Dropped Files | ZeroBOX
Name 160b42939b56c426_mscorsvw.exe
Submit file
Filepath C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe
Size 20.0MB
Processes 3020 (wmi.jpg.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 30f6e7382394f1fe2342acb0afdb0203
SHA1 78659b6e4b2a0aed1bf95b46c25faaaf2abdb903
SHA256 160b42939b56c426ec55ac54b9da9d01b01b19277744892b7ae9361c0fb41c9b
CRC32 C0132C5C
ssdeep 49152:DHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHK:m
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis