Dropped Files | ZeroBOX
Name 4b23cbb62c6cc1fb_aaawave.exe
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\AAAwave.exe
Size 340.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7fc0de527b0a1c2b0c9b73a3891ae723
SHA1 a7130a02b9951a76a80579030dc046a56559b1bf
SHA256 4b23cbb62c6cc1fb316c27fa97c53d7e59896ae591e435949fe7108316ba767f
CRC32 2171A496
ssdeep 3072:EAn9q9vvgWDphf5IJArlXkzQ9Pa+SrfNI2vi/kePGNl8xOwZ0En7167Jlq1Vm14v:79q9v95I4JUi1GNle01VZetY5K
Yara
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name fe3994ee13aac19d_aaawave help.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Worlds\AAAwave\AAAwave help.lnk
Size 1.1KB
Processes 2540 (InstallAAAwave.exe)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Sat Nov 1 20:48:16 2003, mtime=Sun Jun 30 05:03:43 2024, atime=Sat Nov 1 20:48:16 2003, length=936830, window=hide
MD5 5654f5343ce38a2c03fd50f7df671331
SHA1 c9c6ab3c9976faeed1be81c265cb4654db954dfb
SHA256 fe3994ee13aac19dc72dbbaaa7c227ed70ddc6ba95bac12c7780a9ce0919899c
CRC32 DDDD05D0
ssdeep 12:8ici3ArXKcGdp8DCDU/rV0pkd+k8smUtZgYt5IjAAcZTBTASIJbdpYCjOfeBNU98:8gdOEK/rrCwOAAWTid1dpjNUPPyd
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 7d59a8cc7a5c16b3_richtx32.ocx
Submit file
Filepath C:\Windows\SysWOW64\RICHTX32.OCX
Size 198.8KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 722435ba4d18f1704b43e823a12e489a
SHA1 48f3c6e2e14e397055b667e2c8baa85177eb6d44
SHA256 7d59a8cc7a5c16b3b0e0e67c65cf98c45158909f95ca3a5c96b946fdee42c095
CRC32 A5404022
ssdeep 3072:2ZyQLz5i+ES6n2xmV8HlHWuYap8WRN7skMqB/s9FdgJUXsedjuokSER/UmL/W63m:+/i+EbsI8HgNWRNGq+FdgJU3/j6pKrd
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 64c6ee999562961d_comdlg32.ocx
Submit file
Filepath C:\Windows\SysWOW64\COMDLG32.OCX
Size 137.2KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 b73809a916e6d7c1ae56f182a2e8f7e2
SHA1 34e4213d8bf0e150d3f50ae0bd3f5b328e1105f5
SHA256 64c6ee999562961d11af130254ad3ffd24bb725d3c18e7877f9fd362f4936195
CRC32 5BADB463
ssdeep 3072:3ESIiWD8uq4hCqUt6mqD1gRshBgH/voqJrwo2CocrJbQN6N2TRqEydzdHv2:3ETz566VgRyOJ0oDxQRHH
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 1e0176f6e6982dbb_enu.lng
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\plugins\0\lng\Enu.lng
Size 4.8KB
Processes 2540 (InstallAAAwave.exe)
Type Windows setup INFormation, ASCII text, with very long lines, with CRLF line terminators
MD5 ba1b10ebb24772a31c5938c87a97bd60
SHA1 d246aef7d34f8876b676cd9b1e6f7a9682790642
SHA256 1e0176f6e6982dbb83a3302fa26d56b572e6e9cc559e05916c85252569d04370
CRC32 6105325A
ssdeep 96:p+E/OAWSlNjAGvSPiPtVCRO5D7Eu0beMhFEhP74hgw:p1/BllNEMSPilKO5D7EthQMhJ
Yara None matched
VirusTotal Search for analysis
Name da8f749fabca0956_vwlicense.dll
Submit file
Filepath C:\Windows\SysWOW64\VWlicense.dll
Size 84.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 a554fac505a4916fb8a43ea6c08f3e3d
SHA1 e19d0da58d2454e27028eaaaf8c56ea645fa586e
SHA256 da8f749fabca0956bae5022174d1c8908965194231404ad2ce42c2420f44bf61
CRC32 9A81B109
ssdeep 768:EJUIrWpYaae7wxU9OR/azGZBY+KNselRzwadMiZiNu5tIEb7YTxpKNkebpsx2:Yabaewx1ZZK+KN7wadUNu5sSNnNsx2
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name bd489b5946396b23_resume.exe
Submit file
Filepath C:\Temp\1KE80Q1B\Resume.exe
Size 122.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 97ea7d61b3069d5d1ed3a5276a57fc74
SHA1 35b43df338935062e34e8bc780fc0a7f8f131aa2
SHA256 bd489b5946396b235f695008ae0623dee18d8326c0dad7da71298dc773297b72
CRC32 60D6ADD7
ssdeep 3072:mECoRBpZJxmXMvp5zWODkOOkAAafNVUGE0HJRRby9+5:mECGZJxmXMRp74LkJONV40
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name f4f97c2a2963032c_aaa wave.lnk
Submit file
Filepath C:\Users\Public\Desktop\AAA Wave.lnk
Size 1.1KB
Processes 2540 (InstallAAAwave.exe)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Tue Nov 4 20:14:26 2003, mtime=Sun Jun 30 05:03:45 2024, atime=Tue Nov 4 20:14:26 2003, length=348172, window=hide
MD5 6adebf0f4487f3be218535811fd0f9bb
SHA1 d8784b102b28a22511198cb792a1a49e41e11648
SHA256 f4f97c2a2963032c20fc4ecf4a6957d2649d09071641a549c1649b43615e055d
CRC32 852CBA91
ssdeep 24:8BoedOEK/rrQzno9uCAAWTwl5dpjGUUPPyx:8BoedOPncnJhAW0l5d9Ghnyx
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name ea29d5dd15aca3db_uninstall.exe
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\Uninstall.exe
Size 194.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8376735d14dee1837988d44e83df129c
SHA1 e231249ba0a677655631950e1ac19a382252c4d4
SHA256 ea29d5dd15aca3db7a445c08202ddef8a2a7ffe562bf06f0a86a82cc15bdef7b
CRC32 8A4A0C83
ssdeep 3072:TdvRSTPLkxPeuDHk24UtgyDqWVOLH1JB4XuErH8uTQBu8RBX:T66E2MOqWVOLHJmrcu4u
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name e453b3733b2a0dc1_unpack.dll
Submit file
Filepath C:\Temp\1KE80Q1B\unpack.dll
Size 34.5KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 14f73839452c4e55a15c7a92cf394719
SHA1 eb0a20072c3471b18cbc30ab1e379e15680eb674
SHA256 e453b3733b2a0dc178bbfd065a24592fa1d9779c1d85adfd769ede98e6ef6230
CRC32 ABA235F2
ssdeep 768:uD2qpLe1eKwW9IyeQ7sn4sHPNk4L1eDHIfauPwZ6WPYBKn:uqqU1veQ7uZFvReLEa+A3
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 0ae04a940e426574_seamlessverysmall.bmp
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\presetup\SeamlessVerySmall.bmp
Size 24.7KB
Processes 2540 (InstallAAAwave.exe)
Type PC bitmap, Windows 3.x format, 125 x 67 x 24
MD5 dc7b513d2e38128899ab7504c7265fdf
SHA1 bcc3bebf8c5c08ba9e1fe9932de1955c8c337ca4
SHA256 0ae04a940e4265743d38f4b6cbefcd1bd512a003d977f7bef1e7bb92d9eb1ad2
CRC32 46F9B430
ssdeep 768:PAkqFCTGONyl0xzvFRlPNFtMEv6peqLwHTldKXlIhSqx8Y:PvqsR+0xbNpX6p1L0TfKXiR
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 00b598e9c86811cd_tutorial.txt
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\Tutorial.txt
Size 56.5KB
Processes 2540 (InstallAAAwave.exe)
Type data
MD5 a894e95d5c12d340793b25dbe36a8eb7
SHA1 761d463b6e5e06de517a26135bdd9c7db2fa9c8c
SHA256 00b598e9c86811cd2ecdff93b5eba9cd6e7bba1b90a68db5a1a3c7e3e7550970
CRC32 EAAE59D9
ssdeep 1536:Wybt889gva+Ywn31a0noek+D9I4xc3SZ8c0q:m15nOK
Yara None matched
VirusTotal Search for analysis
Name 4600e337e68cdcf7_presetup.bmp
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\presetup.bmp
Size 13.6KB
Processes 2540 (InstallAAAwave.exe)
Type PC bitmap, Windows 3.x format, 300 x 250 x 8
MD5 65668961b4585f1564eb5bbf3b40dcde
SHA1 8966cd3903c4ba85dc3855f3c26ff720e3bbb369
SHA256 4600e337e68cdcf786b193e3d28ea5934576f8b7b3bee6241177eca56c6cea4d
