Dropped Files | ZeroBOX
Name b72e9013a6204e9f_StdUtils.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nswFB97.tmp\StdUtils.dll
Size 100.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c6a6e03f77c313b267498515488c5740
SHA1 3d49fc2784b9450962ed6b82b46e9c3c957d7c15
SHA256 b72e9013a6204e9f01076dc38dabbf30870d44dfc66962adbf73619d4331601e
CRC32 9B0322B4
ssdeep 3072:WNuZmJ9TDP3ahD2TF7Rq9cJNPhF9vyHf:WNuZ81zaAFHhF9v
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b0d38869275d9d29_sk.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\sk.pak
Size 416.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 b7e97cc98b104053e5f1d6a671c703b7
SHA1 0f7293f1744ae2cd858eb3431ee016641478ae7d
SHA256 b0d38869275d9d295e42b0b90d0177e0ca56a393874e4bb454439b8ce25d686f
CRC32 9BB20C96
ssdeep 6144:M43lA0ct/muNypigJ4BOn5aHSL9aQCqoLWGL:91cgsypipBI5aHSL9aQCDLd
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 10e65f42ce01ba19_it.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\it.pak
Size 388.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 745f16ca860ee751f70517c299c4ab0e
SHA1 54d933ad839c961dd63a47c92a5b935eef208119
SHA256 10e65f42ce01ba19ebf4b074e8b2456213234482eadf443dfad6105faf6cde4c
CRC32 3B044047
ssdeep 6144:n9BKi2azctogSrqRrhsO11GT9TeLAG3XRU2gY7OfLwH+WcMgB8HryeuRNBPJX9SO:n9FTnzZY28+2vx+0e55zoI
Yara None matched
VirusTotal Search for analysis
Name e11e8db78ae12f8d_en-GB.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\en-GB.pak
Size 324.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 825ed4c70c942939ffb94e77a4593903
SHA1 7a3faee9bf4c915b0f116cb90cec961dda770468
SHA256 e11e8db78ae12f8d735632ba9fd078ec66c83529cb1fd86a31ab401f6f833c16
CRC32 5C9DFB43
ssdeep 6144:k6QL0f35ubiwMP9egutWbfaYX2YBB5HXSdBruC:6LduwMetW92M53SuC
Yara None matched
VirusTotal Search for analysis
Name 4f44789a2c38edc3_nb.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\nb.pak
Size 359.0KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 55d5ad4eacb12824cfcd89470664c856
SHA1 f893c00d8d4fdb2f3e7a74a8be823e5e8f0cd673
SHA256 4f44789a2c38edc396a31aba5cc09d20fb84cd1e06f70c49f0664289c33cd261
CRC32 5E2A0DA5
ssdeep 6144:TAJxNH0uqnIhgFYMqOp7fwcbgtmX07Sgzuu5Dn4XYnOGrr:ExdfqnPFYMqOp7fwcwSgB5Dn4LGrr
Yara None matched
VirusTotal Search for analysis
Name 9cfd5d29cde3de2f_resources.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\resources.pak
Size 5.2MB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 7971a016aed2fb453c87eb1b8e3f5eb2
SHA1 92b91e352be8209fadcf081134334dea147e23b8
SHA256 9cfd5d29cde3de2f042e5e1da629743a7c95c1211e1b0b001e4eebc0f0741e06
CRC32 581DE23C
ssdeep 98304:/Zgm9tHEEIcjWbEvKfwa2sEJFz993CNh1QeHQF5qrwrw5z0uxRRrY2kuDYj9ds:RgAtkEx4EKfatyNhHwFkkrw5IcRRtkFs
Yara None matched
VirusTotal Search for analysis
Name b393f05e8ff919ef_nsis7z.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nswFB97.tmp\nsis7z.dll
Size 424.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 80e44ce4895304c6a3a831310fbf8cd0
SHA1 36bd49ae21c460be5753a904b4501f1abca53508
SHA256 b393f05e8ff919ef071181050e1873c9a776e1a0ae8329aefff7007d0cadf592
CRC32 DB6CC985
ssdeep 6144:aUWQQ5O3fz0NG3ucDaEUTWfk+ZA0NrCL/k+uyoyBOX1okfW7w+Pfzqibckl:an5QEG39fPAkrE4yrBOXDfaNbck
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d8da7ab28992c829_da.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\da.pak
Size 371.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 e7ba94c827c2b04e925a76cb5bdd262c
SHA1 abba6c7fcec8b6c396a6374331993c8502c80f91
SHA256 d8da7ab28992c8299484bc116641e19b448c20adf6a8b187383e2dba5cd29a0b
CRC32 7D6A4B80
ssdeep 6144:czP4qlrn8+ua0swlGVJJwoXlw5CvET5VTrBGzO7iJyd4tTWwT:dqlr89JklwH55rETL
Yara None matched
VirusTotal Search for analysis
Name fa1e44215bd5acc7_am.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\am.pak
Size 569.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 2c933f084d960f8094e24bee73fa826c
SHA1 91dfddc2cff764275872149d454a8397a1a20ab1
SHA256 fa1e44215bd5acc7342c431a3b1fddb6e8b6b02220b4599167f7d77a29f54450
CRC32 2F52620C
ssdeep 12288:QqhqEuPxT8xZTtWosuF9Q5m9yAAVzfukCQox30jH8+I:Zh8T8xTWoZF9Q5m9yAAVzXCQ0
Yara None matched
VirusTotal Search for analysis
Name b59f932df822ab1a_hu.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\hu.pak
Size 427.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 2aa0a175df21583a68176742400c6508
SHA1 3c25ba31c2b698e0c88e7d01b2cc241f0916e79a
SHA256 b59f932df822ab1a87e8aab4bbb7c549db15899f259f4c50ae28f8d8c7ce1e72
CRC32 E142B6E9
ssdeep 6144:wxEAuskhSSfm4Cky1tV5z8iZfGRzEY63aQSam7gXOeeeQi5gR7azQtGV52n5ydpS:wxLaj6V5z850+7BwQi5Rn6Z
Yara None matched
VirusTotal Search for analysis
Name 1d20e626444759c2_en-US.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\en-US.pak
Size 326.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 19d18f8181a4201d542c7195b1e9ff81
SHA1 7debd3cf27bbe200c6a90b34adacb7394cb5929c
SHA256 1d20e626444759c2b72aa6e998f14a032408d2b32f957c12ec3abd52831338fb
CRC32 3AC6F19F
ssdeep 6144:Mvneu710gxhmrunGeuMP9eczCPMfaYbg3In5N+Sqn8BcwS:Ml0gxvNuMbCPmgA5YSNcwS
Yara None matched
VirusTotal Search for analysis
Name cce1edc1ab6eef10_app-64.7z
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nswFB97.tmp\app-64.7z
Size 65.7MB
Processes 2652 (DamnedSetup.exe)
Type 7-zip archive data, version 0.4
MD5 27eb44e90a2a7ed5b46196de49af6549
SHA1 14acae37f54d8490a8a6074294dd73d9f182dc32
SHA256 cce1edc1ab6eef1094ab27d5f330edc8af771a72c1cd9e50e154377ffb8baa13
CRC32 8C0A62CD
ssdeep 1572864:0rziNx5qXrDG0d5fLbPyfQPnHr06KTvReI8KKy0viUv:fx5qXrb5fLfwrTEDHpv
Yara None matched
VirusTotal Search for analysis
Name 9fcda0d1fab7fff7_ru.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ru.pak
Size 657.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 2885bde990ee3b30f2c54a4067421b68
SHA1 ae16c4d534b120fdd68d33c091a0ec89fd58793f
SHA256 9fcda0d1fab7fff7e2f27980de8d94ff31e14287f58bd5d35929de5dd9cbcdca
CRC32 0CA4F00C
ssdeep 12288:xkFzEroY5eXN2hHO3j/jHXzvMBJJWkKce8P/XzFGGJn/aZ/LNUFC0WGWajfG1UpM:xUQMi5y6d4
Yara None matched
VirusTotal Search for analysis
Name 7fd715914e3b0cf2_id.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\id.pak
Size 350.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 b6fcd5160a3a1ae1f65b0540347a13f2
SHA1 4cf37346318efb67908bba7380dbad30229c4d3d
SHA256 7fd715914e3b0cf2048d4429f3236e0660d5bd5e61623c8fef9b8e474c2ac313
CRC32 9F31E616
ssdeep 6144:UINLZJl/dv1DR9S2fjDVnjHFfRmP2x1r856Rh1vtTtSLsEar:Nf7PDuAVnjHFpm+xh856RhP
Yara None matched
VirusTotal Search for analysis
Name 2caa1da9b6a6e87b_chrome_100_percent.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\chrome_100_percent.pak
Size 126.7KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 8626e1d68e87f86c5b4dabdf66591913
SHA1 4cd7b0ac0d3f72587708064a7b0a3beca3f7b81c
SHA256 2caa1da9b6a6e87bdb673977fee5dd771591a1b6ed5d3c5f14b024130a5d1a59
CRC32 34FB400B
ssdeep 3072:AEKzwqCT4weSxQCS/qGTL2o418Gb0+VRLf0ld0GY3cQ39Vm2I:AEKzwt4hC4/rK18Gb0OV8ld0GecQ3f2
Yara None matched
VirusTotal Search for analysis
Name ee1e014550b85e3d_pt-PT.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\pt-PT.pak
Size 391.0KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 b4954b064e3f6a9ba546dda5fa625927
SHA1 584686c6026518932991f7de611e2266d8523f9d
SHA256 ee1e014550b85e3d18fb5128984a713d9f6de2258001b50ddd18391e7307b4a1
CRC32 DB27DBE8
ssdeep 6144:dqPhA4zslBWfIw2ieJVJJxhmOcXLFIUK5IKM4RV6X:EJolB/2bfK5IKM4RG
Yara None matched
VirusTotal Search for analysis
Name de92f14480770401_cs.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\cs.pak
Size 410.0KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 eeee212072ea6589660c9eb216855318
SHA1 d50f9e6ca528725ced8ac186072174b99b48ea05
SHA256 de92f14480770401e39e22dcf3dd36de5ad3ed22e44584c31c37cd99e71c4a43
CRC32 27BC775E
ssdeep 6144:RquUIAMYOnQYeAIV4g558YwGKNDsku8Qy:Rq/IA5On504g558YwbNDsC
Yara None matched
VirusTotal Search for analysis
Name 898621731ac3471a_bg.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\bg.pak
Size 652.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 38bcabb6a0072b3a5f8b86b693eb545d
SHA1 d36c8549fe0f69d05ffdaffa427d3ddf68dd6d89
SHA256 898621731ac3471a41f8b3a7bf52e7f776e8928652b37154bc7c1299f1fd92e1
CRC32 F6C663FA
ssdeep 12288:MMq8w2kMLlYrdAs1aQUx41aVVwslMLOmFOMw35uKN31tfbDMxbV2Jfu64Kjz5fS+:MMqckulYrdAs1aQUmBsmRw35uK7Jgxho
Yara None matched
VirusTotal Search for analysis
Name 1ea245646a4b4386_bn.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\bn.pak
Size 838.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 9340520696e7cb3c2495a78893e50add
SHA1 eed5aeef46131e4c70cd578177c527b656d08586
SHA256 1ea245646a4b4386606f03c8a3916a3607e2adbbc88f000976be36db410a1e39
CRC32 38C30E2A
ssdeep 3072:6gGTLRFbMdhBVHvr5eSnC6PRWhk7Bbd8+D95H0XluZ:YWBlvr5FCYRWuBbdB5wl2
Yara None matched
VirusTotal Search for analysis
Name 15951767dafa7bdb_he.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\he.pak
Size 507.3KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 fc84ea7dc7b9408d1eea11beeb72b296
SHA1 de9118194952c2d9f614f8e0868fb273ddfac255
SHA256 15951767dafa7bdbedac803d842686820de9c6df478416f34c476209b19d2d8c
CRC32 BCA7F414
ssdeep 12288:iDIJk5rUp/mTLa2/ANNqOL607Af6XVjeQCapb1527oFpMbe54lmdADnwg5Qgx:7205KoM
Yara None matched
VirusTotal Search for analysis
Name b9ee861e1bdecffe_fa.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\fa.pak
Size 577.6KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 2e37fd4e23a1707a1eccea3264508dff
SHA1 e00e58ed06584b19b18e9d28b1d52dbfc36d70f3
SHA256 b9ee861e1bdecffe6a197067905279ea77c180844a793f882c42f2b70541e25e
CRC32 F6A107E0
ssdeep 12288:HniDys0XVX9nuyaXTfwIDwNUWGOGfStQvjy1feKtDmrwMTAKzIxRAQiHedNu36Xp:HneM3uyaXTfwewNUWGOGfStQvjy1feKn
Yara None matched
VirusTotal Search for analysis
Name e32e37ca0ab30f18_th.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\th.pak
Size 753.4KB
Processes 1452 (explorer.exe) 2652 (DamnedSetup.exe)
Type data
MD5 a32ba63feeed9b91f6d6800b51e5aeae
SHA1 2fbf6783996e8315a4fb94b7d859564350ee5918
SHA256 e32e37ca0ab30f1816fe6df37e3168e1022f1d3737c94f5472ab6600d97a45f6
CRC32 63285ABE
ssdeep 12288:5ZY31Mkgs3s5UvfZLRflsjj8FCG1LDoAGkEeuLAD57Kle9d8nyj9FR3o09XAyFHa:57yU5K54
Yara None matched
VirusTotal Search for analysis
Name a62b848a002474a8_ar.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ar.pak
Size 624.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 fdbad4c84ac66ee78a5c8dd16d259c43
SHA1 3ce3cd751bb947b19d004bd6916b67e8db5017ac
SHA256 a62b848a002474a8ea37891e148cbaf4af09bdba7dafebdc0770c9a9651f7e3b
CRC32 674B7322
ssdeep 12288:K+sgtqIj5/XvYUtOkQIkqBJ5SNbW+eTtvZEMgSENjM:KD4Fek75z+K
Yara None matched
VirusTotal Search for analysis
Name 1a5884bd6665b2f4_ko.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ko.pak
Size 398.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 d6194fc52e962534b360558061de2a25
SHA1 98ed833f8c4beac685e55317c452249579610ff8
SHA256 1a5884bd6665b2f404b7328de013522ee7c41130e57a53038fc991ec38290d21
CRC32 56B0424F
ssdeep 12288:Md9PhJeKVoCGet8Oh2J7klCqZ5T7BKI8LtCq7hUoqAX:Md91UJc5184AX
Yara None matched
VirusTotal Search for analysis
Name 7f85673cf80d1e80_es-419.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\es-419.pak
Size 395.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 7da3e8aa47ba35d014e1d2a32982a5bb
SHA1 8e35320b16305ad9f16cb0f4c881a89818cd75bb
SHA256 7f85673cf80d1e80acfc94fb7568a8c63de79a13a1bb6b9d825b7e9f338ef17c
CRC32 B77B6C98
ssdeep 3072:75rkwZKG5KJo0ZyFPK9zj4rMY4rjyujd8pyPWncpwwfNEOv553l50GLFddhRIHKj:t1K2YZIK9BYgapFGl5dLFddA7Fcp
Yara None matched
VirusTotal Search for analysis
Name be254bcda4dbe167_nl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\nl.pak
Size 370.6KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 0f04bac280035fab018f634bcb5f53ae
SHA1 4cad76eaecd924b12013e98c3a0e99b192be8936
SHA256 be254bcda4dbe167cb2e57402a4a0a814d591807c675302d2ce286013b40799b
CRC32 40136176
ssdeep 6144:KcJ9Smne7gqDO5EQHzpamU3D+qn7Cv5qPxOGpLMsLPW:Km9nCgqDO5ELrOv5qPxOGpLM+PW
Yara None matched
VirusTotal Search for analysis
Name ddabb225b671b989_vi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\vi.pak
Size 455.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 db0eb3183007de5aae10f934fffacc59
SHA1 e9ea7aeffe2b3f5cf75ab78630da342c6f8b7fd9
SHA256 ddabb225b671b989789e9c2ccd1b5a8f22141a7d9364d4e6ee9b8648305e7897
CRC32 FBEF0A66
ssdeep 12288:3CwEs5kAfnzs0ACmwSxXwzIJWl+58Qagi7+URTJziV53f:3qOFfnzs0AHwSGz5A5rri7+UtliV53f
Yara None matched
VirusTotal Search for analysis
Name adf8df051b55507e_zh-TW.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\zh-TW.pak
Size 330.2KB
Processes 1452 (explorer.exe) 2652 (DamnedSetup.exe)
Type data
MD5 2456bf42275f15e016689da166df9008
SHA1 70f7de47e585dfea3f5597b5bba1f436510decd7
SHA256 adf8df051b55507e5a79fa47ae88c7f38707d02dfac0cc4a3a7e8e17b58c6479
CRC32 58ED42FE
ssdeep 6144:zQmZEIQee2hZuwv+2440f5lHz8wMCM/9ylTN:cvIpn+2440f5lHzgT/C
Yara None matched
VirusTotal Search for analysis
Name 21d1d273124648a4_el.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\el.pak
Size 712.5KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 e66a75680f21ce281995f37099045714
SHA1 d553e80658ee1eea5b0912db1ecc4e27b0ed4790
SHA256 21d1d273124648a435674c7877a98110d997cf6992469c431fe502bbcc02641f
CRC32 960BFA10
ssdeep 12288:AQbueXYquNw2202pgtZBAujt4NIbsJvaP5A3HRsgQiEYQ3C1gf2ns4CfFnx1Xu2v:B2quNw2202pgtHAujmNrJvaRA3HRsDik
Yara None matched
VirusTotal Search for analysis
Name 9a981f4d6e9e0220_app.asar
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\resources\app.asar
Size 20.7MB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 198d7397b4710cab1fe002eedf61d2f0
SHA1 13de6c968a0f1099d5cafc43acaa592790fbd0be
SHA256 9a981f4d6e9e02203a3b8157e37afc4322231a243430f7f0e5174cc731405f99
CRC32 A0A1AB79
ssdeep 98304:BseUEGhCTOi8sQrZwwpxTbG9tIagImnkiold7GfbJLljZF+3J0gWuXYRM84am:BseUEpB91gImMMxlY3Cg51d
Yara
  • Malicious_Library_Zero - Malicious_Library
  • ftp_command - ftp command
  • Antivirus - Contains references to security software
  • Javascript_Blob - use blob(Binary Large Objec) javascript
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name f681844896c084d2_vulkan-1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\vulkan-1.dll
Size 899.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 0e4e0f481b261ea59f196e5076025f77
SHA1 c73c1f33b5b42e9d67d819226db69e60d2262d7b
SHA256 f681844896c084d2140ac210a974d8db099138fe75edb4df80e233d4b287196a
CRC32 9AF2AB16
ssdeep 24576:PR9nl1crwjLAQw6Z5WUDYsH56g3P0zAk7:PR1l1culw6Z5WUDYsH56g3P0zAk7
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d2107ba0f4e28e35_libEGL.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\libEGL.dll
Size 468.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 09134e6b407083baaedf9a8c0bce68f2
SHA1 8847344cceeab35c1cdf8637af9bd59671b4e97d
SHA256 d2107ba0f4e28e35b22837c3982e53784d15348795b399ad6292d0f727986577
CRC32 DC4FC2F9
ssdeep 12288:su0LAjbIkyVVR8O9v/6TiT5eU3axzvYwo:sub49/6TiQzvYX
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name a19e38dd1bf2ad48_Damned-x64.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\Damned-x64.exe
Size 128.0MB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 93cbff779b435776134710fb4223c089
SHA1 7caab498e6d0cd9082b71ce2c308b914aea9f992
SHA256 e377d402dbfb90b597fd7eb3e8a635841ff78d96656c010edf9335d550332b47
CRC32 D049D330
ssdeep 1572864:GCquurbtqKajQe7vqrTU4PrCsdCXrBngPE1cG7VOWe2IkBmUgq3Fd6iU3x6VCdbi:cDAgM
Yara
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • Obsidium_Zero - Obsidium protector file
VirusTotal Search for analysis
Name 052bcdb64a80e504_ta.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ta.pak
Size 964.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 18ec8ff3c0701a6a8c48f341d368bab5
SHA1 8bff8aee26b990cf739a29f83efdf883817e59d8
SHA256 052bcdb64a80e504bb6552b97881526795b64e0ab7ee5fc031f3edf87160dee9
CRC32 0A6FF382
ssdeep 3072:S3YCY5ynH4ASpuCkCxSiP84Gb/v5nB7zztROcA2P:SnVUdQO84Gb/v55zztROcA2P
Yara None matched
VirusTotal Search for analysis
Name 2593c8b59849fbc6_pl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\pl.pak
Size 412.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 f1d48a7dcd4880a27e39b7561b6eb0ab
SHA1 353c3ba213cd2e1f7423c6ba857a8d8be40d8302
SHA256 2593c8b59849fbc690cbd513f06685ea3292cd0187fcf6b9069cbf3c9b0e8a85
CRC32 C9DD6896
ssdeep 12288:roj98jy/jojSoM/Z+Xgv3iWhbhvPeCUdxUwVTmNF1Qhjhd5UR405Y:ryMV+1Qhb5IY
Yara None matched
VirusTotal Search for analysis
Name d39716633228a587_te.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\te.pak
Size 894.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 a17f16d7a038b0fa3a87d7b1b8095766
SHA1 b2f845e52b32c513e6565248f91901ab6874e117
SHA256 d39716633228a5872630522306f89af8585f8092779892087c3f1230d21a489e
CRC32 F21CBD44
ssdeep 12288:iy/yX8OsABW3p1F9SviTlwJAg5NFO1Tr/p54JAQvfEC28+58XoX0DTq9OyU+0Ak1:vu8OkDY5YMZb
Yara None matched
VirusTotal Search for analysis
Name f11576bf7ffbc366_ffmpeg.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\ffmpeg.dll
Size 2.7MB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 d49e7a8f096ad4722bd0f6963e0efc08
SHA1 6835f12391023c0c7e3c8cc37b0496e3a93a5985
SHA256 f11576bf7ffbc3669d1a5364378f35a1ed0811b7831528b6c4c55b0cdc7dc014
CRC32 29D43C76
ssdeep 49152:XMoI7Qj3trgDtcfkW76fSL5Yqq6uthy4Y6NO8PyJegPTagrcjdiCOi2iNN3lzl3U:H3Kk76fUq/4TagreBOirnW
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 0ad547bb1dc57907_af.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\af.pak
Size 353.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 464e5eeaba5eff8bc93995ba2cb2d73f
SHA1 3b216e0c5246c874ad0ad7d3e1636384dad2255d
SHA256 0ad547bb1dc57907adeb02e1be3017cce78f6e60b8b39395fe0e8b62285797a1
CRC32 729AE7F8
ssdeep 6144:j54QCpN9/WiHIR9a5D4+kQMGSB+jC6kAw1TUKKpg3b9xIsVxSt2y5qP3ux5tPwDV:F9CpN9OiHIRX+HMT+jC6kAw1TYpg3b9P
Yara None matched
VirusTotal Search for analysis
Name 23058c0f71d9e40f_mr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\mr.pak
Size 797.5KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 2cf9f07ddf7a3a70a48e8b524a5aed43
SHA1 974c1a01f651092f78d2d20553c3462267ddf4e9
SHA256 23058c0f71d9e40f927775d980524d866f70322e0ef215aa5748c239707451e7
CRC32 D2FAD0B2
ssdeep 3072:ZE7bv9/9xAvtACKjxUp0djbOXspvibMFFPMUh3RQR3KB+5lx14/H4bmHwMaZ0t4k:ZE7b1fOACsxZjAEV6yZ00VbJ5JgezP5
Yara None matched
VirusTotal Search for analysis
Name 6655fd9dcdfaf2ab_zh-CN.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\zh-CN.pak
Size 332.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 82326e465e3015c64ca1db77dc6a56bc
SHA1 e8abe12a8dd2cc741b9637fa8f0e646043bbfe3d
SHA256 6655fd9dcdfaf2abf814ffb6c524d67495aed4d923a69924c65abeab30bc74fb
CRC32 B9188F63
ssdeep 6144:fmLpS8IeOL27M807pnCKjEWkE0G5xNlEPeVplD:fmLQmK2I1nCKjEjG5xNlEPe
Yara None matched
VirusTotal Search for analysis
Name 3941364d0278e2c4_ur.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ur.pak
Size 571.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 1ca4fa13bd0089d65da7cd2376feb4c6
SHA1 b1ba777e635d78d1e98e43e82d0f7a3dd7e97f9c
SHA256 3941364d0278e2c4d686faa4a135d16a457b4bc98c5a08e62aa12f3adc09aa7f
CRC32 B4127F48
ssdeep 12288:UA3OsGF8Pz0WEJytlkA+7Z5QzUExbW7DQQYrhu6co/9NjjFpvJK:UAe3A85oWB
Yara None matched
VirusTotal Search for analysis
Name 41dfb772ae4c6f9e_sw.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\sw.pak
Size 379.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 67a443a5c2eaad32625edb5f8deb7852
SHA1 a6137841e8e7736c5ede1d0dc0ce3a44dc41013f
SHA256 41dfb772ae4c6f9e879bf7b4fa776b2877a2f8740fa747031b3d6f57f34d81dd
CRC32 A4A0438D
ssdeep 6144:24pV6wBz58kN6vhq//3UZFBIzDWs8ADjLKrYNguA/h5aS0DwV+ChZYeeq0e1k4H5:24bVd5B/3U/BLs8kMKguA/h5N1hZY+0u
Yara None matched
VirusTotal Search for analysis
Name 4df972b7f6d81aa7_hr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\hr.pak
Size 397.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 255f808210dbf995446d10ff436e0946
SHA1 1785d3293595f0b13648fb28aec6936c48ea3111
SHA256 4df972b7f6d81aa7bdc39e2441310a37f746ae5015146b4e434a878d1244375b
CRC32 1A916F5F
ssdeep 3072:z9mYpq0ZkIEZgVRTJ3MOS+WG0uPXbG4TT6WI6DkYAiKbeM/wXbnWNjdmvW0IEifp:zTEgNmW/5tE7IDjG
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 14a131ba318274cf_tr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\tr.pak
Size 385.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 5ff2e5c95067a339e3d6b8985156ec1f
SHA1 7525b25c7b07f54b63b6459a0d8c8c720bd8a398
SHA256 14a131ba318274cf10de533a19776db288f08a294cf7e564b7769fd41c7f2582
CRC32 318ACB5B
ssdeep 6144:xxl+G2KPlJi+kKD80GlTgAI7WTge95j/0+Vi1havX9vwiBrVmI:rlt2IlrRn57m5j/1
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name b1c7fb6909c8a416_hi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\hi.pak
Size 848.3KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 b5dfce8e3ba0aec2721cc1692b0ad698
SHA1 c5d6fa21a9ba3d526f3e998e3f627afb8d1eecf3
SHA256 b1c7fb6909c8a416b513d6de21eea0b5a6b13c7f0a94cabd0d9154b5834a5e8b
CRC32 F12658C6
ssdeep 3072:FugBVdK+X9c+XdfdkhSvf4QAEm5dmGrsUt3GR3GXO7NLdYnLsBPtv83ctKOf4z8d:cuVAsc+NZB5/5MNSD
Yara None matched
VirusTotal Search for analysis
Name 7fa148369c64bc59_es.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\es.pak
Size 394.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 04a9ba7316dc81766098e238a667de87
SHA1 24d7eb4388ecdfecada59c6a791c754181d114de
SHA256 7fa148369c64bc59c2832d617357879b095357fe970bab9e0042175c9ba7cb03
CRC32 BC3ED1E9
ssdeep 6144:/Q0DA42b4XUx+SCHgfUcp9Ch48BKjbu5mrj7o2oxjm6PZqJ:YK2b40P9pchXgjbu5mrroNSJ
Yara
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
VirusTotal Search for analysis
Name 340e0babe5fddbfd_sl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\sl.pak
Size 401.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 ca763e801de642e4d68510900ff6fabb
SHA1 c32a871831ce486514f621b3ab09387548ee1cff
SHA256 340e0babe5fddbfda601c747127251cf111dd7d79d0d6a5ec4e8443b835027de
CRC32 B56AC388
ssdeep 6144:tnerKYjnS4fhmi0i2iiBnnbANjbnPMum4ocyxPbPD/yu0zrVftjQLc35BdFPcNpU:lEjnSn1iHd35vtcqO+i/fz50qg
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 6632bd12f04a5385_pt-BR.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\pt-BR.pak
Size 389.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 8e931ffbded8933891fb27d2cca7f37d
SHA1 ab0a49b86079d3e0eb9b684ca36eb98d1d1fd473
SHA256 6632bd12f04a5385012b5cdebe8c0dad4a06750dc91c974264d8fe60e8b6951d
CRC32 D171A92C
ssdeep 6144:oNssFqCoNBXBL3sNA65VyS15LqJVlLUoR1peV:oNssFqIF5uJH4oR/g
Yara None matched
VirusTotal Search for analysis
Name db4a63fa0d5b2bab_fil.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\fil.pak
Size 410.0KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 d7df2ea381f37d6c92e4f18290c6ffe0
SHA1 7cacf08455aa7d68259fcba647ee3d9ae4c7c5e4
SHA256 db4a63fa0d5b2baba71d4ba0923caed540099db6b1d024a0d48c3be10c9eed5a
CRC32 78170774
ssdeep 6144:BnI+f5Qm2xaVyEDQftIK9bSNxeFXGvZ3Omy5GzmHYFAk1s8:C+f541e+b4xy5ym8
Yara None matched
VirusTotal Search for analysis
Name bd02966f6c6258b6_uk.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\uk.pak
Size 657.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 361a0e1f665b9082a457d36209b92a25
SHA1 3c89e1b70b51820bb6baa64365c64da6a9898e2f
SHA256 bd02966f6c6258b66eae7ff014710925e53fe26e8254d7db4e9147266025cc3a
CRC32 C6C27CF6
ssdeep 12288:Yoff7plonpyOKtPXiNcnZx75kB3IjE8EmLvLNiXEJq//GW:YoffaXMd59E7
Yara None matched
VirusTotal Search for analysis
Name 56efff228ee3e112_ca.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ca.pak
Size 400.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 4cd6b3a91669ddcfcc9eef9b679ab65c
SHA1 43c41cb00067de68d24f72e0f5c77d3b50b71f83
SHA256 56efff228ee3e112357d6121b2256a2c3acd718769c89413de82c9d4305459c6
CRC32 31027CF1
ssdeep 12288:bgoRVrijIs3cejEYBCqS4o3nbhjJSwHQliEwfwVEMXdLbpuQ16BtryBiGIle3nei:b3GQUwJAMNTCypxB5WMml
Yara None matched
VirusTotal Search for analysis
Name 9b1fbf0c11c520ae_elevate.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\resources\elevate.exe
Size 105.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 792b92c8ad13c46f27c7ced0810694df
SHA1 d8d449b92de20a57df722df46435ba4553ecc802
SHA256 9b1fbf0c11c520ae714af8aa9af12cfd48503eedecd7398d8992ee94d1b4dc37
CRC32 C908A44F
ssdeep 3072:1bLnrwQoRDtdMMgSXiFJWcIgUVCfRjV/GrWl:1PrwRhte1XsE1l
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 32d83ff113fef532_vk_swiftshader_icd.json
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\vk_swiftshader_icd.json
Size 106.0B
Processes 2652 (DamnedSetup.exe)
Type ASCII text, with no line terminators
MD5 8642dd3a87e2de6e991fae08458e302b
SHA1 9c06735c31cec00600fd763a92f8112d085bd12a
SHA256 32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
CRC32 596B3D49
ssdeep 3:YD96WyV18tzsmyXLVi1rTVWSCwW2TJHzeZ18rY:Y8WyV18tAZLVmCwXFiZ18rY
Yara None matched
VirusTotal Search for analysis
Name 66005bc01175a4f6_ml.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ml.pak
Size 974.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 1c81104ac2cbf7f7739af62eb77d20d5
SHA1 0f0d564f1860302f171356ea35b3a6306c051c10
SHA256 66005bc01175a4f6560d1e9768dbc72b46a4198f8e435250c8ebc232d2dac108
CRC32 84187D0D
ssdeep 12288:T6ALnHOE47/URV1BQMmWDcZubSAD7qcDs3eThx5D/7dZdO3cb:9Owoys3eT5D/79O3u
Yara None matched
VirusTotal Search for analysis
Name ab96a18177af9049_sr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\sr.pak
Size 616.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 c68c235d8e696c098cf66191e648196b
SHA1 5c967fbbd90403a755d6c4b2411e359884dc8317
SHA256 ab96a18177af90495e2e3c96292638a775aa75c1d210ca6a6c18fbc284cd815b
CRC32 87C0399E
ssdeep 12288:H0JfhK5lIRIS151RHexYzs+DN5W9xTvvWF37sQ/k/k/i:y5V9dN5Oxjn
Yara None matched
VirusTotal Search for analysis
Name 5154e165bd6c2cc0_LICENSE.electron.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\LICENSE.electron.txt
Size 1.1KB
Processes 2652 (DamnedSetup.exe)
Type ASCII text
MD5 4d42118d35941e0f664dddbd83f633c5
SHA1 2b21ec5f20fe961d15f2b58efb1368e66d202e5c
SHA256 5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
CRC32 3958EFAA
ssdeep 24:36DiJHxRHuyPP3GtIHw1Gg9QH+sUW8Ok4F+d1o36qjFD:36DiJzfPvGt7ICQH+sfIte36AFD
Yara None matched
VirusTotal Search for analysis
Name a1a9d84fd3af571a_lv.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\lv.pak
Size 427.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 a8cbd741a764f40b16afea275f240e7e
SHA1 317d30bbad8fd0c30de383998ea5be4eec0bb246
SHA256 a1a9d84fd3af571a57be8b1a9189d40b836808998e00ec9bd15557b83d0e3086
CRC32 582F125E
ssdeep 6144:TjewdtAe6tN4tVFHzmstt4Uoo3W3sb3F5hZanXnEv9AhraszLOAty6ls1V:RR/v4UVWwF5UEabns1V
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 0bfa9a636e722107_LICENSES.chromium.html
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\LICENSES.chromium.html
Size 6.5MB
Processes 2652 (DamnedSetup.exe)
Type HTML document, UTF-8 Unicode text, with very long lines
MD5 180f8acc70405077badc751453d13625
SHA1 35dc54acad60a98aeec47c7ade3e6a8c81f06883
SHA256 0bfa9a636e722107b6192ff35c365d963a54e1de8a09c8157680e8d0fbbfba1c
CRC32 8A0D4480
ssdeep 24576:d7rs5kjWSnB3lWNeUmf0f6W6M6q6A6r/HXpErpem:rovj
Yara None matched
VirusTotal Search for analysis
Name 7a34483e6272f9b8_kn.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\kn.pak
Size 938.4KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 caab4deb1c40507848f9610d849834cf
SHA1 1bc87ff70817ba1e1fdd1b5cb961213418680cbe
SHA256 7a34483e6272f9b8881f0f5a725b477540166561c75b9e7ab627815d4be1a8a4
CRC32 E14854C9
ssdeep 12288:P8nyRnHoS7yB/rt2o6i7u7b5frUb+7G+Vma:ti6X5jUA
Yara None matched
VirusTotal Search for analysis
Name 5653bc7b0e270156_d3dcompiler_47.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\d3dcompiler_47.dll
Size 4.7MB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 cb9807f6cf55ad799e920b7e0f97df99
SHA1 bb76012ded5acd103adad49436612d073d159b29
SHA256 5653bc7b0e2701561464ef36602ff6171c96bffe96e4c3597359cd7addcba88a
CRC32 D12CC069
ssdeep 49152:IuhjwXkKcimPVqB4faGCMhGNYYpQVTxx6k/ftO4w6FXKpOD21pLeXvZCoFwI8ccA:oy904wYbZCoOI85oyI
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 7cc213e2c9a2d2e2_de.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\de.pak
Size 397.1KB
Processes 1452 (explorer.exe) 2652 (DamnedSetup.exe)
Type data
MD5 cf22ec11a33be744a61f7de1a1e4514f
SHA1 73e84848c6d9f1a2abe62020eb8c6797e4c49b36
SHA256 7cc213e2c9a2d2e2e463083dd030b86da6bba545d5cee4c04df8f80f9a01a641
CRC32 598C2351
ssdeep 6144:V3JEmQ1hqVK+6aU8WUmzg3ELWzhqY305QgfXlIsCJd:V5t6sKXaK/LWy5POsCJd
Yara None matched
VirusTotal Search for analysis
Name d8fab5714dafecb8_ja.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ja.pak
Size 472.7KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 38cd3ef9b7dff9efbbe086fa39541333
SHA1 321ef69a298d2f9830c14140b0b3b0b50bd95cb0
SHA256 d8fab5714dafecb89b3e5fce4c4d75d2b72893e685e148e9b60f7c096e5b3337
CRC32 81BABE5B
ssdeep 3072:fznG4qRo+yixrD1r04XURrRpZd2hy/NPNQPkwRI6dIKhUNH7bbeCsy5SWbaabF/G:fzGBRo+911WlRpZd2yNp6k5AYxVk
Yara None matched
VirusTotal Search for analysis
Name 7c8c7b05d7014512_icudtl.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\icudtl.dat
Size 10.1MB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 adfd2a259608207f256aeadb48635645
SHA1 300bb0ae3d6b6514fb144788643d260b602ac6a4
SHA256 7c8c7b05d70145120b45ccb64bf75bee3c63ff213e3e64d092d500a96afb8050
CRC32 1DB88670
ssdeep 98304:ffPBQYOo+ddlymff2LfPQCvliXUxiG9Ha93Whla6ZENSs285:ffPBhORjfAHliXUxiG9Ha93Whla6ZEV7
Yara None matched
VirusTotal Search for analysis
Name 50c4dc73d69b6c01_libGLESv2.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\libGLESv2.dll
Size 7.2MB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 a5f1921e6dcde9eaf42e2ccc82b3d353
SHA1 1f6f4df99ae475acec4a7d3910badb26c15919d1
SHA256 50c4dc73d69b6c0189eab56d27470ee15f99bbbc12bfd87ebe9963a7f9ba404e
CRC32 848992B0
ssdeep 98304:BuT3g23jeZ/02YPuLaw5RoD1rfEQ3CPdOEabcgsOMdi:BuDPTwLap14QzEijsvi
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 3eb38ae99653a7db_System.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nswFB97.tmp\System.dll
Size 12.0KB
Processes 2652 (DamnedSetup.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0d7ad4f45dc6f5aa87f606d0331c6901
SHA1 48df0911f0484cbe2a8cdd5362140b63c41ee457
SHA256 3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
CRC32 D50C2CEF
ssdeep 192:1enY0LWelt70elWjvfstJcVtwtYbjnIOg5AaDnbC7ypXhtIj:18PJlt70esj0Mt9vn6ay6
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 2b7906f33bfbe8e9_ro.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ro.pak
Size 403.1KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 d2758f6adbaeea7cd5d95f4ad6dde954
SHA1 d7476db23d8b0e11bbabf6a59fde7609586bdc8a
SHA256 2b7906f33bfbe8e9968bcd65366e2e996cdf2f3e1a1fc56ad54baf261c66954c
CRC32 4B9C396F
ssdeep 6144:Lsg4/xnSFcFG1Y6vFEsif5QB0o1s21/oulzr:Lt7FcFG1Y6vesif5QKob/dr
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 1923e0edf1ef6935_fr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\fr.pak
Size 426.2KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 3ee48a860ecf45bafa63c9284dfd63e2
SHA1 1cb51d14964f4dced8dea883bf9c4b84a78f8eb6
SHA256 1923e0edf1ef6935a4a718e3e2fc9a0a541ea0b4f3b27553802308f9fd4fc807
CRC32 C1F954AA
ssdeep 12288:LKi1uIt6QuagV1ZzosmZ7MYnYV1S3Bb5MxlqE0wC5wZLljHnkH0oR5FEu64JGV7h:qVVQ515CF
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name c6471aee5f34f314_ms.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\ms.pak
Size 365.7KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 aee105366a1870b9d10f0f897e9295db
SHA1 eee9d789a8eeafe593ce77a7c554f92a26a2296f
SHA256 c6471aee5f34f31477d57f593b09cb1de87f5fd0f9b5e63d8bab4986cf10d939
CRC32 32459453
ssdeep 6144:DZ/AO2kUDrt2MBrIxFQJulcul5WkS/PSOW5soNY3MMyvek:DZ/ApkUDrt2MOxSIl51kP05RYcMA
Yara None matched
VirusTotal Search for analysis
Name 8a5d6e29833374e0_lt.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\lt.pak
Size 429.5KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 64b08ffc40a605fe74ecc24c3024ee3b
SHA1 516296e8a3114ddbf77601a11faf4326a47975ab
SHA256 8a5d6e29833374e0f74fd7070c1b20856cb6b42ed30d18a5f17e6c2e4a8d783e
CRC32 B18A34B1
ssdeep 6144:zXtEPi5jFX4VU4EzsnHIOBoU+1Qi7t5GkzvLdyaj+teJvxY2I96Su:CEmguHLBoUnU5TzvLWeJJG6Su
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e40ee4f24839f9e2_gu.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\gu.pak
Size 813.0KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 308619d65b677d99f48b74ccfe060567
SHA1 9f834df93fd48f4fb4ca30c4058e23288cf7d35e
SHA256 e40ee4f24839f9e20b48d057bf3216bc58542c2e27cb40b9d2f3f8a1ea5bfbb4
CRC32 1923DA20
ssdeep 3072:RqlNvTn1Pdm06M0ITsKMaWZKerbtsMhmksd4Mqz2sQmB51jvjsWnhAgfZw/g/I/f:RuN7n1VQFLFwsL5cqhgrA8
Yara None matched
VirusTotal Search for analysis
Name 07bee34e189fe9a8_chrome_200_percent.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\chrome_200_percent.pak
Size 175.8KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 48515d600258d60019c6b9c6421f79f6
SHA1 0ef0b44641d38327a360aa6954b3b6e5aab2af16
SHA256 07bee34e189fe9a8789aed78ea59ad41414b6e611e7d74da62f8e6ca36af01ce
CRC32 4A499A0A
ssdeep 3072:rDQYaEQN6AJPrSxQCS/qGTafR54x5GMR+F44ffbdZnYw9p4AbIVGYoDd+HxNK/r4:rDQYaNN68rC4/Ygx5GMRejnbdZnVE6YR
Yara None matched
VirusTotal Search for analysis
Name 2d337924139ffe77_fi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\fi.pak
Size 365.7KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 21e534869b90411b4f9ea9120ffb71c8
SHA1 cc91ffbd19157189e44172392b2752c5f73984c5
SHA256 2d337924139ffe77804d2742eda8e58d4e548e65349f827840368e43d567810b
CRC32 5BA35C80
ssdeep 6144:sMeOXrZx5SkDbhCwx+sk/bOE/BanTLLE5lJucHcEJ18OWUczfSUWcX1wR2:snAr15wRBaA5lJxHcEJ18OWUII2
Yara None matched
VirusTotal Search for analysis
Name 4de0f720c4167764_snapshot_blob.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\snapshot_blob.bin
Size 158.5KB
Processes 1452 (explorer.exe) 2652 (DamnedSetup.exe)
Type data
MD5 8fef5a96dbcc46887c3ff392cbdb1b48
SHA1 ed592d75222b7828b7b7aab97b83516f60772351
SHA256 4de0f720c416776423add7ada621da95d0d188d574f08e36e822ad10d85c3ece
CRC32 8B6CC4E2
ssdeep 1536:uebVb91USSzM+uCPNgswpzHD41OzB965pUB8/DR9BgyLMRPoq/rX4JHj/kMKE0YC:uTgsED41OV965LXMj4zF2Xl9B
Yara None matched
VirusTotal Search for analysis
Name d69489a723b304e3_et.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\et.pak
Size 356.9KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 ccc71f88984a7788c8d01add2252d019
SHA1 6a87752eac3044792a93599428f31d25debea369
SHA256 d69489a723b304e305cb1767e6c8da5d5d1d237e50f6ddc76e941dcb01684944
CRC32 934FC541
ssdeep 6144:U/RGRpph+2n4x6i05L9H4h+JbT/R/WiMMn5bjN43qcLQ6PQX:8R6pHnpcmzn5bjh
Yara None matched
VirusTotal Search for analysis
Name 6150a413ebe00f92_vk_swiftshader.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\vk_swiftshader.dll
Size 5.0MB
Processes 2652 (DamnedSetup.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 a0845e0774702da9550222ab1b4fded7
SHA1 65d5bd6c64090f0774fd0a4c9b215a868b48e19b
SHA256 6150a413ebe00f92f38737bdccf493d19921ef6329fcd48e53de9dbde4780810
CRC32 5F0BAA0A
ssdeep 49152:tG7ixZvPbWjIXTFy1RYQZHJvuZBiDTwgvsrt5/PXd0kpmaN+WUf4CvB25zT7RCAq:c7iDPqjvzO1Lhgf49zT7grg4
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d15b46bc9b5e3144_sv.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\locales\sv.pak
Size 361.7KB
Processes 1452 (explorer.exe) 2652 (DamnedSetup.exe)
Type data
MD5 272f8a8b517c7283eab83ba6993eea63
SHA1 ad4175331b948bd4f1f323a4938863472d9b700c
SHA256 d15b46bc9b5e31449b11251df19cd2ba4920c759bd6d4fa8ca93fd3361fdd968
CRC32 6F08D66D
ssdeep 6144:A3J7MHJrRRcAjowQx+ByxN6dn4bLXvu9M7SOVDE/xUDv6o5WI5ggbN:G7EHl9BdU5X5x
Yara None matched
VirusTotal Search for analysis
Name 43b58ca4057cf750_v8_context_snapshot.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2ekW28DriA2QSQ423cuVpx1UOPH\v8_context_snapshot.bin
Size 465.6KB
Processes 2652 (DamnedSetup.exe)
Type data
MD5 a373d83d4c43ba957693ad57172a251b
SHA1 8e0fdb714df2f4cb058beb46c06aa78f77e5ff86
SHA256 43b58ca4057cf75063d3b4a8e67aa9780d9a81d3a21f13c64b498be8b3ba6e0c
CRC32 A7D3F84E
ssdeep 3072:qqgtKzy7vqUSMd+5ZTR4ymbsLIniZiYIU+gTh3WOdvmttow2LyZDvooPmdZwmNgi:lgEzy2NTROsLftIU+gTQ4E2ro+dOmp
Yara
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nswFB96.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nswFB96.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis