Dropped Files | ZeroBOX
Name 6b0f20de49a284a4_ad.trace
Submit file
Filepath C:\Users\test22\AppData\Roaming\AnyDesk\ad.trace
Size 34.4KB
Processes 2536 (AnyDesk_setup.exe) 2684 (AnyDesk_setup.exe) 2720 (AnyDesk_setup.exe)
Type ASCII text, with CRLF line terminators
MD5 a953834acaf6c5ccc2dfcc7630469579
SHA1 00474233587e74911f7953894050254924ffe1da
SHA256 6b0f20de49a284a4354b03114b613cb902ea52189981ce05e5c466280e34d520
CRC32 66B7AA2F
ssdeep 384:E+h2tMbhqyUCu6th20K5CLHpNG0RCeFEiK085wkBvK5n:E+wNA20tHnhChD085wkUn
Yara None matched
VirusTotal Search for analysis
Name 593be786a63f1788_user.conf
Submit file
Filepath C:\Users\test22\AppData\Roaming\AnyDesk\user.conf
Size 1.9KB
Processes 2536 (AnyDesk_setup.exe) 2720 (AnyDesk_setup.exe)
Type ASCII text, with very long lines
MD5 a273b7c922ff9f5425c8bc39537eec0d
SHA1 af2208e32394e59d247a8da84969fb1dccddbaab
SHA256 593be786a63f17885157041409292f8488d45995b5b94fc5f32aa9d7d04280d0
CRC32 F1A00D27
ssdeep 48:2fdDd25Zhfjbnn90186Xa2enQN7H2PnJagp3lOLc8gMl:21Z27h7zn48nnUSPnE
Yara None matched
VirusTotal Search for analysis
Name b6504458071189dd_service.conf
Submit file
Filepath C:\Users\test22\AppData\Roaming\AnyDesk\service.conf
Size 2.7KB
Processes 2684 (AnyDesk_setup.exe)
Type ASCII text, with very long lines
MD5 80dd0f157d0e0580bc1d231ca23f64a5
SHA1 b9b03067dc6bf429ca553c36528e8f064dca83f2
SHA256 b6504458071189ddd0b1378e21b0c98b3f6ef87849c9c3ec0d0cf34c5c738434
CRC32 2A6EC05F
ssdeep 48:uISTmwQifyR32aHPg28G8PTejN1uHGlog0yNDVRJS4kNh9GZHfoWVLq+HtvMEfjY:uISTm5ig32aHPgKuep1WGlog0yNDV3Sv
Yara None matched
VirusTotal Search for analysis
Name a8495dd308497df4_system.conf
Submit file
Filepath C:\Users\test22\AppData\Roaming\AnyDesk\system.conf
Size 424.0B
Processes 2684 (AnyDesk_setup.exe)
Type ASCII text
MD5 844d8c4a396f31e79f4cf4d9a4587a5e
SHA1 bbf6d5ee833ee820cf45cbfc0bf575b934ce4e9a
SHA256 a8495dd308497df4f67296b9ed43855a64bd9e7b0c725f4b7d6ac248c4354b13
CRC32 D0E1484D
ssdeep 6:owXCjHOJG/E+aqQAmvbahOmQgRQUQgRQPYQgRQOYQgfxPZxi3B6QgfxPg3qg3B6N:oxjHO8/E/qQHvWhOLroBGgFBGt
Yara None matched
VirusTotal Search for analysis
Name 89cc5b62b5688a2a_75fdacd8330bac18.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\75fdacd8330bac18.customdestinations-ms
Size 3.6KB
Processes 2536 (AnyDesk_setup.exe)
Type data
MD5 348bd142277e58874816214e159443ad
SHA1 f55b3dbe80af0e966a1f54d319bf3fd094b38a15
SHA256 89cc5b62b5688a2a007c19d809a66ad911d7afd5777b09fc771aaefe2ca6d665
CRC32 89F63C4D
ssdeep 48:QWsHlRjTll1ZMjpRFxQLbMDZrqbM1lWsHlRjTll1ZMjpRwbMDZrqbMsG:wrjhl1ZAxonqrjhl1Znn+
Yara None matched
VirusTotal Search for analysis