Dropped Files | ZeroBOX
Name d3983e52c48a6f98_explorti.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
Size 1.8MB
Processes 2536 (enter.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5aa3b4d694bc828650c63ade641f4581
SHA1 3f3e91f7b65be4e4b24fd29ea837206c00d55fc3
SHA256 d3983e52c48a6f9844b5ca10248ee51b8a1f2bd6637243ff0384a92288572f61
CRC32 3BD32A3D
ssdeep 24576:bcW1jg/Z+bPaeDOAIsfkRTePAFt2adNSUZBNMxsMFAbwfSQbcI+LWBMmQ4JX+ZGm:gmjglbsfkRmadNbqBFA9HCW4wF5uCb
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 58f2e2d814299ecc_webext.sc.lz4
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\webext.sc.lz4
Size 105.0KB
Type data
MD5 1c5d6d46653fbdfaab865d9fe0b41a54
SHA1 0bf5b952a5adbd1290f6e3baee0d944b8e95fab8
SHA256 58f2e2d814299ecc744a1a7fbdfacfb0632549941b0f3801954eb3b8ed940676
CRC32 87904CCE
ssdeep 3072:igI+ruOTMFUau+63U0BYLiM97vzY/lkRAYjIW0ePk:0+rvTYo6j1236s
Yara None matched
VirusTotal Search for analysis
Name ef9d0abf6e66a0e7_daeecdb5-e933-49b7-b27d-531c663a8ef4.dmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\daeecdb5-e933-49b7-b27d-531c663a8ef4.dmp
Size 25.8KB
Processes 3744 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Fri Jul 26 13:59:06 2024, 0x820 type
MD5 a8406e48dec877d23f6b6bcd2eb6695c
SHA1 be5d6a5ad98bcea46003ac74e0c2a136a3b5e8bc
SHA256 ef9d0abf6e66a0e743c32978dd7db05367e5bdeb4d8fcd75f91affac06668676
CRC32 9CBAA2D6
ssdeep 24:5u9gvcW/LdX30tI/IkfVBEUwffMr/vPtO7+XwHHHTih1A:5x3/hnQyVBESTV2RifA
Yara None matched
VirusTotal Search for analysis
Name 7ee927529f7108d8_BrowserMetrics-63327DF3-A54.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-63327DF3-A54.pma
Size 8.0MB
Type data
MD5 2f83a72f095bc42146a77940353d776c
SHA1 7b525857dbae3b79cce3f836475604f46d60008a
SHA256 7ee927529f7108d85841c07e1d05bafa82cb7d5a9a0db3ad9cf804c5a7b1632e
CRC32 1A7C42BC
ssdeep 6144:H9LG+zeL7c/lhRgdTTEDtsHVdUXaHmVGKPFIrgHkjdr:t6bcF
Yara None matched
VirusTotal Search for analysis
Name 7d1aea549f757bdc_e480ae2e-3c27-4abb-b232-bf0f3440ee91.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\e480ae2e-3c27-4abb-b232-bf0f3440ee91.dmp
Size 63.9KB
Processes 3892 (firefox.exe) 3616 (minidump-analyzer.exe) 3844 (firefox.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Fri Jul 26 13:59:02 2024, 0x820 type
MD5 6defb838fb03471ac118be310198acd8
SHA1 0f3022cd8dd7565fdd607faf0a534935723042c7
SHA256 7d1aea549f757bdc7891c74447fb47378c2d1d95269c3d96c4db7818c2e547c0
CRC32 E7EA1114
ssdeep 384:7Ig3ZRly3BQ1E1Vz1e1pT1omyFDksj0T+TzER2e1CECWx:7IwRlIl0W9Dksj7HER2o
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 252ee64bfb5ade53_urlCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\urlCache.bin
Size 3.2KB
Type data
MD5 ed220b99d29a9f969ba42da9deea2dfa
SHA1 33afcd8d6390e85e519d49e5db7654147daf34ec
SHA256 252ee64bfb5ade53b7b419d634b519a6223008339fa8b316293d90d4e65b4ab5
CRC32 52377592
ssdeep 48:/qbHgqedXU753de/xJtISt3bqhJtgtkt0IbvVr9cHSWypBr/BWLaLWcbsyMJrls:/qMqedXUd3AIq3bucwbhcmVsXJr6
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_D78.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\D78.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name dc8e6ba70253d52a_07491923-3d16-4c30-a991-fe94ad83fed3.extra
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\07491923-3d16-4c30-a991-fe94ad83fed3.extra
Size 784.0B
Processes 1868 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 c2ca277d8c2f751dc2b23b65c4289e6d
SHA1 830a205d6abac1d1acf02bdf8d4b2666bf95db48
SHA256 dc8e6ba70253d52ab1810f9ad0c4c429b5df44d5ff99d3ad8ecf2917e976b477
CRC32 EB46009C
ssdeep 12:YNTvJijyKBS4zQqMuSH+9SSJiFjopNxTjJxpQccijpQJiUo18h94Ai3Vn:YRkjyK7v96sPpLpQ/ijpQJiUo18p0
Yara None matched
VirusTotal Search for analysis
Name 5a3ec8851acd1bb6_CrashpadMetrics.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
Size 1.0MB
Type data
MD5 aea7ffdba870ea9d59d542f890fecc8c
SHA1 2efe83750eebdfacc148d376cc4edfdf8e5d2ac9
SHA256 5a3ec8851acd1bb62d270e9bdca9625da9f34df69ef39608bc2ce3de68960056
CRC32 CB7B9D10
ssdeep 12:bHiZXAVMMOKEKSCemJKlkQPdl/JG89Hy3aJ0oMFgigpCbUycIXuYJ05:bwQOMzBS+Mk0/JvWoMeigp1y5eYW
Yara None matched
VirusTotal Search for analysis
Name eb0f4767ea7c9845_6a33a94b-fc28-4b34-8220-6090ccbeebb2.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\6a33a94b-fc28-4b34-8220-6090ccbeebb2.dmp
Size 85.1KB
Processes 3188 (firefox.exe) 2228 (chrome.exe) 1868 (firefox.exe) 3396 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Fri Jul 26 13:58:29 2024, 0x820 type
MD5 ec713515bb5715741460e24b2e20271f
SHA1 9e75ddce4ae6298be2ff4f03907279788481b944
SHA256 eb0f4767ea7c98456ad43d2b34074c3543bae682ca4cbaa6660b07df0c8302a3
CRC32 E7E98D6D
ssdeep 384:n6gDQly3LG/myBDIf6BeOZ+1kuN4mNSlIQFvPBjEL:n61lmgpDu6NZ+iuN4mIIQOL
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e087fa068f19c9a8_metadata
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
Size 114.0B
Processes 2228 (chrome.exe)
Type data
MD5 fb22e741beb8360b62c4d0118c7df95b
SHA1 faf5635229bfa9eee938dd8eeda44df71aea5578
SHA256 e087fa068f19c9a8e302be168a5197c968e69ad70c765c09bfac5b7eacff6d8e
CRC32 7053F227
ssdeep 3:mTll+Xlz4l/klTUllllllnlQc1IESD9DQpWsdGRm1Kd:mTlEhT8/lT1zwDQ4swkKd
Yara None matched
VirusTotal Search for analysis
Name 2e4dbfed35bcf2cc_lastcrash
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\LastCrash
Size 10.0B
Processes 2820 (firefox.exe) 3188 (firefox.exe) 1868 (firefox.exe)
Type ASCII text, with no line terminators
MD5 31febb6b14e986a185022189ac8980f1
SHA1 dd80de4319da96bac07204a435aecb31ebee7f24
SHA256 2e4dbfed35bcf2cc79e96ad8642a115b0abda7f820052b0a3301fceb61f056e9
CRC32 5A66E9A6
ssdeep 3:LHVVXWXS:rVVXWXS
Yara None matched
VirusTotal Search for analysis
Name 817f4787ab03c437_chrome_shutdown_ms.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
Size 4.0B
Type ASCII text, with no line terminators
MD5 274583a65fe6b9b9874eb891eb0acf17
SHA1 19c068ea4adbdf7bfe8729c603dcf8ba9249dac5
SHA256 817f4787ab03c4377decd864c064ec156a0b3f5dffdc70795908d37a81a556bb
CRC32 BC9CD6FD
ssdeep 3:Lin:G
Yara None matched
VirusTotal Search for analysis
Name ddcf76c3d8d45779_explorti.job
Submit file
Filepath C:\Windows\Tasks\explorti.job
Size 274.0B
Processes 2536 (enter.exe)
Type VAX-order 68k Blit mpx/mux executable
MD5 f27d6621289558ccaca94e35dba7e2ea
SHA1 caccb32beae5a81799cb8782a7636edfd1fc6c6e
SHA256 ddcf76c3d8d45779d3adb18a214244ca9b3f3bd3cf0478a70787523162c2b261
CRC32 8069B62C
ssdeep 6:Z9QXZFtXE/Xm/UEZ+lX1cI1l6lm6tI4y0l1X+ut0:QXZFZkW/Q1cagc4V13t0
Yara None matched
VirusTotal Search for analysis
Name 68b3db8466acad16_6a33a94b-fc28-4b34-8220-6090ccbeebb2.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\6a33a94b-fc28-4b34-8220-6090ccbeebb2.extra
Size 4.3KB
Processes 3188 (firefox.exe) 3440 (minidump-analyzer.exe) 3396 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 123d9caa458c7657dcb2751d1b9d82b3
SHA1 5078efe4487eacba63c5076377f71d17f1b0f356
SHA256 68b3db8466acad16d816e14c3df613ce252a624b8720e689f0c7a1e8b107d8b4
CRC32 FC3B587B
ssdeep 48:Y/Qo0Q6673DTIOPfWk+S8QsnxkD4HEujHtYDe7uwqzYqsabVjyX55p3iUSJMg5MH:Dor3bDUYiu52abBi5X3qK0CALIFYfwz
Yara None matched
VirusTotal Search for analysis
Name 03a51cb1ed95d96b_6a33a94b-fc28-4b34-8220-6090ccbeebb2
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\6a33a94b-fc28-4b34-8220-6090ccbeebb2
Size 2.9KB
Processes 3188 (firefox.exe) 3396 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 2f797116503939b5aa1a9fad6ff9e460
SHA1 413d81a3dc81443e6d1db8f02e6a75a650b70cbb
SHA256 03a51cb1ed95d96ba0b44231b38efb2c3f7aa8f39fcde737d651d537f1e9ac62
CRC32 A741A8FA
ssdeep 48:8Qo0QT67m2uVjyX55p3iUSJMg5MKCTWCFZULczTVzBvJ49vZX0DA9Ki:ToreiRBi5X3qK0CALIFYfwA9X
Yara None matched
VirusTotal Search for analysis
Name 0bbff6318469e56b_3e59b4bf-187f-49f5-8de3-f688a44e4600.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\3e59b4bf-187f-49f5-8de3-f688a44e4600.dmp
Size 919.2KB
Processes 2228 (chrome.exe) 3188 (firefox.exe) 1868 (firefox.exe)
Type Mini DuMP crash report, 10 streams, Fri Jul 26 13:57:38 2024, 0x0 type
MD5 744d67db5506a671c54100b3510c2362
SHA1 ba59a5fb033ce03baaa04a4baf872a33b6e6c06f
SHA256 0bbff6318469e56b1356077128949187abe1cd4786e3d10064578b6c5c721a04
CRC32 579D3D19
ssdeep 6144:IeDVitSZRSyDAjqC9pvl5IEK7jbZxh036FlqZU8R9ne:A4ul5hR9e
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 98c0fe2d7007304b_f6f1921920.exe
Submit file
Filepath C:\Users\test22\1000003002\f6f1921920.exe
Size 89.5KB
Processes 2800 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e218f9c24fad48bdf255a952b9e6f626
SHA1 77b92536b6e8c31a11ae5a4aed8bb368d613b678
SHA256 98c0fe2d7007304be990c568f8214d2f17be3d7afe79a5d981080b3f2929c22b
CRC32 201785B2
ssdeep 1536:L7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfGxx67iOq:Hq6+ouCpk2mpcWJ0r+QNTBfGCg
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a67115b767cd1f5b_scriptCache-child.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\scriptCache-child.bin
Size 824.1KB
Type data
MD5 5fca71ec196a94ddd75c299f455f8289
SHA1 e2eac02c316dc41ef01819b48111f9eb9a7ae0ba
SHA256 a67115b767cd1f5b92828998b99d1865067e567f8051340849b6def682234d33
CRC32 20E727DA
ssdeep 6144:7Lv50b7rtyuRMAMgDh6QbZpZltg2ebfhAFgMWM/OB48SuTSBWobBmPLtPkZ:f5ctdD15PgMWM/OXnSBWobItcZ
Yara None matched
VirusTotal Search for analysis
Name 9e2695fb31e2c16d_debug.log
Submit file
Filepath C:\Program Files (x86)\Google\Chrome\Application\debug.log
Size 272.0B
Processes 2228 (chrome.exe)
Type ASCII text
MD5 c02ac6b38148b5b4e385e2db5374e667
SHA1 0f1169627583d2be16f2d1d162b0fdb34a5df71a
SHA256 9e2695fb31e2c16d3dd1fda093b19e76a0520a4d13ddbf3fb463b8658f0c200c
CRC32 94E76B21
ssdeep 6:qcUmSlNoqYlHIvRU4LGGmm3V4v8BIjhRU4LGGmm3V4vF:nyyqYlovRU4LGBm3V6NjhRU4LGBm3V6F
Yara None matched
VirusTotal Search for analysis
Name a1e1b422c40fb611_D7A.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\D78.tmp\D79.tmp\D7A.bat
Size 2.8KB
Processes 1120 (f6f1921920.exe)
Type ASCII text, with CRLF line terminators
MD5 de9423d9c334ba3dba7dc874aa7dbc28
SHA1 bf38b137b8d780b3d6d62aee03c9d3f73770d638
SHA256 a1e1b422c40fb611a50d3f8bf34f9819f76ddb304aa2d105fb49f41f57752698
CRC32 932D7B77
ssdeep 48:Nd27V5rN81fN80XUbaOUb5OzQ/iqzQ/hXDTjODAKpxVgXDOev0W:j6rrN81fN80Ebanb5OzQ/iqzQ/hTTj+y
Yara None matched
VirusTotal Search for analysis
Name b4709acbae8c9355_scriptCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\scriptCache.bin
Size 9.2MB
Type data
MD5 2a531b9908cd4740306590090699e0b2
SHA1 92fb9d89d108db2ad580c77345faf9c5961cf860
SHA256 b4709acbae8c9355f5344c2cb670de78da945a0f5b3d1636ea2fff6ca2718be0
CRC32 E6DFCFD0
ssdeep 49152:zfNsfR/eXfWVAoIgPm6tnQhA3RAViGtP7lbASvzmjdYDNMpeckIOehICZ3ZkF:zfNyYOVi6xskmPZASvz0GMs2hIF
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • RedLine_Stealer_b_Zero - RedLine stealer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 43032a9f1dc6c32d_fae861c1-0e9c-4047-a4b9-1df299d24fc6
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\fae861c1-0e9c-4047-a4b9-1df299d24fc6
Size 3.3KB
Processes 2820 (firefox.exe) 2504 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 617f6d6b3f4f07075e31a7179660a4dc
SHA1 5d42683f0a00b5388fcc94d4a24390d7f089c2df
SHA256 43032a9f1dc6c32d8c2a2fd95c465ad94e24bdf7b7dbc5b736647b28b99c0f6f
CRC32 7EDA60DC
ssdeep 48:JQoWQI1mW8gjyX55p3iUSuMggxKCjNWCFZULcPL+xGlAh1nvJGXv6XFuKnGi:aoV1Xci5X3hA98CALkAPoiUKnr
Yara None matched
VirusTotal Search for analysis
Name ac162670ad98591b_submit.log
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\submit.log
Size 392.0B
Processes 2504 (crashreporter.exe) 3396 (crashreporter.exe)
Type UTF-8 Unicode text, with CRLF line terminators
MD5 ccbcded8c56dda1f5402867083169025
SHA1 c82e808e3056b78e68f917eea47e86acafced14b
SHA256 ac162670ad98591b1ea5cadcfaceef2020b2ecf3ddd4051da402671b77fbc013
CRC32 95DC42FB
ssdeep 6:SXJYcVd6QwHdlQxXJYcVd6QwHdlQxXJYbzd6QwHdlQxXJYbzd6QwHdlQK:SmggQw9wmggQw9wmvgQw9wmvgQw95
Yara None matched
VirusTotal Search for analysis
Name adf00abeb87553c4_fae861c1-0e9c-4047-a4b9-1df299d24fc6.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\fae861c1-0e9c-4047-a4b9-1df299d24fc6.extra
Size 4.6KB
Processes 2820 (firefox.exe) 800 (minidump-analyzer.exe) 2504 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 ea14f333b33351e850463b1d6e88e35f
SHA1 e64efddabb0687fcdacbe73e29885eaa9d1eeaea
SHA256 adf00abeb87553c4ca8ffaaedf23352028182ea0468fa360fa5b0fc0d9534e26
CRC32 A4F326E5
ssdeep 96:DownDLrCb52abci5X3hA98CALkAPoiUKnY:DowmN2aGOLkr8Y
Yara None matched
VirusTotal Search for analysis
Name 65b3c292d3e4d00d_07491923-3d16-4c30-a991-fe94ad83fed3
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\07491923-3d16-4c30-a991-fe94ad83fed3
Size 845.0B
Processes 1868 (firefox.exe)
Type ASCII text, with very long lines
MD5 94ab6e3ad44760de63a9e9db319e7805
SHA1 d14674462a0a45971a9f0aff0e039314c17f9edf
SHA256 65b3c292d3e4d00dd2eb7a5e31349777861458a4aad91842eeb03b9f84dbd873
CRC32 863C956B
ssdeep 12:8ng0DtTvJijyKBS4zQqMuSH+9SSJiFjopFTjJxpQ2hPijpQJifm68h92i3Vn:KkjyK7v96sPpBpQ2lijpQJifp8i0
Yara None matched
VirusTotal Search for analysis
Name 7c4e88c5033bce68_6a33a94b-fc28-4b34-8220-6090ccbeebb2-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\6a33a94b-fc28-4b34-8220-6090ccbeebb2-submission
Size 73.0B
Processes 3396 (crashreporter.exe)
Type ASCII text
MD5 93d48f83561ac1adb4ce57fb830c5181
SHA1 45087979784e645329ba06706abb4b810f69b3cf
SHA256 7c4e88c5033bce680e877a87f8f77f05f0b67f9c8fad3a6ed2d112f5f3658a4d
CRC32 B8397F09
ssdeep 3:RIRL/z4WWQ4Kx9VuwHHLTAvn:e+WNcwLTAvn
Yara None matched
VirusTotal Search for analysis
Name b569cb887281c57c_07491923-3d16-4c30-a991-fe94ad83fed3.dmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\07491923-3d16-4c30-a991-fe94ad83fed3.dmp
Size 91.7KB
Processes 1868 (firefox.exe) 3188 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Fri Jul 26 13:58:38 2024, 0x820 type
MD5 da17ef518d2dae8c244c1dd7c35d7893
SHA1 16ae7868a987024e3ab1d62c1022c6426ad5f14b
SHA256 b569cb887281c57c7cd18173535d2f7bdd3214451f97584e50d782313f61c3bf
CRC32 332FD573
ssdeep 384:eMkzAQJLly3CIzfmyRDsOCJD8tv0H1iIouJMd+jMojiSWxdHKE7VOsD:eM9QBlwTZDslD31FWhoOx5ZD
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 02ed395f87ba1171_66cf9615db.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000002001\66cf9615db.exe
Size 248.0KB
Processes 2800 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 34021b6d78d07fd9a2342a6864163605
SHA1 5ffd48d499977f2f5360296240702fa254514707
SHA256 02ed395f87ba1171cf49e460bc73209e6dd90b7d0b0b482881ac4c153345e7b6
CRC32 E6A78CE1
ssdeep 6144:bPJmQUzJnsZtws3aTTlOUK20syaToOdT:bPEQosZGYa3B0uTjp
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name cacb3b090bd98317_compatibility.ini
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\compatibility.ini
Size 200.0B
Processes 1868 (firefox.exe) 3744 (firefox.exe)
Type Windows WIN.INI, ASCII text, with CRLF line terminators
MD5 63f28ee6c5768202c31eaf82725b64c2
SHA1 edc0b0c87aaa262a0aba6e6b29b2c31cc04fcf39
SHA256 cacb3b090bd98317500f593712c4bf51b5197c7aa9e07b6e10cab50144339ff0
CRC32 D70ADABB
ssdeep 3:tZAQU6oEl1mE12NE2aT/P4WX1rDZjrEFwHQ3ZjrEFwslyy:VoKmbbabN1rDVEFycVEFL
Yara None matched
VirusTotal Search for analysis
Name a8cf1803039bb68e_fae861c1-0e9c-4047-a4b9-1df299d24fc6-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\fae861c1-0e9c-4047-a4b9-1df299d24fc6-submission
Size 73.0B
Processes 2504 (crashreporter.exe)
Type ASCII text
MD5 14ea5ad9cf5bfeab01f4223748afcb35
SHA1 712b6059ebf01c162a659db48df26e5286ed7df7
SHA256 a8cf1803039bb68e29e35aa7179d78df84eebb9848777804d9813bbd30d75183
CRC32 49CBB211
ssdeep 3:RIRL/z4XCpdrs3wHbMwXYKn:e+ypdrs3wHbDXYKn
Yara None matched
VirusTotal Search for analysis
Name 8f39e29bf4e05f6c_BrowserMetrics-66A3AB44-94.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-66A3AB44-94.pma
Size 8.0MB
Type data
MD5 2470a87898fb77e31d79530d38389302
SHA1 33d4cc51c1b63451f8d7c10006b85edfecefd372
SHA256 8f39e29bf4e05f6c59f2c39399b0fdfeb3d37e5ab762706bba324671f403d8c4
CRC32 F0D1A5A6
ssdeep 96:bRWnHu3M05KJF1LelP8sN5Mo9IqsJpVKLmk15O2nFPSkDYcb9uULqAbmLJU:EOh5KH1LepN+qj5skIUL1qV
Yara None matched
VirusTotal Search for analysis
Name d37fcb160d37cfdd_settings.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Size 40.0B
Processes 148 (chrome.exe)
Type data
MD5 a3122d4670c51912628b97bdd6fffb80
SHA1 45d2e3060e09f46071125d6125983c81ae4970a1
SHA256 d37fcb160d37cfddefea794094044b7e588d44c4883c72ba0ef1503e5f9c7d59
CRC32 77809701
ssdeep 3:FkXD3WyqUm:+ix
Yara None matched
VirusTotal Search for analysis
Name ec86dff13ec188e0_startupCache.8.little
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\startupCache.8.little
Size 7.4MB
Type data
MD5 c9fdf6ced10ea267f5e1e7d6cb4b467c
SHA1 181148adeccc66362e241a8f434ea384daa5f27b
SHA256 ec86dff13ec188e0afcec1f59397551e7072a12b24d6a20dc91b3e9705a63e4e
CRC32 F1DD0004
ssdeep 98304:XxxN8Jzl6VttNx8UoxmuWR2FPGjD79MJRGD3j/s3:Xl89lMz/FuW+6D72iTk
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 0b98a25983af2652_fae861c1-0e9c-4047-a4b9-1df299d24fc6.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\fae861c1-0e9c-4047-a4b9-1df299d24fc6.dmp
Size 92.0KB
Processes 2820 (firefox.exe) 2504 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Fri Jul 26 13:57:29 2024, 0x820 type
MD5 9d482948521fe8ac7d0788cf2b56c1b4
SHA1 df7b7c1e96847ea4f8bf59f61555944370b36b22
SHA256 0b98a25983af2652aee3f28b0d6fcafdc3240e0c6f9c7b7bac24b587eb304033
CRC32 F557C0F5
ssdeep 384:KikzAQyAly3UUtipztrYd+AvGMy+myXxD0T1UttCmsRoc/tRUrfShVHxKGuwZR7d:Ki9QVllB+5D0KmHlRLxjD
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis