Dropped Files | ZeroBOX
Name 2ae4169f721beb38__isbunzp.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-I0H8J.tmp\_isbunzp.dll
Size 32.0KB
Processes 2592 (INSF01C.tmp)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 b4786eb1e1a93633ad1b4c112514c893
SHA1 734750b771d0809c88508e4feb788d7701e6dada
SHA256 2ae4169f721beb389a661e6dbb18bc84ef38556af1f46807da9d87aec2a6f06f
CRC32 6FC55B73
ssdeep 384:jT0DmlTZXYYCJWJqzg9kT8gbtNYvRPtAsLiA:jT0DmltXYYCJukT8gPoN23A
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name a44707ed7ababc6c_insf01c.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\INSF01C.tmp
Size 377.0KB
Processes 2540 (dssdj.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ef80f42a048f92263f758f14b09fa30d
SHA1 e250058636dee689d6a935d71c0f462e10457239
SHA256 a44707ed7ababc6ca81355e9a6afe0e5095d01f1c72ef7b37681447036da518e
CRC32 B9629542
ssdeep 6144:LOgfnd1GoWW6J45g8NZRsNVNammG24+KKZN1GrUoaMLfzGJu:ygfLv1pO24+/bGx
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 9884e9d1b4f8a873__shfoldr.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\is-I0H8J.tmp\_shfoldr.dll
Size 22.8KB
Processes 2592 (INSF01C.tmp)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 92dc6ef532fbb4a5c3201469a5b5eb63
SHA1 3e89ff837147c16b4e41c30d6c796374e0b8e62c
SHA256 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
CRC32 AE2C3EC2
ssdeep 384:+Vm08QoKkiWZ76UJuP71W55iWHHoSHigH2euwsHTGHVb+VHHmnH+aHjHqLHxmoq1:2m08QotiCjJuPGw4
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis