840ed3b64b0965db34c17eb79b975c88bcafd31a4a062a55296e64faeca3d
CRC32 098BB3DD
ssdeep 768:4HkZ4eHrnsOoYtvfskhXGihoxbUHgF9yKQ7vxf0Huhz6qTKbTG3ZQ8eF0yh/Ah1q:h3+zwObi3FxZrf97gWKKpE
Yara None matched
VirusTotal Search for analysis
Name b7c225ef3cc3e875_d93f411851d7c929.customDestinations-ms~RF16f6661.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF16f6661.TMP
Size 7.8KB
Processes 2792 (powershell.exe) 2884 (powershell.exe)
Type data
MD5 81ca4510272caf505e8091e9a28cb716
SHA1 71414aeec9f1e4a6f5a461b01700cc9cc992cd9e
SHA256 b7c225ef3cc3e87506150eb140e7b9cc127a3469c50a808854acac71a53d98bf
CRC32 FC31E90F
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:EtCgXoRtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 12099de0a18a2739_fiskeredskabers.ise
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Acerae\Threap\fiskeredskabers.ise
Size 410.1KB
Processes 2648 (wlanext.exe)
Type data
MD5 cff3fa7edc20ef0a456cf79b8921c985
SHA1 098286ee748ec5174ced21f06ac4172fae005b8e
SHA256 12099de0a18a2739365d6bc9971d3a5f56b7ea8afa1f3ed66c8ab33149f1ad37
CRC32 B485F02C
ssdeep 768:7NS2T9ICyUb7Ku9bkg4f7jwTkrJ5nnk8sXe6cAbBNb4kDGbVISaPaMN3DLsXgy0B:nSjwwr4D6X8k0Iz94hFmQGzfJuIi5v
Yara None matched
VirusTotal Search for analysis
Name fdfa13e2eead2586_milieubeskyttelsesreglementernes.tyn
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Paco\milieubeskyttelsesreglementernes.tyn
Size 561.6KB
Processes 2648 (wlanext.exe)
Type data
MD5 c181fba162db55fa38300f0c7008389a
SHA1 0e991e0e30fa0512911320d7747d0cb37879ad55
SHA256 fdfa13e2eead25861bfa430223b9bd14dd91636335953610cc584ee42e703c79
CRC32 44D5DEF7
ssdeep 1536:Pc2JZWIRaVylxQVRNFoEi4dmFcuvz6qQpbqzaZ4UwzsL:PdduVRNXmFcuvzAp5L
Yara None matched
VirusTotal Search for analysis
Name 7cf6f28e81464bc7_tourneys.txt
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Paco\tourneys.txt
Size 476.0B
Processes 2648 (wlanext.exe)
Type ASCII text, with CRLF line terminators
MD5 9222b909e2244335b372fa166d7c2c4f
SHA1 c454c0f956be17d0c9054eebb96f2c688299262f
SHA256 7cf6f28e81464bc76620e7f25bb4bdfeafb872d3450a64e700297a199a2cd4a4
CRC32 796F6896
ssdeep 12:oxn3BXRr8Uk9OPBqXZ8dctVtqJJaNyNAS0QFdMUX85WgU:S3BXR8O8XZUctV8USpFgYgU
Yara None matched
VirusTotal Search for analysis
Name ecc50cc84cf52756_tyngdepunktsforskydningens236.fon
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Solskinnets\Climacium\Ekspliciterende\Tyngdepunktsforskydningens236.fon
Size 343.4KB
Processes 2648 (wlanext.exe)
Type data
MD5 65ec9192752e2a20a5b9621ed706ba40
SHA1 15deba8c747004e7ed43fb27fb3fc633586dc829
SHA256 ecc50cc84cf5275665ed5cf926e98924a91ef192172c1c197e3479ac7632e492
CRC32 CB21125A
ssdeep 768:pAWxdi6JDvgFGk6IfMGuL7uDn6YNOf74zMh8SG7TdK26uNzFbUdx2TEeWQSh8VEC:608tQw/FuRVjCPxpv
Yara None matched
VirusTotal Search for analysis
Name 218545d41377e111_ungdomsfngselet185.fus
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Acerae\Threap\Ungdomsfngselet185.fus
Size 309.5KB
Processes 2648 (wlanext.exe)
Type data
MD5 f68aacf822112e1a0177b4d628f244b7
SHA1 d59d6bb1020889271af1f89136bbf7394f61ea76
SHA256 218545d41377e11198cb7bfa7ecab8485f675e76dbbf7c489558b48d6e6ef932
CRC32 55F37E47
ssdeep 768:dRM+qnukF5BPfZ7PMRsG6h7oF5pE7m/NWDnlCiBeFEIUfp03pk6ZlHgjrI+SAfSw:d6vRBDlC6ZABve137kjTXJrJPV
Yara None matched
VirusTotal Search for analysis
Name 40e1947edb63ad36_favorite.vej
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Favorite.Vej
Size 23.9KB
Processes 2648 (wlanext.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 4d09f2e611c0a5ff3ea87a77de607dcd
SHA1 e31f751fe883196dc92359a56047b6d3409b08be
SHA256 40e1947edb63ad3607b900d8da7e46e30c1746735f2fc2eec342532934378948
CRC32 D751AD43
ssdeep 384:3Wc5ZAoiSNSvFY43XOHk23Yn5jyVvEBeB7CIp0uTQsBu:N/tNSNYg+ZY1yVvBBxp0u0+u
Yara None matched
VirusTotal Search for analysis
Name d3f7058756dda969_cardiogramme.kru
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Cardiogramme.Kru
Size 428.9KB
Processes 2648 (wlanext.exe)
Type data
MD5 c3b65d23cd7e7904570742d6dae09d85
SHA1 94b1d90e2a258e289ffe7772cca275c063f2d474
SHA256 d3f7058756dda96964da41ba1fd4ca6696e19e9a6b60c8d35cf5f8414dd43a91
CRC32 75EA7F88
ssdeep 12288:vRpXrv/Zpba6Czb5eFiqs0XF5zsL6ZFAN:5ZrvBduzb8hs5L67A
Yara None matched
VirusTotal Search for analysis
Name 7ac485e9ba85562d_lydisolere.qat
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Acerae\Threap\lydisolere.qat
Size 278.5KB
Processes 2648 (wlanext.exe)
Type data
MD5 4f34accc2a3849ee31a8c90b0a5e816f
SHA1 1ab0fcb8c30d0aab74ff68591e7a8ea2377a2332
SHA256 7ac485e9ba85562dfa0082dec66937142fe3399886a722e097975d83e2100308
CRC32 D59D108A
ssdeep 768:yLEO5/wuWDo8ZmeZZyswV+Dv1PRyyuV3NcbZwmmGRRYC2/4AmTxuBselmUNq+rG/:kEO8ddCYjG0BVboVlv0OxmYQyb3
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nshFA7D.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nshFA7D.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name b6f5ad6409c9f76c_amaryllisens.plu
Submit file
Filepath C:\Users\test22\AppData\Local\preoppression\Kleres81\Acerae\Threap\amaryllisens.plu
Size 172.4KB
Processes 2648 (wlanext.exe)
Type data
MD5 6b735c5a0a795a943298f4702b09824a
SHA1 44a4fea25ada078596212fac0f3a024a42c747ca
SHA256 b6f5ad6409c9f76c99160b41c14e02679acd8d4a447d8cb2418d1fe0f58e2854
CRC32 9D7DE202
ssdeep 768:3Hk+cAGq/ga4ZwJD5hw1Dhfxrwxiuq/wkec8VmJlPkrnlrODG7qwztuS:3h0wqqizHGckVD
Yara None matched
VirusTotal Search for analysis