Dropped Files | ZeroBOX
Name d6431d5645fffd05_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2368 (powershell.exe)
Type data
MD5 260d23ce04a8f8555a73b7d2dc15e911
SHA1 ebad746fb7de847c50f7502a44f6e35534733efd
SHA256 d6431d5645fffd05a23166d630253bc7ce8c099cf6e9c956f8ae5e1249ee8588
CRC32 11D6B213
ssdeep 96:ctuCeGCPDXBqvsqvJCwo5tuCeGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:ctvXo5tvbHnorrxQ
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e3b0c44298fc1c14_Oepwtyyypefw-wal
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\Oepwtyyypefw-wal
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name a9220271c0eb79e5_d93f411851d7c929.customDestinations-ms~RF1df93d9.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF1df93d9.TMP
Size 7.8KB
Type data
MD5 b0c9ff441742f3847ea27da9dee7f2cd
SHA1 c42a1eb32ba953a0ce5d8635caabf71b5b281495
SHA256 a9220271c0eb79e5750e0d0e62058ecac560e09cdf9e82ef61aeeabada5d48a4
CRC32 0BBCAB1A
ssdeep 96:RutuCOGCPDXBqvsqvJCwo+utuCOGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:UtvXoxtvbHnorrxQ
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 1c02730953829883_Rtfqeh
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Rtfqeh
Size 36.0KB
Processes 2632 (rundll32.exe)
Type data
MD5 18747fcb2508eeec79415b32f63f3654
SHA1 72a2fd22d7caa80127fe08e70ff1e7c75f74eb81
SHA256 1c0273095382988333e2f2b5ae487cea460737ed9be65cbad9c5de537f95bf75
CRC32 0660D54C
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name fd4c9fda9cd3f9ae_Oepwtyyypefw-shm
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Oepwtyyypefw-shm
Size 32.0KB
Type data
MD5 b7c14ec6110fa820ca6b65f5aec85911
SHA1 608eeb7488042453c9ca40f7e1398fc1a270f3f4
SHA256 fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
CRC32 DDC506B6
ssdeep 3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
Yara None matched
VirusTotal Search for analysis
Name 3a3ed164e42500a1_Oepwtyyypefw
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Oepwtyyypefw
Size 96.0KB
Processes 2632 (rundll32.exe)
Type data
MD5 0a9156c4e3c48ef827980639c4d1e263
SHA1 9f13a523321c66208e90d45f87fa0cd9b370e111
SHA256 3a3ed164e42500a1c5b2d0093f0a813d27dc50d038f330cc100a7e70ece2e6e4
CRC32 9B32EAFB
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name fa569e2360c540e6_Aayafrewteuas
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Aayafrewteuas
Size 80.0KB
Processes 2632 (rundll32.exe)
Type data
MD5 030a4f48dc8db0956add25994004e5ca
SHA1 d81c6afaf95fa3886685df4f9f7d93f4f403226c
SHA256 fa569e2360c540e6280e34a4627516770f1a5f34d81d35689334a99cc1013357
CRC32 A7A90A69
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 02b1c22346806178_Tfqtfy
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Tfqtfy
Size 40.0KB
Processes 2632 (rundll32.exe)
Type data
MD5 ab893875d697a3145af5eed5309bee26
SHA1 c90116149196cbf74ffb453ecb3b12945372ebfa
SHA256 02b1c2234680617802901a77eae606ad02e4ddb4282ccbc60061eac5b2d90bba
CRC32 2C2BB90A
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 28e9601193984d4c_twqeeseeyehpfi.tmp
Submit file
Filepath C:\ProgramData\Twqeeseeyehpfi.tmp
Size 9.3KB
Processes 2632 (rundll32.exe)
Type data
MD5 a65eab7c8809683a783ec2ec4565ce5f
SHA1 ffef8c1df8572cb5d293f96fd0d9b4959a8e6327
SHA256 28e9601193984d4c73690a3308f4fc7ed03f4d7f010be81aefa178ff9a937c03
CRC32 1AE6B95C
ssdeep 192:p/uBgLoL8yfIXDFD7J6o2DsKippmgGXsL9UAcQPCG+H:FuBgsghSDsdT+sx8OCGK
Yara None matched
VirusTotal Search for analysis
Name 3381de4ca9f3a477_Peudahte
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Peudahte
Size 192.0KB
Processes 2632 (rundll32.exe)
Type data
MD5 ef2e0d18474b2151ef5876b1e89c2f1d
SHA1 aef9802fcf76c67d695bc77322bae5400d3bbe82
SHA256 3381de4ca9f3a477f25989dfc8b744e7916046b7aa369f61a9a2f7dc0963ec9e
CRC32 B66B2FCB
ssdeep 3::
Yara None matched
VirusTotal Search for analysis