CRC32 CCAEBB90
ssdeep 192:NCzldtfPXhwp/pjWMa6Zw+K1cCLcy3sg+8nff6nXsv7K1efI/OSAFXsPV:NCzlTPOpBap+DycgxnX6nXsvLePV
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 368f3db48b70eb9c_main.pdb
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\main.pdb
Size 1.2KB
Processes 2540 (InstallAAAwave.exe)
Type data
MD5 33385ba57edd35100862714b4cb560a8
SHA1 3606806f816f25537c95d223e5585a3c723a740c
SHA256 368f3db48b70eb9c2dda2586ca51ab21ce94e472484b22bd552f3f2ffed0c760
CRC32 54F5A7E7
ssdeep 24:YW2LRBsmYpoosdMR4EaQbKSLyhnG1vDe/yniaYMwmkWTIzcj/:eLRxooosdMR7bcQ5e/AiL6Z
Yara None matched
VirusTotal Search for analysis
Name 2b7a1f905486736e_mscomct2.ocx
Submit file
Filepath C:\Windows\SysWOW64\MSCOMCT2.OCX
Size 632.7KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 c1b4af41a0370e4081d59ac99bcc929d
SHA1 c0c55de97f41a24bf50b2d08eb428371bb4a3cce
SHA256 2b7a1f905486736eda8b51add1bc2590c2a6d9d5a9ab7565335d989f39c0eb8e
CRC32 0E9FACA9
ssdeep 12288:qxxeCsfuxdH8ZOlK/kV99RWiVwyzgAQk9yjWy6OcjKN7jsUseUbQ/D5v:qxUCwwd7T9fWQgAQkEjyOcjKJsUseuQF
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name fcbaf18adda48dcf_splash.bmp
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\splash.bmp
Size 13.0KB
Processes 2540 (InstallAAAwave.exe)
Type PC bitmap, Windows 3.x format, 393 x 66 x 4
MD5 e753ced2dcd33f0af5cf219195a6e976
SHA1 936af4df7ad616e838fc369a83e3ff731561dc7f
SHA256 fcbaf18adda48dcfa57f46e53fdd9985c247bb62f5afe6fe8cf14de2285fabe8
CRC32 CAEDCC05
ssdeep 48:/SZ0Pz11QkOp1Dn91tBmXdq1gYYNTYHYmh:/SZE11QkI94/YIY4mh
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name ad53bd42cfd95b34_splash.rgn
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\splash.rgn
Size 11.6KB
Processes 2540 (InstallAAAwave.exe)
Type data
MD5 bfbe8d8e2537826c76efeca8ab57ea43
SHA1 8f26047e1f5098765211e61afb59551d578a7136
SHA256 ad53bd42cfd95b347d8666659ccb35fc3fe1057a09e742d769fe25130a1c77ba
CRC32 66747CE7
ssdeep 192:LiQ8WkrfQeRh2LFnpklXylJCo9RK8zDuQ7u6PvSSLjhN1lrOuNuiIgmc4Vg:HYTFyFneV2s6jz9u6XxfDr7NuiIgmk
Yara None matched
VirusTotal Search for analysis
Name 0e51cf63515d3906_license.txt
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\presetup\License.txt
Size 6.4KB
Processes 2540 (InstallAAAwave.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 182a0413dd3abdc678161946b55ff111
SHA1 8faf2b37fd24b91ca05a4b5c171688ff5a70088c
SHA256 0e51cf63515d3906057f058545453cf54b4b77012c888eb84b63f6869eaed4ca
CRC32 353F1154
ssdeep 96:Y3LiCXl6+SUzdOsz+e78A0QHAR7nlqOpfzRfbKWIcKL7OSubRqn8h3f9X:69SUzdt+egA78DAOptgJPEFq8hVX
Yara None matched
VirusTotal Search for analysis
Name 58623415fa9c6cdc_dx7vb.dll
Submit file
Filepath C:\Windows\SysWOW64\dx7vb.dll
Size 588.5KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 16913af40beee13f9b2874c349e2941f
SHA1 2fa172c74e783557d4f18372e436e1224de522f6
SHA256 58623415fa9c6cdcdad238f486b796298499e129ffc3aa9390b05eec4794a0d3
CRC32 315E5C4F
ssdeep 12288:DgvoPMy9NpLXcJHSY8I4mE0fzduc7rSiHwneHZHvlXst+c99xZRKKWdlqaBuJt5e:DSOHG
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c4d75385128a72f6_enu.lng
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\lng\Enu.lng
Size 5.5KB
Processes 2540 (InstallAAAwave.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 79f71c56a73e779574c62468a3dcf623
SHA1 ba96056fc4dc4beb7c4cf5a0d780df76a38f7940
SHA256 c4d75385128a72f60d372389943b7e8c0eba3798f53e475803b8f8fde0382b51
CRC32 CFA98FF7
ssdeep 96:ao8GLaWD/88KW/rJWT9+2oLngH5HgrF/1KMdnDsl89HjDYz/3DfQB6DslTs2XmAj:18GLaW7GqAT9+xLgH1grF/1KMdw8RjD1
Yara None matched
VirusTotal Search for analysis
Name 5e9daeac8e430274_readme.txt
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\presetup\Readme.txt
Size 572.0B
Processes 2540 (InstallAAAwave.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 47b5199df19816de36750b405e73b17a
SHA1 007fc8ab39eac9f319eda24c137a977c400556c1
SHA256 5e9daeac8e430274a854a0b300802fc8e406b0350433ebb1d95044e84f85964d
CRC32 04956781
ssdeep 12:ZKGLRDpWCC84Gcltt9ysMDJmWH1JsTNiMXegoQuLNmrKA2AlttVs:lCZ1ApIiuDE8H2A1Vs
Yara None matched
VirusTotal Search for analysis
Name 345e636f29dbbdfa_hdk3html.dll
Submit file
Filepath C:\Windows\SysWOW64\HDK3HTML.DLL
Size 40.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 dba28cdf7a36fa280830d6a0ef9d210a
SHA1 0aef935def8fef9a019dcaba3e479b728ebbb65b
SHA256 345e636f29dbbdfad4be2582fc5740b39fb012735f00e7bf539b1185615f4931
CRC32 8155CF81
ssdeep 768:Z8d3K1rD7We2duijOjATh9JjB/RfV8RMgtqoWO+h3+:Z89cS7IjATh9towQ
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 2576ef477613d51a_aaawave.lnk
Submit file
Filepath C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Worlds\AAAwave\AAAwave.lnk
Size 1.1KB
Processes 2540 (InstallAAAwave.exe)
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Archive, ctime=Tue Nov 4 20:14:26 2003, mtime=Sun Jun 30 05:03:45 2024, atime=Tue Nov 4 20:14:26 2003, length=348172, window=hide
MD5 742bff6ccb7e4a6e654597fa2f661c16
SHA1 187ddb9e590e8bb52801b0bd71aae1ccc02e05f0
SHA256 2576ef477613d51a4b0585f2f2546b2a8c486b81ee02e1f6d2af068c015d4fda
CRC32 A60B1C98
ssdeep 24:8BoedOEK/rrQzno9uCAAWTwlNdpjGUUPPyx:8BoedOPncnJhAW0lNd9Ghnyx
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format
VirusTotal Search for analysis
Name 387faea7fe4732e3_stdui.dll
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\plugins\0\StdUI.dll
Size 142.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 394075f8529332b8e292f645cfcc50e3
SHA1 c1fc22f5be3761ffee82993f8c586260dda12e63
SHA256 387faea7fe4732e378702b79bb8390345d5f334fd1122da313706b4e04bbb7bb
CRC32 F35058A2
ssdeep 3072:5e/6K/TmVAVWBqZMUOIwkWuB9qmNkRnmrkfVX:5e6KSUOqW+q8kRnMkf
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • mzp_file_format - MZP(Delphi) file format
VirusTotal Search for analysis
Name 155c75cc4e9ce0bb_db.pdb
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\db.pdb
Size 5.3KB
Processes 2540 (InstallAAAwave.exe)
Type data
MD5 525655a02df7f6b9c3bf882402f89706
SHA1 d7e91119203be10562bc435a750c34d6487ca599
SHA256 155c75cc4e9ce0bb4efbb0990235ae04378c12250f0a55a300fbe456c15eb5c1
CRC32 15A96C3F
ssdeep 96:051fPVvADchb32pIDZK3SKYfmcUHIumR8ApOjHBvHUe4NUMU9oV9h9Iw46n6e7Xs:051fPV00xM3fFcsxmRhMDdUexq9ha15R
Yara None matched
VirusTotal Search for analysis
Name 76ac268396f4bd01_hdk3ctnt.dll
Submit file
Filepath C:\Windows\SysWOW64\HDK3CTNT.DLL
Size 272.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 56d9924fed25ea636a29e5291799da0c
SHA1 40eb1774454455f377b94a6ffe751aae34b5114f
SHA256 76ac268396f4bd014d15a0084f297543609c834accf88eb58767d13fb2be7fa8
CRC32 D7CD6EC6
ssdeep 6144:2/I9d4ACLO5yua9Ror+M/Nmn5CiVrsQTpu4N7Y+vIl:QI96li5yuF+M/Ng5rSQTpN7YmIl
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2f1aa25df978af88_install.sss
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\install.sss
Size 487.0B
Processes 2540 (InstallAAAwave.exe)
Type ASCII text, with CRLF line terminators
MD5 1b9c77eb1bb2a200ffaf2606b37e486a
SHA1 84e6071f7885bb9b81d2a237a6c37602fdfba62f
SHA256 2f1aa25df978af88d6e05661d4477aab8da9ff2f9e5ffdb3427bab89f8ca3177
CRC32 481CC3F0
ssdeep 12:NlW+QlacZTBTi9L1XgfZTBTi9LWUlmdzWEl3WMl3WTN6XhjlI/HK4u:vXnWTM9L1mTM9L6dzB1zxi/s
Yara None matched
VirusTotal Search for analysis
Name 37739aa44ebb8144_aaawave.hlp
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\AAAWAVE.HLP
Size 914.9KB
Processes 2540 (InstallAAAwave.exe)
Type MS Windows 3.1 help, Sun Nov 2 10:48:15 2003, 936830 bytes
MD5 932d12f0943d263c503f46b6e16ced44
SHA1 72999fd36f0a346de857ce17cb1c340e0023f615
SHA256 37739aa44ebb814428b0d35943ca999c18093159f0b8a70c94506b814d1c1f1a
CRC32 391096F2
ssdeep 12288:uV+c2loZawcFEKEosiD8giD8xlI5gRkuRL5fZOFqaX3hT/flsjJa4I4OI9gXu4D2:uV+JloZawcFEKEo6jo
Yara None matched
VirusTotal Search for analysis
Name f3e44e40ca64e751_vwcontrols4.ocx
Submit file
Filepath C:\Windows\SysWOW64\VWcontrols4.ocx
Size 848.0KB
Processes 2540 (InstallAAAwave.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 ddb253fd3d1ec0d0f2a19a2e3418d20d
SHA1 b61fd2714682f42ef6cd510945efe230e5c9a8a6
SHA256 f3e44e40ca64e751b03e97d861d674397ee689efcb44d0c5fc34cae4a3b0195d
CRC32 29568BD1
ssdeep 24576:hkvwaI9c8blJOf5IDu9gFFZxHSP7qARv+xTD8K:hIwapOu9gUv+JT
Yara
  • DllRegisterServer_Zero - execute regsvr32.exe
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 480ddf3da6509ac1_aaawave.dat
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\AAAwave.DAT
Size 160.0B
Processes 2540 (InstallAAAwave.exe) 1560 (AAAwave.exe)
Type data
MD5 54c4572426b1556c3b4dd2aa3bf1a592
SHA1 6e0f401ddb8053e29478cdc65943012a5c00cd76
SHA256 480ddf3da6509ac1843382c871843e9f0539649a65248f077ffbaebed7ff8933
CRC32 AD13F553
ssdeep 3:g/D//0l:9l
Yara None matched
VirusTotal Search for analysis
Name cc0b0c69fb12cba8_presetup.rgn
Submit file
Filepath C:\Temp\1KE80Q1B\InstallAAAwave\presetup.rgn
Size 1.1KB
Processes 2540 (InstallAAAwave.exe)
Type data
MD5 172eeccf4687e172e12a1b4ad3023e9f
SHA1 2b74254b4426b38932748aae109ddd1635ee7261
SHA256 cc0b0c69fb12cba8230c363bf63809ac1b8c8695a533446c87c86d9f8643c8c7
CRC32 B4A8F6D3
ssdeep 24:aRs5ObA7/5z8kTtg3wgoQ2FbE0Dth6Jb8usJQgR/UiC4K:xU+zN0/oQ2LthebeQO/o4K
Yara None matched
VirusTotal Search for analysis
Name d637f912b60df407_install.log
Submit file
Filepath C:\Program Files (x86)\Virtual Worlds\AAAwave\INSTALL.LOG
Size 6.0KB
Processes 2540 (InstallAAAwave.exe)
Type Windows setup INFormation, ASCII text, with very long lines, with CRLF line terminators
MD5 229fe43ec230717244464ca1f1cb934d
SHA1 f67ceb27a69eb13e38a1dbb7b2e51a2de0124f78
SHA256 d637f912b60df407852499c26b044512e2f78307cda1b481765ed3b69da71e19
CRC32 400C9138
ssdeep 192:U9+xLjiEizZn1KUdVJjDYH/bABlsN7f2IC:U6GzF1JdV6H/qALY
Yara None matched
VirusTotal Search for analysis