Dropped Files | ZeroBOX
Name c7e67928407dc0d2_efthfxj.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\efthfxj.exe
Size 251.0KB
Processes 2816 (efthfxj.sfx.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 dcb591d1fc03274934709e24b502d719
SHA1 9d4172d007347a9aa54b48cb5a214a792ad03708
SHA256 c7e67928407dc0d2fe2a61e10e2f97104986770b6ba6e59f8faa7b6fcc595028
CRC32 C74310CC
ssdeep 6144:lVlX/ZBmQzSmsjICshnbjEZHzsZ9fYoI:lTX/ZBmQzzsXWgzsZ9fYV
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_3661109
Empty file or file not found
Filepath C:\Users\test22\AppData\Roaming\__tmp_rar_sfx_access_check_3661109
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name c3f004c34695080e_eystsdf.cmd
Submit file
Filepath C:\Users\test22\AppData\Roaming\eystsdf.cmd
Size 18.4KB
Processes 2552 (Display1.exe)
Type DOS batch file, ASCII text, with very long lines, with CRLF line terminators
MD5 fa0fdc18cccb4a2fb162362848d10d73
SHA1 9ccab8577c310e19e1299fb7fcad538c72a36420
SHA256 c3f004c34695080e75df6dccc39dae9e269eba7164aa0f95b9964078973f3736
CRC32 FA5DF2A1
ssdeep 384:b55S5l5LNraGP34HAXtn8tzv3kFjCSQGi:bKnP4HAdKzvGuEi
Yara None matched
VirusTotal Search for analysis
Name ded2b1a499ba8ac0_efthfxj.sfx.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\efthfxj.sfx.exe
Size 474.5KB
Processes 2552 (Display1.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 642a150be5bbed12c85dff794b955c01
SHA1 115de36f192e2bb10ec7c2c8bba9bf3dd639b461
SHA256 ded2b1a499ba8ac097361b01b1e56bdaa67769c0b7130489af489bef58cb5dfc
CRC32 2E654FEE
ssdeep 12288:WcrNS33L10QdrX2oVnaeIZuIlS+fc7Re7RR:FNA3R5drXxV/IUuG7077
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis