Dropped Files | ZeroBOX
Name 7975314d23cd385e_wps.lnk
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WPS.lnk
Size 1.9KB
Processes 2556 (tomcat.exe)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Mon Sep 26 19:48:00 2022, mtime=Mon Sep 26 19:48:00 2022, atime=Mon Sep 26 19:48:00 2022, length=1421664, window=hide
MD5 54241065dcebcb39a35a9b5685a0702e
SHA1 b8a68d1dfa50ca2542b993758c8625fc92882f41
SHA256 7975314d23cd385e859900401db126beb571db0b57d45390c911565ddb20f21a
CRC32 560CC228
ssdeep 24:8SwfkHsERdglRFmlwhhzNRb8SpX8SJO4Z6q8Sg6PyoiliK:8LesHlR3hhpRb8MX8+Z6q8ayZ
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 9bbe1bb0e827e273_conf.ini
Submit file
Filepath C:\Users\test22\Documents\conf.ini
Size 13.0B
Processes 2556 (tomcat.exe)
Type ASCII text, with CRLF line terminators
MD5 c1e96f256ef707e26bf543fc75075a7d
SHA1 cf2c893a330ea5a60b4922843d14fb6880b47859
SHA256 9bbe1bb0e827e2732d241fe5a915d254d310393345916cb92d60d9e157b3f338
CRC32 108A83DC
ssdeep 3:5WSMxv:5WSs
Yara None matched
VirusTotal Search for analysis