Dropped Files | ZeroBOX
Name b2f63c432e2ef499_licencekuwaitsudije.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwaitSudije.fr3
Size 111.7KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 b30fccf4c766d678cc49490276d8958c
SHA1 488a796814a70ee156db3fbc5fbfa5c3b8683070
SHA256 b2f63c432e2ef4991778d9457cff0758b51f4b13f7c2e0436886522f47bb1ce9
CRC32 89F68227
ssdeep 1536:yrwc6YYY4WrzRlbwhXEu8vqxATu6JRttg9BrxGKs:jVCCLFa
Yara None matched
VirusTotal Search for analysis
Name a1315f06a045e0b9_licencekuwait.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwait.fr3
Size 7.1KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 c386e76b7e52136f74e7fee28ef36529
SHA1 4319bc9d11da5f7115dcf815d0c66f556671ca52
SHA256 a1315f06a045e0b9835ff396bfaa31298882d0344c07e97c6d1ffaeaebdd5ee0
CRC32 7199236C
ssdeep 96:s7wbk6J933z8JCrs6fnjb/FV9dYowSloBBJx:733rrL33RChx
Yara None matched
VirusTotal Search for analysis
Name 773c11dcfd97fd75_database kuwait.bak
Submit file
Filepath c:\program files (x86)\kuwait ice hockey db\database kuwait.bak
Size 11.2MB
Processes 2720 (KuwaitSetupHockey.tmp) 2884 (DataBase Kuwait.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b6027fc15cb0e74dc1968cc286648516
SHA1 94b90b4e411cb6e6f008ce28130a2964f49417ac
SHA256 773c11dcfd97fd7502c36efa1fc2dd8e7d3a68f22206e3b4a9da5ca30dafb873
CRC32 5A62B4C4
ssdeep 196608:lJ2GpQtnOtGp5mLqGg/zD1K3GeLMSE623IDVlqUSu:9ee8/zD1EGeLMAVDV
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 69bfb5d817133afb_unins000.exe
Submit file
Filepath c:\program files (x86)\kuwait ice hockey db\unins000.exe
Size 2.5MB
Processes 2720 (KuwaitSetupHockey.tmp)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6233a332b6a00194e949385695945150
SHA1 51f80d129cc72b8ca269492668d05f4b8ac7aae8
SHA256 69bfb5d817133afb1c09a9fc40e706d747974de3068758b380be5d49328d5235
CRC32 9B851558
ssdeep 49152:hR/KpmZubPf2S8W2ILeWl+C1p9jWy5Snd0eigXN4DVo:v/jtYLP1Sy5E01DVo
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 57407c990405cef2_licencekuwaittreneri.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwaitTreneri.fr3
Size 120.4KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 cb1294ad250d5c42931d3c669b3b51f6
SHA1 d577d571db52dfc7e82780e4b393d3047e0d0882
SHA256 57407c990405cef242ef87a8280380847bad503c44dc04750ad679c15676a17f
CRC32 6F076118
ssdeep 1536:mLaFxZlYY4WrzRlbwhXEu8vqxATu6JRttg9BmPB06NnnvRtMkiD:oE2VCCLmPPnTo
Yara None matched
VirusTotal Search for analysis
Name 068f5e5bc0de7c4c_kuwait ice hockey db.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kuwait Ice Hockey DB.lnk
Size 1.1KB
Processes 2720 (KuwaitSetupHockey.tmp)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Jul 4 17:05:14 2024, mtime=Thu Jul 4 17:05:14 2024, atime=Sat Oct 9 00:22:48 2021, length=11781632, window=hide
MD5 9fd8bc3c333811fae668626a03789565
SHA1 2fee88fd0c246291635619574c2d4bf54e9d4fd9
SHA256 068f5e5bc0de7c4cec74325330efb689e66f6828d0a279f34d358b323ccb3198
CRC32 4F6FAEA7
ssdeep 24:8m2YyBdOEAosRlbAuacqKFAqfY2didZDKzdZqUPPytdN:8mhyBdORo8ZAlrNqfY/dZD2dZLnyp
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 86e1c021e7199690_licencekuwaitm.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwaitM.fr3
Size 171.4KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 c68721cab2a5e1f57fc9219f758f38a8
SHA1 9b2320f550f9b997a37824b14dbae80bf4a7d9b7
SHA256 86e1c021e719969099dda488e5c0e2bc46711069e5b4d199442dcdc444c005b2
CRC32 08CAF755
ssdeep 1536:IryVGAtuY1U5hhXBrmhh8hIXhnGgrA6zuj4QIjwBU78VKGo/1waKXQ7TQSzqvIxy:uJxBkGOtQSGXQABgjn9GP5e+9
Yara None matched
VirusTotal Search for analysis
Name 7da8b863d9db6bf1_KuwaitSetupHockey.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-70CNA.tmp\KuwaitSetupHockey.tmp
Size 2.5MB
Processes 2628 (KuwaitSetupHockey.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 656ac8a5f7d94898aca0506acaff40f5
SHA1 4bb836b01cb0bdca3ee39c2541109f76499918ac
SHA256 7da8b863d9db6bf1a94be017c302ca5e2116d0380c86ff4f05fc3f790c18f630
CRC32 ED040617
ssdeep 49152:JR/KpmZubPf2S8W2ILeWl+C1p9jWy5Snd0eigXN4DVO:3/jtYLP1Sy5E01DVO
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 9e4982a89352091c_licencekuwaitz.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwaitZ.fr3
Size 172.4KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 abad6379a8f3818d8c94e9c568003cab
SHA1 96f247e1463a326e77f93082933aa064a8047d9b
SHA256 9e4982a89352091c53f69c4956a59faf085e4594d6fd04f1d04b16c7bd349ce6
CRC32 437D1F89
ssdeep 1536:lrRXp0aZ90d9Y1U5hhXBrmhh8GEW7ew2GOLwyICXhXKVczcBsplv1Og7TQSzqvI8:HC/JxBnQCR6VFkUgABgjn9G+vBOH
Yara None matched
VirusTotal Search for analysis
Name d77e05f090d07934_database kuwait.exe
Submit file
Filepath C:\Program Files (x86)\Kuwait Ice Hockey DB\DataBase Kuwait.exe
Size 15.0MB
Processes 2884 (DataBase Kuwait.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a72bf1c59ec607ddfa33ac0a36dd6fe4
SHA1 c169b9714ad45faa76df08988bf9428d9938b0f9
SHA256 d77e05f090d07934d15b084490febcefd5dd0f5b93a2e975d80eb7abe20f6eef
CRC32 42573C28
ssdeep 196608:D+PeuP9ntI66OBa/IxZ8xqI06rIb5vDVp5M6B:D+2uLIj3AxZCFDYZDV
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Malicious_Packer_Zero - Malicious Packer
  • ftp_command - ftp command
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • Generic_Malware_Zero - Generic Malware
  • mzp_file_format - MZP(Delphi) file format
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 82d0e5ac4fa9ce33_licencekuwaitzapisnik.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\LicenceKuwaitZapisnik.fr3
Size 118.7KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 3c301a5a60fc84af409e4885cd22cb00
SHA1 fc9199ad9b0c5327b3e2b8fb99661b7129f9b95e
SHA256 82d0e5ac4fa9ce336f2c6e69ddc1f62cdccd8dbdeb658e360bd21df885de37d7
CRC32 BCFE8DD0
ssdeep 1536:graaFxZlYY4WrzRlbwhXEu8vqxATu6JRttg9BmPB06NnnvRtMkiC:HE2VCCLmPPnTr
Yara None matched
VirusTotal Search for analysis
Name 007342c6b9b956f4_libeay32.dll
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\libeay32.dll
Size 1.3MB
Processes 2544 (DataBase Kuwait.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 de484d5dafe3c1208da6e24af40e0a97
SHA1 3e27b636863fefd991c57e8f4657aded333292e1
SHA256 007342c6b9b956f416f556b4bd6f1077e25bd077cc4f4ac136e3fccb803746e3
CRC32 9FB7893B
ssdeep 24576:j3mX+KpPUqBeo0DN9d4gNIm0rsZBYddjpO3qJkBYEECY:oMaeZ74gNIm0rVdxpO3qKBZEC
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2d11228520402ef4_ssleay32.dll
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\ssleay32.dll
Size 330.0KB
Processes 2544 (DataBase Kuwait.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 284e004b654306f8db1a63cff0e73d91
SHA1 7caa9d45c1a3e2a41f7771e30d97d86f67b96b1b
SHA256 2d11228520402ef49443aadc5d0f02c9544a795a4afc89fb0434b3b81ebdd28c
CRC32 B090547D
ssdeep 6144:HZcUmTisWdw0HCXs2r84u5B//+AN7tpkKFsh1TW1Q4PQgu/7r2cEfXKrryAdH/8m:HZcUmGsWdw0HCXs2rdu5B/WAN7rkKFol
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 02e7f720127328fb_unins000.dat
Submit file
Filepath C:\Program Files (x86)\Kuwait Ice Hockey DB\unins000.dat
Size 1.7KB
Processes 2720 (KuwaitSetupHockey.tmp)
Type data
MD5 c4b518f3297b9c3c0df9822223c45cbb
SHA1 2796a2df422e6399fbbb75cfa0a6cedfca7a18d5
SHA256 02e7f720127328fb668641312d1118fee98f0f1c309a54b002ebc0f527ded597
CRC32 B8D526E9
ssdeep 48:Z9JXdZHdZIrCy1qdZhdZDbrCy4yrCy4pMxeUhmRY:ZfryC0UtTCHUCHpMHhGY
Yara None matched
VirusTotal Search for analysis
Name 388a796580234efc__setup64.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-3QJC1.tmp\_isetup\_setup64.tmp
Size 6.0KB
Processes 2720 (KuwaitSetupHockey.tmp)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
CRC32 2CDCC338
ssdeep 96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 506fce8eccf523ae_playerkuwait.fr3
Submit file
Filepath C:\Users\test22\Documents\Zapisnik_ONLine\PlayerKuwait.fr3
Size 162.2KB
Processes 2884 (DataBase Kuwait.exe)
Type XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5 54404389c02911885178b9a43fa0a8e4
SHA1 00887e68134f8d7d30934798f0b70d2fddd410dd
SHA256 506fce8eccf523aedc5fa098a8b87dcfb6f473ce1fefba356e41d6b5ff3f7304
CRC32 4BEDCECD
ssdeep 1536:AASIQh0YZpmMWxjbbZ7DYHrAbAV7RsbaR3+Opkr96uPtIv/iGjaj5k+NSzLu86/J:hlcd6PtIslJR
Yara None matched
VirusTotal Search for analysis