Dropped Files | ZeroBOX
Name 6e36cda60845bbe1_installc.bat
Submit file
Filepath C:\Program Files (x86)\GameServerClient\installc.bat
Size 238.0B
Processes 2568 (install_new.exe) 3056 (cmd.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 8b1a66e9898c6054903c6fb23d6c197c
SHA1 06a2131ac4cd1dcdd7999322e728445e732b265d
SHA256 6e36cda60845bbe139f6fa3eaaa71047bb117b74ac47d698bbc526ebf512d025
CRC32 31AEB30C
ssdeep 6:hAUHkejSPkpLc6hWjP1kEjYftkmEC3IviAjdaUykRFZgILY:7EUrp5hs2EsOmbSPRvs
Yara None matched
VirusTotal Search for analysis
Name 472232ca821b5c2e_gameservice.exe
Submit file
Filepath C:\Program Files (x86)\GameServerClient\GameService.exe
Size 288.0KB
Processes 2568 (install_new.exe)
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 d9ec6f3a3b2ac7cd5eef07bd86e3efbc
SHA1 e1908caab6f938404af85a7df0f80f877a4d9ee6
SHA256 472232ca821b5c2ef562ab07f53638bc2cc82eae84cea13fbe674d6022b6481c
CRC32 33C3919D
ssdeep 6144:4BULviqYnI3QA7JTXRnZSHL2GZbkG/TZgLgst2rDkXNBD:wqBlG/TZgUsxXNBD
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 6fb647a3af04d0bb_gameclient.exe
Submit file
Filepath C:\Program Files (x86)\GameServerClient\GameClient.exe
Size 2.5MB
Processes 2568 (install_new.exe)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 0fac9d21508e154127a9fd4b90a1ca39
SHA1 cb9df00888a37443e6b4f87daf74e591b4dc373a
SHA256 6fb647a3af04d0bb02d9925cf974c21be48512ee56eb3275be575dadd1a7aec0
CRC32 CFA5A0A3
ssdeep 49152:UpfKz89joh6mLPe3euyh+r/bI2+1VzZ9BRYvrn:x49EHvuw+rzr+179BRq
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name cfe5ca7465376b1f_7ZSfx000.cmd
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\7ZSfx000.cmd
Size 197.0B
Processes 2568 (install_new.exe) 2504 (cmd.exe)
Type ASCII text, with CRLF line terminators
MD5 393ba16b5ee6950cac75cbab72d5be81
SHA1 e6211c0fcb0af8af3026d1cbc54492b88306a238
SHA256 cfe5ca7465376b1fe8a62300f4f17fda12891f152aa9d4b9949e0d8bdebd8e65
CRC32 6F6CEAAB
ssdeep 6:mRoiomQpcLJ23fcJ0UMD2UmQpcLJ23fcJ0i0WiomQpcLJ23fS3:mRoROLMvOLM+LROLM8
Yara None matched
VirusTotal Search for analysis
Name 864f529a4618eec7_gameclientc.exe
Submit file
Filepath C:\Program Files (x86)\GameServerClient\GameClientC.exe
Size 13.2MB
Processes 2568 (install_new.exe)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 fc63d47dd6b9847ab82f4dd05ed7cb99
SHA1 cac41f14caaabef4d89d3311e2314a09f602e256
SHA256 864f529a4618eec7e5eff997c66dd5001c75beed21b587bcc492e944fb059a49
CRC32 B74A3184
ssdeep 393216:sF5v+w5bFpYbUYPYQ2x4bpQzelZq1tWQG5jOzEt6FDIfOtJvjZ5EE+m4Mem4ML5F:Pm4Mem4ML5NM5l15NM5lfm4Mem4ML5NO
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 4cd8586d09ba9e97_install_new.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\install_new.exe
Size 2.4MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ba7445dd6438c2097c1c5b2ce173c064
SHA1 24873c5c09152806caa71b6bb990ef0797e626ae
SHA256 4cd8586d09ba9e97b4e50bb2d9d1e671a50bfe79bcd29ebf851ae6defc8d1768
CRC32 DD5BB667
ssdeep 49152:zgwRBNhWLwbYdMsr37tl5oaSeaduub9vdcOMigvOQowQEJHQJPT5NuEj3uWNtiT:zgwRBNhmwbirt02q1r4PFJwJ1fjeWNk
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 5c4b3d2bbfc98237_install.bat
Submit file
Filepath C:\Program Files (x86)\GameServerClient\install.bat
Size 231.0B
Processes 2568 (install_new.exe) 2680 (cmd.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 b9ecefec035b92492661437972d20a33
SHA1 6d694ed7107919baa1da347784b2fb2378f25193
SHA256 5c4b3d2bbfc982378155656046dccd2fac16a5f8d2bbf23f5dbc6a6dc8ebfde8
CRC32 27E823B9
ssdeep 6:hAUHkaCpjSPkaJDQ6hWjP1kaQjYftkmECUNSiAjdaUykSZgm:7EaCJrajhs2aQsOmMSP2b
Yara None matched
VirusTotal Search for analysis