Dropped Files | ZeroBOX
Name 58f2e2d814299ecc_webext.sc.lz4
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\webext.sc.lz4
Size 105.0KB
Type data
MD5 1c5d6d46653fbdfaab865d9fe0b41a54
SHA1 0bf5b952a5adbd1290f6e3baee0d944b8e95fab8
SHA256 58f2e2d814299ecc744a1a7fbdfacfb0632549941b0f3801954eb3b8ed940676
CRC32 87904CCE
ssdeep 3072:igI+ruOTMFUau+63U0BYLiM97vzY/lkRAYjIW0ePk:0+rvTYo6j1236s
Yara None matched
VirusTotal Search for analysis
Name 8dc10dc4dbdc18ef_ed748d2a-8ada-4d33-884e-e2fb34e8f309-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\ed748d2a-8ada-4d33-884e-e2fb34e8f309-submission
Size 73.0B
Processes 2604 (crashreporter.exe)
Type ASCII text
MD5 171649071cc8fe130f97cd687624ea93
SHA1 6dd08ac2b3ad5f5e70169ef2a9a2e4a60eee3019
SHA256 8dc10dc4dbdc18efedb40d0e0367cc4c800ff53aa38a8fbc12d3716c4bde0719
CRC32 A6A07A4F
ssdeep 3:RIRL/zRXQvx9sBRgdm1Dudn:enKETY4udn
Yara None matched
VirusTotal Search for analysis
Name 7e07bcd893945daa_explorti.job
Submit file
Filepath C:\Windows\Tasks\explorti.job
Size 274.0B
Processes 2544 (random.exe)
Type VAX-order 68k Blit mpx/mux executable
MD5 bb038c2d2c88c132ff588658ddc397cb
SHA1 f5192a76f8021fb8344c124ec68803cb85d03d20
SHA256 7e07bcd893945daace584bf42e4ad749f4540ad5c6d646b3ded3de3f1587ea70
CRC32 113BA6C9
ssdeep 6:Z9QXZFtXE/Xm/UEZ+lX1cI1l6lm6tI4y0l14Kl0ut0:QXZFZkW/Q1cagc4V14Kldt0
Yara None matched
VirusTotal Search for analysis
Name 6baf9dcca64beada_bc4b21ca-8f6b-41c8-9a22-fcc66457be4b.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\bc4b21ca-8f6b-41c8-9a22-fcc66457be4b.extra
Size 783.0B
Processes 736 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 1a2409a0f6f208e7fa5566c0c277d385
SHA1 9ad5795eb182b636bce40e058841cb7c6b785b64
SHA256 6baf9dcca64beadaab7894199a053b69fcccb4404378257ddf8d8d66c446f504
CRC32 C001C815
ssdeep 12:YNTvJijyKBS4zQqMuSHdzJiF/pp4TjJxpQivijpQJif0PQ8oi3rn:YRkjyK7v96dVcpEpQeijpQJif0Y8o2
Yara None matched
VirusTotal Search for analysis
Name c82169e1a16cc52a_ed748d2a-8ada-4d33-884e-e2fb34e8f309.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\ed748d2a-8ada-4d33-884e-e2fb34e8f309.extra
Size 4.6KB
Processes 2216 (firefox.exe) 2812 (minidump-analyzer.exe) 2604 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 683a081bc23d211c18dd5468d785ae1a
SHA1 4024034e012614231139e38aaeaf0acfa75122ba
SHA256 c82169e1a16cc52ab934c1dd58ba6a7760847a28a9533af1a489cb2b7ed09c5d
CRC32 AB784E86
ssdeep 48:Y/QoRQj93DUTIOPfD+SQAkkn8+D4HEujtlDWJbwqzYesabgjyX55p3iUSSMgLyRH:DoC9DJrOb5Oabci5X3V4YCVLFDfhambH
Yara None matched
VirusTotal Search for analysis
Name 8a6dfa9b381a4575_42dc52c3-4edb-4337-842a-8cf86b5d9964.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\42dc52c3-4edb-4337-842a-8cf86b5d9964.dmp
Size 95.7KB
Processes 676 (firefox.exe) 2668 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Mon Jul 29 05:03:58 2024, 0x820 type
MD5 c594a6b9e72fb350508e73089688ab34
SHA1 ac668b4540d90046e02d1a451631641041e30f07
SHA256 8a6dfa9b381a4575e67e3fccfc10a23e8adabaa73a28164f265e7c45297548ee
CRC32 5AA0673D
ssdeep 768:PV3Q1l9LxnoDq3LuXClr+ZCmL6gvxaWhD:PejUjylr+smLt
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name d6c77624f72da6ab_75c5ed8dda.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000017001\75c5ed8dda.exe
Size 3.1MB
Processes 2820 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ee498e00b008aa295eae6800ebdac6b8
SHA1 7726df893593df94f75874194b5422e82e221479
SHA256 d6c77624f72da6abb78453bece06257efb245c99db4cbb3bf908b4a1ab069bbb
CRC32 0E979658
ssdeep 49152:MnVqaTJ3Cl58ZPKPWME7qJhUC1EPz2uxIbpW0TF3YH4o4VpdKmlGaRlejIf6Q:MBZy8ZScGJKPSSIbgRHqpIqMK6Q
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • EnigmaProtector_IN - EnigmaProtector
VirusTotal Search for analysis
Name bcb50fb436471a48_42dc52c3-4edb-4337-842a-8cf86b5d9964.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\42dc52c3-4edb-4337-842a-8cf86b5d9964.extra
Size 4.7KB
Processes 676 (firefox.exe) 2144 (minidump-analyzer.exe) 2668 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 14abcab56b2d3d5a93225d37142e8725
SHA1 7190217bc678a85d21e12d5a9ed6d9120c30e3ac
SHA256 bcb50fb436471a487a9893f3649bcdcf847370310d276c60078b0623c28d555d
CRC32 9413EE65
ssdeep 96:Do8IWDJrGb5oabHi5X3NJLHCVLfmILdRj01oa:DonLNobELfmceoa
Yara None matched
VirusTotal Search for analysis
Name 252ee64bfb5ade53_urlCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\urlCache.bin
Size 3.2KB
Type data
MD5 ed220b99d29a9f969ba42da9deea2dfa
SHA1 33afcd8d6390e85e519d49e5db7654147daf34ec
SHA256 252ee64bfb5ade53b7b419d634b519a6223008339fa8b316293d90d4e65b4ab5
CRC32 52377592
ssdeep 48:/qbHgqedXU753de/xJtISt3bqhJtgtkt0IbvVr9cHSWypBr/BWLaLWcbsyMJrls:/qMqedXUd3AIq3bucwbhcmVsXJr6
Yara None matched
VirusTotal Search for analysis
Name 6930d12002531452_lastcrash
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\LastCrash
Size 10.0B
Processes 2216 (firefox.exe) 676 (firefox.exe) 736 (firefox.exe) 2452 (firefox.exe)
Type ASCII text, with no line terminators
MD5 ae69ed44ae69efee551a0583ae309209
SHA1 4431be36d304e8a40b2f5c4e6db88ed67b8b63f7
SHA256 6930d12002531452bad9f30f6e3ee745032de44e5775830ddb8a7b23f52df075
CRC32 42A2A6DA
ssdeep 3:LHXXgdWn:rXXgU
Yara None matched
VirusTotal Search for analysis
Name 9de2665c586d3abe_42dc52c3-4edb-4337-842a-8cf86b5d9964-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\42dc52c3-4edb-4337-842a-8cf86b5d9964-submission
Size 73.0B
Processes 2668 (crashreporter.exe)
Type ASCII text
MD5 3fe1e3c11cfdbadaa68f32b3f50d7335
SHA1 00aa4f3ad4730ef4c83c0800448f7f32e60eda89
SHA256 9de2665c586d3abec46e902883269a3825c41ea598dd9540dec79c1fb6350dcf
CRC32 520A6CE2
ssdeep 3:RIRL/zRTWZBJsRSgeGTRvfKn:en6/sRFJfKn
Yara None matched
VirusTotal Search for analysis
Name c1077896a5d58c33_25486c72-1a2d-424a-acf3-a490fab06966
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\25486c72-1a2d-424a-acf3-a490fab06966
Size 844.0B
Processes 2452 (firefox.exe)
Type ASCII text, with very long lines
MD5 6dcf8ed0b7b580f94e8e47e82d098c17
SHA1 b70f21ee883606e9aa651c3eeea4029c29502e90
SHA256 c1077896a5d58c33d642e4e0ac91183d1fc2284b9a8ea4291ff8acd24817fe22
CRC32 C9F2F8AD
ssdeep 12:8mGSV1apTvJijyKBS4zQqMuSHYoGJiF/p/TjJxpQv7PijpQJifNQF8JMi3rUn:ivtkjyK7v96NKcpXpQjPijpQJifo8JMl
Yara None matched
VirusTotal Search for analysis
Name a2285d364e7f627f_25486c72-1a2d-424a-acf3-a490fab06966.extra
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\25486c72-1a2d-424a-acf3-a490fab06966.extra
Size 783.0B
Processes 2452 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 eb6eb6f0f47abd19bf77445c14a8edad
SHA1 6015f20a0ff72f600dd02e85a12c86d7dc60a49f
SHA256 a2285d364e7f627f878249a310d5c8b0bfd532eb8a30032db64f5d165a67fd2a
CRC32 AA1E2496
ssdeep 12:YNTvJijyKBS4zQqMuSHYoGJiF/p/TjJxpQnijpQJiKaIF8J1i3rUn:YRkjyK7v96NKcpXpQnijpQJi6F8J1l
Yara None matched
VirusTotal Search for analysis
Name 4c79172b7d2127c2_bc4b21ca-8f6b-41c8-9a22-fcc66457be4b.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\bc4b21ca-8f6b-41c8-9a22-fcc66457be4b.dmp
Size 87.1KB
Processes 736 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Jul 29 05:04:30 2024, 0x820 type
MD5 39fc1757414c0c68bad4cab21f7234af
SHA1 65937ee36ce3b0b018dae434c31f44be68c82090
SHA256 4c79172b7d2127c25764e7267cb35c2903c06fe9a7106483aefaadb992ffe2a8
CRC32 A5630E2E
ssdeep 384:A+pscJCUAbly3cTLnlZZmy4DBs4sMe1OMTLQK3ZS7xdBrCY5SdGfRsao8MEPCmCv:bpbJElFTLn1gDOaMTLU/98j9W6Hb
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 49279aced529c13c_25486c72-1a2d-424a-acf3-a490fab06966.dmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\25486c72-1a2d-424a-acf3-a490fab06966.dmp
Size 92.8KB
Processes 2452 (firefox.exe) 2228 (minidump-analyzer.exe)
Type Mini DuMP crash report, 11 streams, Mon Jul 29 05:04:34 2024, 0x820 type
MD5 89621ee35df1a2b8f1d71defa5fc010a
SHA1 7916cab40af2c7192c57bf6cd235c9fcdf57786c
SHA256 49279aced529c13c16d7f340abd2088a966801e500aeab43e2e77645af61e38e
CRC32 D85FBFA2
ssdeep 768:PK3QClnkLEWJuLDuNkLiF/BuW/fYAI6gvxaWhD:PnO08fYNQW/fYAIt
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name bd7458b4201fc99b_explorti.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
Size 1.8MB
Processes 2544 (random.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a45cd34dab56ce2f61232c79a750374d
SHA1 a806bb585f82d2c50967e3dc864149b774cd0793
SHA256 bd7458b4201fc99b83cf5784c8f02b575d724cc4dee8972a8e95a37858fde55f
CRC32 90A7409C
ssdeep 49152:wB5UV20xq7JP4Kcr8/wNh3IV+T3ebUv6uA4+66M:wB+2uGJQKcrW2we3eYv6V6D
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name a67115b767cd1f5b_scriptCache-child.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\scriptCache-child.bin
Size 824.1KB
Type data
MD5 5fca71ec196a94ddd75c299f455f8289
SHA1 e2eac02c316dc41ef01819b48111f9eb9a7ae0ba
SHA256 a67115b767cd1f5b92828998b99d1865067e567f8051340849b6def682234d33
CRC32 20E727DA
ssdeep 6144:7Lv50b7rtyuRMAMgDh6QbZpZltg2ebfhAFgMWM/OB48SuTSBWobBmPLtPkZ:f5ctdD15PgMWM/OXnSBWobItcZ
Yara None matched
VirusTotal Search for analysis
Name b4709acbae8c9355_scriptCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\scriptCache.bin
Size 9.2MB
Type data
MD5 2a531b9908cd4740306590090699e0b2
SHA1 92fb9d89d108db2ad580c77345faf9c5961cf860
SHA256 b4709acbae8c9355f5344c2cb670de78da945a0f5b3d1636ea2fff6ca2718be0
CRC32 E6DFCFD0
ssdeep 49152:zfNsfR/eXfWVAoIgPm6tnQhA3RAViGtP7lbASvzmjdYDNMpeckIOehICZ3ZkF:zfNyYOVi6xskmPZASvz0GMs2hIF
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • RedLine_Stealer_b_Zero - RedLine stealer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ffd97e6062070ad0_42dc52c3-4edb-4337-842a-8cf86b5d9964
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\42dc52c3-4edb-4337-842a-8cf86b5d9964
Size 3.3KB
Processes 676 (firefox.exe) 2668 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 96e6a034661791c1d5e36be3c2bae61a
SHA1 4c15cdb8ea2e423b43369da435bb7ffd29930fe4
SHA256 ffd97e6062070ad009b882556e5eb5cf17b3947f90174a12ca4f9351d1fd7e9e
CRC32 94A5CF4F
ssdeep 48:EOQo8/Qg9mcbDjyX55p3iUSmV3MghVKCN3CFAULcP2BuanJvAGzFvJ/dRYv6Xlab:oo8IV6Hi5X3NJLHCVLfmILdRj01V
Yara None matched
VirusTotal Search for analysis
Name 58e1762c1638f036_bc4b21ca-8f6b-41c8-9a22-fcc66457be4b
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\bc4b21ca-8f6b-41c8-9a22-fcc66457be4b
Size 844.0B
Processes 736 (firefox.exe)
Type ASCII text, with very long lines
MD5 9172098079008608622ca3173d874653
SHA1 4c23ba67e9442e6c4309864282248fe3d6dc3bf2
SHA256 58e1762c1638f036b0945c615cac2e8a4c70bc59d168d4d93d2a515dead26f9b
CRC32 AC325F40
ssdeep 12:8JC6xTvJijyKBS4zQqMuSHdzJiF/pp4TjJxpQvBvijpQJif0PQ8Wi3rn:p6lkjyK7v96dVcpEpQdijpQJif0Y8W2
Yara None matched
VirusTotal Search for analysis
Name 742ca3a5e70a5001_ed748d2a-8ada-4d33-884e-e2fb34e8f309
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\crashes\events\ed748d2a-8ada-4d33-884e-e2fb34e8f309
Size 3.3KB
Processes 2216 (firefox.exe) 2604 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 4bd8809980c4687fed18b1ab7164944f
SHA1 20e8ce03342cde7fa30a93c5c9e99b542c928b9e
SHA256 742ca3a5e70a50012b80499f24624d5b10551451bb792c03e94ee49a3e857d54
CRC32 4ABE936B
ssdeep 48:q43QoSQR9mN6IgjyX55p3iUSSMgLyRKCI3CFAULcP2BvyiDf0I0vJvYvDX2+mi:QoZ6N6Ici5X3V4YCVLFDfhambL
Yara None matched
VirusTotal Search for analysis
Name cacb3b090bd98317_compatibility.ini
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\compatibility.ini
Size 200.0B
Processes 676 (firefox.exe) 2452 (firefox.exe)
Type Windows WIN.INI, ASCII text, with CRLF line terminators
MD5 63f28ee6c5768202c31eaf82725b64c2
SHA1 edc0b0c87aaa262a0aba6e6b29b2c31cc04fcf39
SHA256 cacb3b090bd98317500f593712c4bf51b5197c7aa9e07b6e10cab50144339ff0
CRC32 D70ADABB
ssdeep 3:tZAQU6oEl1mE12NE2aT/P4WX1rDZjrEFwHQ3ZjrEFwslyy:VoKmbbabN1rDVEFycVEFL
Yara None matched
VirusTotal Search for analysis
Name 277b7774cba5ffd4_17a12ed0f8.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000016001\17a12ed0f8.exe
Size 249.0KB
Processes 2820 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 596e36370f12c4b25ae83ca524ded51c
SHA1 fe851eb1970ded01d1c2109fd04c2a04c5972642
SHA256 277b7774cba5ffd4ddee993048d329995ce4d1c12246a45484c1765743323baf
CRC32 EEAAA833
ssdeep 3072:7B56ePzvBTK3aa6wex65zP8RrCz7tfL5ClsTM7Mq:9UePrBTFwex610Ruj4l+x
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 111b4ffebccba2bc_ed748d2a-8ada-4d33-884e-e2fb34e8f309.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\ed748d2a-8ada-4d33-884e-e2fb34e8f309.dmp
Size 97.4KB
Processes 2216 (firefox.exe) 2604 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Mon Jul 29 05:03:15 2024, 0x820 type
MD5 31fdc44f6ae6e0cc961e1d3bd169f02b
SHA1 a9f4ef64fb15794c58f6993b60487fb40a235f7f
SHA256 111b4ffebccba2bc4b7fff7d95d4089b0a1016ebc914ee5af67dc31c25f565c6
CRC32 41B36372
ssdeep 768:gyfgrltLouo4DCDRLYrZqMS9BjSSV3w8bPmjeAPR62jT:gy4foEF8MS9B+SVg8bPEr
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 110e3165f222815d_submit.log
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\submit.log
Size 392.0B
Processes 2604 (crashreporter.exe) 2668 (crashreporter.exe)
Type UTF-8 Unicode text, with CRLF line terminators
MD5 ccd805840cded029048a03d89bc3c01e
SHA1 e709be542d5383e01608063b8435bf77a0806484
SHA256 110e3165f222815d6f11f6cb99a3fa5d57038828beef8ab1e16db23c8289757a
CRC32 3CE8135A
ssdeep 6:g/sVB5d6QwHdlQP/sVB5d6QwHdlQPSTd6QwHdlQPSSj4md6QwHdlQK:bB5gQw9NB5gQw9FTgQw9FSEmgQw95
Yara None matched
VirusTotal Search for analysis
Name ec86dff13ec188e0_startupCache.8.little
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\startupCache\startupCache.8.little
Size 7.4MB
Type data
MD5 c9fdf6ced10ea267f5e1e7d6cb4b467c
SHA1 181148adeccc66362e241a8f434ea384daa5f27b
SHA256 ec86dff13ec188e0afcec1f59397551e7072a12b24d6a20dc91b3e9705a63e4e
CRC32 F1DD0004
ssdeep 98304:XxxN8Jzl6VttNx8UoxmuWR2FPGjD79MJRGD3j/s3:Xl89lMz/FuW+6D72iTk
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis