Dropped Files | ZeroBOX
Name dacfaf5624e25339_mscorsvw.exe
Submit file
Filepath C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe
Size 20.0MB
Processes 2564 (wmi.jpg.exe) 2632 (netsh.exe) 2740 (netsh.exe) 2916 (netsh.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 09a2fe09dc328d0061c70b7355af4226
SHA1 615f8a9693e1b8843981c0e95895a9316cda2f64
SHA256 dacfaf5624e25339114f22694d69120621c779d091a93c38cf4ed71f4f64aa85
CRC32 A3EAFD65
ssdeep 49152:TOHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHq:Th
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis