Dropped Files | ZeroBOX
Name 4f76cd6ec7222833_loader.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\mr3660875\loader.exe
Size 6.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7b91d2784eaef8f79e4d60c1c1145d8b
SHA1 328224b6fc4789054c16f71172c8dd4d85a3be8b
SHA256 4f76cd6ec7222833969dcad5f71ab7cbddfd3714bc9adda334413c66c2826209
CRC32 B3109D8E
ssdeep 98304:zuwg7O8YO6xtedsiMV6oaNIwkmTFfYURRHbry7/bGaas3RW1PfR/yxkBfPy8Sh:ARdsiAkJQi/y7yzs3RWVfJyxafp
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 1550fbc51c842e8f_2786e7e2
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2786e7e2
Size 1.8MB
Processes 2556 (hola.exe)
Type PNG image data, 4176 x 603, 8-bit/color RGB, non-interlaced
MD5 2094ddc2476788a39de6be04d3420c25
SHA1 cd76e5863f694f2d9f2c4dd2491dbd9de3989b18
SHA256 1550fbc51c842e8fe98e7f7046bd1672c5fa5f46807228d4cc457331e4e56a86
CRC32 29479F9F
ssdeep 49152:VBeJna4he7j96GUc0LniSGDa2awjmoqY0X9KF9wkZUrfFjdkJ:DedsiMV6oaNIwkmTFw
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis