Dropped Files | ZeroBOX
Name 3314b6ea393e180c_zt1fbtn.on5l
Submit file
Filepath C:\ProgramData\zT1fbtn.oN5L
Size 258.0KB
Processes 2960 (certutil.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 537806c02659a12c5b21efa51b2322c1
SHA1 c90a00b80670da65da968e0503f41b433888b9d2
SHA256 3314b6ea393e180c20db52448ab6980343bc3ed623f7af91df60189fec637744
CRC32 C713E1F3
ssdeep 3072:pVd9uD8AuiLW12ucm9595SQFNazYDKhSPW7bQxOB0dnWBGs5W3nE0fv4JzAVLSB1:2gAuQW0gUQqzYDKhkWvBoer5yM1t/
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name f58a9905aad4d82a_system safety manager jd (general dynamics hr division ii).pdf
Submit file
Filepath C:\ProgramData\System Safety Manager JD (General Dynamics HR Division II).pdf
Size 105.7KB
Processes 2560 (wscript.exe)
Type PDF document, version 1.7
MD5 6e5d5a8d06452852f1ccbc9b6dbab3eb
SHA1 5dd9f817d184115d17da659f59641d0cac65db3d
SHA256 f58a9905aad4d82a89a787017f1a357309caa01e2da081d76671f3319c66aa74
CRC32 D9EC38F2
ssdeep 1536:yEPcwxz2CZrFrVx0kTTkvqmdbOnzI1qo/IxPzEQalusKYAHLIam8uxJ:7tnak/kvvd4LFxPOTKJH8amBf
Yara
  • PDF_Format_Z - PDF Format
VirusTotal Search for analysis
Name 7ee927529f7108d8_BrowserMetrics-63327DF3-A54.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-63327DF3-A54.pma
Size 8.0MB
Type data
MD5 2f83a72f095bc42146a77940353d776c
SHA1 7b525857dbae3b79cce3f836475604f46d60008a
SHA256 7ee927529f7108d85841c07e1d05bafa82cb7d5a9a0db3ad9cf804c5a7b1632e
CRC32 1A7C42BC
ssdeep 6144:H9LG+zeL7c/lhRgdTTEDtsHVdUXaHmVGKPFIrgHkjdr:t6bcF
Yara None matched
VirusTotal Search for analysis
Name f25bf03a594a33d8_BrowserMetrics-665DB962-A60.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-665DB962-A60.pma
Size 8.0MB
Type data
MD5 3ecd29974736bb7c289371680801116a
SHA1 83dde81a47ad86b20d478d181522c455cb2a72f8
SHA256 f25bf03a594a33d86ab21db0a1318059128f81e2b03cb60135f24efb5a268fc2
CRC32 92E5E26A
ssdeep 192:Bmh5KH1LepNNAfHkkqukLf4lNs9PggaQ1x:BmhqLyePxkLQuogaM
Yara None matched
VirusTotal Search for analysis
Name febd0b15df57385e_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2192 (powershell.exe)
Type data
MD5 4ac6fcaa41dd47b2e35239accca1b443
SHA1 312db50c2c725dc60d2a63e29a7d741cfcf685a8
SHA256 febd0b15df57385ecbf0ab2b7fa6a24ef9570904c26b9abe4626271d0f88b2bc
CRC32 BCD38317
ssdeep 96:gtuCcBGCPDXBqvsqvJCwodtuCcBGCPDXBqvsEHyqvJCworH47HwxulUVul:gtCgXodtCgbHnorjxg
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 5a3ec8851acd1bb6_CrashpadMetrics.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
Size 1.0MB
Type data
MD5 aea7ffdba870ea9d59d542f890fecc8c
SHA1 2efe83750eebdfacc148d376cc4edfdf8e5d2ac9
SHA256 5a3ec8851acd1bb62d270e9bdca9625da9f34df69ef39608bc2ce3de68960056
CRC32 CB7B9D10
ssdeep 12:bHiZXAVMMOKEKSCemJKlkQPdl/JG89Hy3aJ0oMFgigpCbUycIXuYJ05:bwQOMzBS+Mk0/JvWoMeigp1y5eYW
Yara None matched
VirusTotal Search for analysis
Name 3de74ed16510c59a_debug.log
Submit file
Filepath C:\Program Files (x86)\Google\Chrome\Application\debug.log
Size 272.0B
Processes 2768 (chrome.exe)
Type ASCII text
MD5 b700e86fd4542973726a465b4f65930e
SHA1 42f2285b54657e56f41da1228ce02814614f290e
SHA256 3de74ed16510c59a193745b40dc5d11e4fcb272b76bb0541879ea2d09be0de2b
CRC32 AB3A6919
ssdeep 6:qcUmSlNoqYli8cI8RU4LGGmm3V4v8T88cI8RU4LGGmm3V4vF:nyyqYli1pRU4LGBm3V6R1pRU4LGBm3VO
Yara None matched
VirusTotal Search for analysis
Name ff3aaedb6bba7313_metadata
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
Size 114.0B
Processes 2768 (chrome.exe)
Type data
MD5 314059def9ee6db6f99a303e29daa5ad
SHA1 2d1aa61dc84ddf7ddc2a22b199bc27b1fbeea1f2
SHA256 ff3aaedb6bba73134388e3bf79ba8da086690f643204253684002a26853ae3d3
CRC32 4BDFD51F
ssdeep 3:mTll+Xl2r2VlYlWlllVDlltlnllkTmD6RHcwkItUP9qlln:mTlEeAlYli/pllGmWRHcWy96n
Yara None matched
VirusTotal Search for analysis
Name 501f3f25e6bf1003_vjvr53p.yool
Submit file
Filepath C:\ProgramData\vjVr53p.yOOL
Size 344.0KB
Processes 2560 (wscript.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 ca99585a3560c9605d1635134acc0407
SHA1 77bd159501fba9388b8f642cd2c489bf6f8af2c9
SHA256 501f3f25e6bf1003bbd85a6603f74771b465d4d283fc99184f3304a424c2b42b
CRC32 20210648
ssdeep 6144:RC4do/kAzKwNtjCXjIhfGy5RKUGITN4LEPJ0aBJkAN//SxbbaarkZh:Bo/kAzKw32duRlJYaarkz
Yara
  • hide_executable_file - Hide executable file
VirusTotal Search for analysis
Name a48a8b27acc5e461_d93f411851d7c929.customDestinations-ms~RF1a65d9c.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF1a65d9c.TMP
Size 7.8KB
Processes 2700 (powershell.exe) 2192 (powershell.exe)
Type data
MD5 3a3ea040d33b35f7e07b44b2f8305b3e
SHA1 98d5e86e20a9a23022cadcc40ad8ef1b572811be
SHA256 a48a8b27acc5e46108848f71f20078951adc4c4b618a30fac3b43201580d1b3b
CRC32 98289B89
ssdeep 96:8tuCcBGCPDXBqvsqvJCwoxtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:8tCgXoxtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 49059f15c5e1c6e2_3b23ed6e-1f99-4b92-8a88-fe81391e447d.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\3b23ed6e-1f99-4b92-8a88-fe81391e447d.dmp
Size 906.3KB
Processes 2768 (chrome.exe)
Type Mini DuMP crash report, 10 streams, Mon Jun 3 12:39:09 2024, 0x0 type
MD5 2e021f87edb53ef6b2c402fa466499b0
SHA1 c459bffe4993d4bd29b9013637b0a75db1a0d15d
SHA256 49059f15c5e1c6e2c720e6969b99d7dd49bff504fc7776bcbf3b32380f185ea4
CRC32 D6B21EFA
ssdeep 3072:ifnvZ9NQDz3hoMhvTgu9yzF7TwDEP+NUz7ljXCrD/NDX4TInFiSuSVv/FzgfC+5q:89NQXHhvTqLKp+g/pX
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e3b0c44298fc1c14_cerFABB.tmp
Empty file or file not found
Filepath C:\Windows\cerFABB.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name d37fcb160d37cfdd_settings.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Size 40.0B
Processes 2656 (chrome.exe)
Type data
MD5 a3122d4670c51912628b97bdd6fffb80
SHA1 45d2e3060e09f46071125d6125983c81ae4970a1
SHA256 d37fcb160d37cfddefea794094044b7e588d44c4883c72ba0ef1503e5f9c7d59
CRC32 77809701
ssdeep 3:FkXD3WyqUm:+ix
Yara None matched
VirusTotal Search for analysis
Name 7a80f52ba429f6bf_zt1fbtn.on5lXinfo
Submit file
Filepath C:\ProgramData\zT1fbtn.oN5L:info
Size 4.5KB
Processes 2884 (regsvr32.exe)
Type data
MD5 fa9c2e458fdd4d4c94c7352dad16fca1
SHA1 c04b872d2d5c07f6fe000db8b00092cc22d68896
SHA256 7a80f52ba429f6bf3e5bbdeb504d59fcd2ae6eac2518cd59e2c30726312bac43
CRC32 A17E2C45
ssdeep 3:hlRqWReRASRYlAtUKlkALt/lEdl+Sli5l2GkRk15l3Bttc1:mR3e7KSAwn+SkyGkRkJxta1
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis