Dropped Files | ZeroBOX
Name 695d87f880e40ddf_714ebb42-5311-4f11-93fe-3625f15d0edd
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\714ebb42-5311-4f11-93fe-3625f15d0edd
Size 3.3KB
Processes 2600 (firefox.exe) 2288 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 bcf500cda747fd8f65a1addf014927b3
SHA1 9fe20114d00af3e9b061d4e1f22e9fc2822f2b54
SHA256 695d87f880e40ddf641f7a6a09673204346f6601a756e1c8a48d16c417358ae4
CRC32 A183A1C3
ssdeep 48:hQo2QQHhrL1mKNNjyi54SiUeRMgQnKCzk+CFLULcP1tPDoBydvV/vJfov1JX6F5i:yo1YrBm4pr5rCSZnC+LUUBydddGwo
Yara None matched
VirusTotal Search for analysis
Name b0bcbebba3f0a4b7_scriptCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\scriptCache.bin
Size 9.2MB
Type data
MD5 7fcd6694c7418071bb6f0e1c879bf833
SHA1 022fdf4208fba1c4dd34c6bb1444591529509cf2
SHA256 b0bcbebba3f0a4b75f692e5c955707ad67e4312590330b97e987638eb72d0b11
CRC32 46CB710E
ssdeep 49152:SfNsfR/eXfWVAoIgPm6t7eh+3R8ViGUrilbASvzmj/YDNM3eckIOehICZ3ZkF:SfNyYOVi6Fa2vraASvz6GMu2hIF
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • RedLine_Stealer_b_Zero - RedLine stealer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ac5c92fe6c51cfa7_nss3.dll
Submit file
Filepath C:\ProgramData\nss3.dll
Size 2.0MB
Processes 3048 (356feeff4e.exe) 2104 (minidump-analyzer.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1cc453cdf74f31e4d913ff9c10acdde2
SHA1 6e85eae544d6e965f15fa5c39700fa7202f3aafe
SHA256 ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5
CRC32 7DC07205
ssdeep 49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8e5ccfd0800ba82f_explorti.job
Submit file
Filepath C:\Windows\Tasks\explorti.job
Size 274.0B
Processes 1676 (herso.exe)
Type VAX-order 68k Blit mpx/mux executable
MD5 a69641ecf96809bc3bf5f5b2f328b522
SHA1 76a64f8645b15716e049a2a447e685a2dde248ed
SHA256 8e5ccfd0800ba82f21cb21ca7c1bac71305052b18f9baa5c454a3c077b1dc1ce
CRC32 8DBE92D4
ssdeep 6:EWHDXE/Xm/UEZ+lX1cI1l6lm6tI4y0le/Cct0:5HDkW/Q1cagc4V9ct0
Yara None matched
VirusTotal Search for analysis
Name 63e02015af0699aa_scriptCache-child.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\scriptCache-child.bin
Size 824.1KB
Type data
MD5 19421dc0192e633eec157df491fd8c13
SHA1 adeb399426e11cb6de823cc8f5269e9f2f3e657f
SHA256 63e02015af0699aa0c1a90951bd36f1f62a10746c7e5eb004e29d27d3d80ab23
CRC32 C98B88C5
ssdeep 6144:jLv50b7rtyuRMAMgDh6QbZpZltg2ebfhAFgMWM/OB48SuTSBWobB2PLtPkZ:X5ctdD15PgMWM/OXnSBWob4tcZ
Yara None matched
VirusTotal Search for analysis
Name 5136a49a682ac8d7_msvcp140.dll
Submit file
Filepath C:\ProgramData\msvcp140.dll
Size 439.5KB
Processes 3048 (356feeff4e.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 5ff1fca37c466d6723ec67be93b51442
SHA1 34cc4e158092083b13d67d6d2bc9e57b798a303b
SHA256 5136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062
CRC32 FE675AE5
ssdeep 12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
Yara
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14_cookies.sqlite-wal
Empty file or file not found
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite-wal
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 872ea10c56fbd7ee_explorti.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0d8f5eb8a7\explorti.exe
Size 1.8MB
Processes 1676 (herso.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 54dda3a0f0895906ba57a691a4655415
SHA1 079bb6d2069c1f09d1798ddbb1b81e37d8d8ed54
SHA256 872ea10c56fbd7eed22a86a03387e45213bf90e7e85df771b0a747075a4fa004
CRC32 E33B1C81
ssdeep 24576:j7I25TWJuUpiD3iaFXJubX9iOQkZ1+G0n/v92SJojo1aS/pxPZxSN11INelXUt14:YyTvubXkO8G0ndD/nZ4WAlEtKgSLCrI
Yara
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 824fae3331b95e2f_CFBAKKJDBKJJJKFHDAEB
Submit file
Filepath C:\ProgramData\CFBAKKJDBKJJJKFHDAEB
Size 40.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 41c19a9e8541fcb934c13c075bf47721
SHA1 648a7622d533d79b9a0bb31dc370134ec3a75ed7
SHA256 824fae3331b95e2f88ca60c87a6c9569086906ec76fc1db8d6dee9adddc4e80c
CRC32 560F7642
ssdeep 48:+35TqYzDGF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:Ulce7mlcwilGc7Ha3f+u
Yara None matched
VirusTotal Search for analysis
Name 169c04331f72fe4a_FIIIIDGHJEBFBGDHDGIIIIJDHJ
Submit file
Filepath C:\ProgramData\FIIIIDGHJEBFBGDHDGIIIIJDHJ
Size 5.0MB
Type SQLite 3.x database, user version 53, last written using SQLite version 3031001
MD5 f77930486de1b1bb4b397d5d8f3cd124
SHA1 e3f5727a0774c7cba17f0b10569012dcea24cb55
SHA256 169c04331f72fe4ae9958da09e1b28ec5910f7ea523d6105b7e4ad521b2baaee
CRC32 D85072F9
ssdeep 96:Dm8j5PnH6xY2Wi+67tH2iB4q2xfX7ZbiZzdFzb4PPwI3A7:l5/IYOTAlQzdFzaDm
Yara None matched
VirusTotal Search for analysis
Name d9798bda5b0cd389_356feeff4e.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000038001\356feeff4e.exe
Size 187.5KB
Processes 2232 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 59eefb04a8cb9a94d148464cd4324e93
SHA1 e1e550383c9de11d18bb6cb5b8d83f62f51340bb
SHA256 d9798bda5b0cd389f0b0f184ded085cded77a8652d96be4054789452b2a04ca5
CRC32 5ABA1087
ssdeep 3072:Uk9U0KFj5qj6o8KaxfE54HnnGqaKl+b2n8OZD4LFmpKa:Uky/j5K62aOanGqCbAj4LFAKa
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name d820603eb308a436_CGCAKKKEGCAKJKFIIEGI
Submit file
Filepath C:\ProgramData\CGCAKKKEGCAKJKFIIEGI
Size 12.0KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 0647d44f50372ccfa8f1e56b37e9fe76
SHA1 5e7fac4675932c1faa55f925c958ca1c75324a20
SHA256 d820603eb308a43651cc248106d188c1602f5de460de659300721f03cd863dbc
CRC32 A8996995
ssdeep 192:O6nHM58sK1zjyPySpI+JpVgxXhKQuylvICf/eEoBqIrv0bEHa+n:O6sPPZIcpmxO3BqIr0IH/n
Yara None matched
VirusTotal Search for analysis
Name f28d7550eaff9b04_feb1d719-5d37-4d6f-814f-ef095b02b421.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\feb1d719-5d37-4d6f-814f-ef095b02b421.dmp
Size 95.5KB
Processes 2868 (firefox.exe) 2060 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Tue Aug 6 05:58:19 2024, 0x820 type
MD5 ec49a6c5473654972564cf6c8e7a7005
SHA1 1df1e6e495a7d6c9db18f3cfe6f1acd05480b104
SHA256 f28d7550eaff9b046c13de9a1719f6b20dc80eb38c5c09e11a5d63bed82a4e4c
CRC32 B1B5F12F
ssdeep 384:dWlQsnv1d6ly3Chvyzmy7ADm9AxJ2vU34MNC+oYfbK6YLxMlt+A672rGLB0AfMae:dWlH1d6llUDADm2J21AK61jelfMah7w
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name fd4c9fda9cd3f9ae_cookies.sqlite-shm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite-shm
Size 32.0KB
Type data
MD5 b7c14ec6110fa820ca6b65f5aec85911
SHA1 608eeb7488042453c9ca40f7e1398fc1a270f3f4
SHA256 fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
CRC32 DDC506B6
ssdeep 3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
Yara None matched
VirusTotal Search for analysis
Name ab63fe23f686cb7f_854944f6-c863-4df9-957c-e39bb5ed1152.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\854944f6-c863-4df9-957c-e39bb5ed1152.extra
Size 4.2KB
Processes 1712 (firefox.exe) 2948 (minidump-analyzer.exe) 2076 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 618d04080817f1309e2efc1072b0ce11
SHA1 c9a0f90f93041eb11f6784cce3bb246b5be93c9f
SHA256 ab63fe23f686cb7ff3c1380cb34532a56022b0fe7843ea801cc97519b57975e2
CRC32 D1ED6277
ssdeep 96:DorpDc+duNYab7r5rCSZnC+LDGAydddDhD:DorZ4YELDGZTD
Yara None matched
VirusTotal Search for analysis
Name 011f27daeabcc245_854944f6-c863-4df9-957c-e39bb5ed1152.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\854944f6-c863-4df9-957c-e39bb5ed1152.dmp
Size 84.2KB
Processes 1712 (firefox.exe) 2076 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Tue Aug 6 05:58:59 2024, 0x820 type
MD5 5fd70391b7a5bb400816925db78e1482
SHA1 4484d45a07e3972f84284ef3e25bbdc0ac68dd6d
SHA256 011f27daeabcc2452d33b52e916cfa457dff761a790dcf31604862c154157340
CRC32 216DAB78
ssdeep 384:PZm5ly3FPmy0DAnj4oCpvwDOXlVO+Mhyxz9NyXnS1vl4:PZSlO8DS4oCBwDOXIyI
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 0b8607fdf72f3e65_FIIIIDGHJEBFBGDHDGIIIIJDHJ
Submit file
Filepath C:\ProgramData\FIIIIDGHJEBFBGDHDGIIIIJDHJ
Size 96.0KB
Type SQLite 3.x database, user version 12, last written using SQLite version 3038003
MD5 d367ddfda80fdcf578726bc3b0bc3e3c
SHA1 23fcd5e4e0e5e296bee7e5224a8404ecd92cf671
SHA256 0b8607fdf72f3e651a2a8b0ac7be171b4cb44909d76bb8d6c47393b8ea3d84a0
CRC32 842B3569
ssdeep 12:DQAwfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAwff32mNVpP965Ra8KN0MG/lO
Yara None matched
VirusTotal Search for analysis
Name 38f773d470fa94dc_714ebb42-5311-4f11-93fe-3625f15d0edd.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\714ebb42-5311-4f11-93fe-3625f15d0edd.extra
Size 4.7KB
Processes 2600 (firefox.exe) 2564 (minidump-analyzer.exe) 2288 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 9b1235f2ba108e55d3227e7d616f402f
SHA1 fa2908757432503f1f693622907571ace927ac24
SHA256 38f773d470fa94dc88cc4ed43c8a1874e0cd94040556bd6d2351555b6d455d7a
CRC32 DDE3B12B
ssdeep 96:DoXy2Dc+YbNYab4pr5rCSZnC+LUUBydddGwn:DoC1pYTLUUwJn
Yara None matched
VirusTotal Search for analysis
Name c119a54b6bef3a48_IIJJDGHJ
Submit file
Filepath C:\ProgramData\IIJJDGHJ
Size 80.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 255929949dea51a2f43a1f40e63764ec
SHA1 8f32ab419264fdad05f4f3828db3c1cd38d919fd
SHA256 c119a54b6bef3a48234950dc07fe70f73b69d1390ef0235e66481faa1048ead6
CRC32 F7A79605
ssdeep 96:5Bc7fYLKYZCIdE8XwUWaPdUDg738Hsa/NhuK0l0q8oc5PyWTJereWb3lxzasq9u4:5BPOUNlCTJMb3rEDFAa6E/
Yara None matched
VirusTotal Search for analysis
Name b87beb4bbc429f0c_webext.sc.lz4
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\webext.sc.lz4
Size 105.5KB
Type data
MD5 86f4fe26175341c830af0ae6353d41db
SHA1 a1449571cf2014cac60a7f3dd7cab8a55380be81
SHA256 b87beb4bbc429f0c98428686eb04b7692f12d53385ab5a3d324bf094bef0c29d
CRC32 D9310E97
ssdeep 3072:igI+rushnjZa9uB1StrmnZI1wwZPxUwwc9ifT:0+rNjc9b+Zet1S08L
Yara None matched
VirusTotal Search for analysis
Name 5cb00ed4dbf5bde9_6e18515bc8.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000036001\6e18515bc8.exe
Size 3.1MB
Processes 2232 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1cefacb92893a044ff7dfcd7fae8a09f
SHA1 dc5e35ba32f0c33cd45369e1ac3cc1238c1e8819
SHA256 5cb00ed4dbf5bde91ac1a4f30b84713fc7169954d179b5304f893f292e8674a3
CRC32 FFEE43D3
ssdeep 49152:5bO4ksLgwfj2LMwFFd/ibhxLH/PI2WAE9hJ8lxvLrmnL2I3G4TIEuiafW:5bzl3OMo6bHbP5vMM1rLI2bniau
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • EnigmaProtector_IN - EnigmaProtector
VirusTotal Search for analysis
Name c869e9d826b01eba_714ebb42-5311-4f11-93fe-3625f15d0edd.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\714ebb42-5311-4f11-93fe-3625f15d0edd.dmp
Size 95.3KB
Processes 2600 (firefox.exe) 2288 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Tue Aug 6 05:59:09 2024, 0x820 type
MD5 5bf06e38df73054d1516df122bc401ad
SHA1 3965b311ffb1cbdfd3871dbfdbb41a42e7ee1ba9
SHA256 c869e9d826b01ebac9edee226456901f15b78a9e40b2901082dc4477aacddce3
CRC32 71900133
ssdeep 384:iIFDrt1ily36dpSRbmyEnDrVgSdW4UHsbSU5dQ9l6JLQqYEC78bSSxIAnGh5lbK8:iIFV1ilib8nDq3HsbSU5Yl6hQv4xIa8
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name edd043f2005dbd59_freebl3.dll
Submit file
Filepath C:\ProgramData\freebl3.dll
Size 669.3KB
Processes 3048 (356feeff4e.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 550686c0ee48c386dfcb40199bd076ac
SHA1 ee5134da4d3efcb466081fb6197be5e12a5b22ab
SHA256 edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fa
CRC32 085C6D2B
ssdeep 12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ba06a6ee0b15f5be_mozglue.dll
Submit file
Filepath C:\ProgramData\mozglue.dll
Size 593.8KB
Processes 3048 (356feeff4e.exe) 2104 (minidump-analyzer.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c8fd9be83bc728cc04beffafc2907fe9
SHA1 95ab9f701e0024cedfbd312bcfe4e726744c4f2e
SHA256 ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196a
CRC32 28C04754
ssdeep 12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 88f9dc0b9a633e43_HCGCAAKJDHJJJJJKKKFBKFBAEB
Submit file
Filepath C:\ProgramData\HCGCAAKJDHJJJJJKKKFBKFBAEB
Size 512.0KB
Type SQLite 3.x database, user version 11, last written using SQLite version 3031001
MD5 dd47ebe6866ad2ab59d0caa1de28d09e
SHA1 afdf6eb7a01bb7ef4c9d768b65abbbeae5ba2663
SHA256 88f9dc0b9a633e43c6d2c6fae136e782c15aa38c1601dcff948987f1c2a391c3
CRC32 8DEE9EEA
ssdeep 24:DQHtJl32mNVpP965hKN0MG/lZpNjCKRIaU5BnCMOkC0JCpL3FYay:DQfrbWTTTqtStLm
Yara None matched
VirusTotal Search for analysis
Name fae77250fcf99828_feb1d719-5d37-4d6f-814f-ef095b02b421-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\feb1d719-5d37-4d6f-814f-ef095b02b421-submission
Size 73.0B
Processes 2060 (crashreporter.exe)
Type ASCII text
MD5 e7b0de08235d2ebc5d839cbb80ef66ea
SHA1 6b76cd7316b68ddecbe35c1b37aa2391a20517a8
SHA256 fae77250fcf998284cade3bb253da60b40be3b914f460f55722bdaec40ce8a2f
CRC32 5D3DE9E3
ssdeep 3:RIRL/zLbuc0BnuVGhHVnJHvn:eFBlUh1JHvn
Yara None matched
VirusTotal Search for analysis
Name ef783e4448617850_lastcrash
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\LastCrash
Size 10.0B
Processes 2868 (firefox.exe) 1712 (firefox.exe) 2600 (firefox.exe)
Type ASCII text, with no line terminators
MD5 87d7c7cb22f8f90210c9866e6208db19
SHA1 4d1c54c93a084bd9f6bc53d7391a6e22211ebedc
SHA256 ef783e4448617850fe8e41459f0369ee1b82971bf848a67003868b8a82713a32
CRC32 1A7BB27D
ssdeep 3:LHcLJn:rKJ
Yara None matched
VirusTotal Search for analysis
Name cecf59649ccf1d76_AECFCAAECBGDGDHIEHJE
Submit file
Filepath C:\ProgramData\AECFCAAECBGDGDHIEHJE
Size 8.8KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 07951590532d8114ea1caca9ed7e0a39
SHA1 7a4bebc2f20ead9546fa5749aafe739ad5f551de
SHA256 cecf59649ccf1d7668ad3c7119bf9b380d6d5c339d7f0faeb2f29f163fd3f3ee
CRC32 E3F3A320
ssdeep 192:ZDnijRILMMdaWaLbFlp/PuFbylfFw8AxSwSO:pmsy7wIO
Yara None matched
VirusTotal Search for analysis
Name 1d417807b94f958c_urlCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\urlCache.bin
Size 3.2KB
Type data
MD5 26c3ea73c6885eaea20b6a5a6280ce50
SHA1 32fb4a91b1f37d0228ff31c0f0d6c37a173e67f2
SHA256 1d417807b94f958c6a4069a9dedf24b001099a68936f8ac10ef7bc30a126af38
CRC32 7DB0ACAF
ssdeep 48:BAbHgqedXU753de/xJtISt3bqhJtgtkt0IbvVr9cHSWypBr/BWLaLWcbsyMJrls:BAMqedXUd3AIq3bucwbhcmVsXJr6
Yara None matched
VirusTotal Search for analysis
Name 8916fb1d76be83e4_JKJECBAAAFHIIEBFCBKFIDGDHI
Submit file
Filepath C:\ProgramData\JKJECBAAAFHIIEBFCBKFIDGDHI
Size 192.0KB
Type SQLite 3.x database, user version 4, last written using SQLite version 3031001
MD5 6b9c2ac2b5025e180231d8d38ece698c
SHA1 36f5cfe6ac59aaa7d7173555edeef5caa9bf61c6
SHA256 8916fb1d76be83e42cd2f7b41ee06706fe0adb936259ed7a7daa4dbcb4c51fcb
CRC32 95ACFD74
ssdeep 12:DBl/lkf12Of5LZWfY0xpMujuHWMu6N2OHjWOzMbdym/eRgBoQFmgW2FOmO6Mz6LX:DLlI1x7WxHaiSlMxosJF/Ezo
Yara None matched
VirusTotal Search for analysis
Name dc3f8281a2caaaa6_submit.log
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\submit.log
Size 228.0B
Processes 2060 (crashreporter.exe)
Type ASCII text, with CRLF line terminators
MD5 a16b3901f04e9b345e09e5d2cdeb5c74
SHA1 c0befcef1bf8080380247131bf8f92d2bd306f9e
SHA256 dc3f8281a2caaaa6dec147334044cdc258e6567a5aed734a235a292fd6db9990
CRC32 1BF2263D
ssdeep 6:pX7RId6Qw0HZAsCpYA6Dp6x8X7RId6Qw0HZAsCpYA6Dp7:9OgQw0eTGDpZOgQw0eTGDp7
Yara None matched
VirusTotal Search for analysis
Name edb006e05cfa8501_ECBGHCGCBKFIECBFHIDGHDGIEG
Submit file
Filepath C:\ProgramData\ECBGHCGCBKFIECBFHIDGHDGIEG
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 3f5ca3e29b1b60e298aeca0a32164c03
SHA1 f9b5ee59c31a3b06a6b8e476b22d2d7cf1fa8b66
SHA256 edb006e05cfa85015aa76c758d6298c279fd318cff0dbb286927c7ad45105488
CRC32 E1ACA097
ssdeep 24:TL2C0RlPbXaFpEO5bNmISHdL6UwcOxvo5:TYLOpEO5J/KdGU1Eo5
Yara None matched
VirusTotal Search for analysis
Name b0a8b4cbc8a92306_854944f6-c863-4df9-957c-e39bb5ed1152
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\854944f6-c863-4df9-957c-e39bb5ed1152
Size 2.9KB
Processes 1712 (firefox.exe) 2076 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 4a030211efeeecd6625a4f1dd39f8f0b
SHA1 f81b533fd33e8d3d261c6c74c1480b5a1e19222b
SHA256 b0a8b4cbc8a92306153dba507cfa6740c39048fad31bc79b2a53ed7787910933
CRC32 DB870CA3
ssdeep 48:VQo0QL9hePjyi54SiUeRMgQnKCzk+CFLULcz2xUAydvV/vJfXR3Jnvpvi:Oorve7r5rCSZnC+LDGAydddDha
Yara None matched
VirusTotal Search for analysis
Name 63b3bfc5a1b9e58c_feb1d719-5d37-4d6f-814f-ef095b02b421
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\feb1d719-5d37-4d6f-814f-ef095b02b421
Size 3.3KB
Processes 2868 (firefox.exe) 2060 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 b6e936399e42ecb0ce5901a8c57e38e3
SHA1 2cbb08e2e8c8c6e4fdd7e128851af498e58bb34f
SHA256 63b3bfc5a1b9e58ccae07cad519011a9507383cbbe7354dde6ad51907e075437
CRC32 F66CD4CC
ssdeep 48:LTQoyfQwJ9bhNp1gjyi54SiUeWMg4UKCPbCF2ULcPGh3ruqeryvCKvJ9BAvLxX4v:IoPul1cr5rlBtC7LlDmy6yBciB
Yara None matched
VirusTotal Search for analysis
Name 63f5a75bc6e48a60_startupCache.8.little
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\startupCache.8.little
Size 7.4MB
Type data
MD5 366cb8639aeb3f55c7d6999a7fbac41d
SHA1 5c763f6a53320c8282fa1c648111fd2e68d34145
SHA256 63f5a75bc6e48a60722f5b706b3f3953f8139e31c3d81eff92f8aad6943dac01
CRC32 CF035B97
ssdeep 98304:LXEV8Jzl6VPltC/8Toxmu5RTRPG/D79MJRGDx/s3:LE89l2mYFu5HsD72idk
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name cacb3b090bd98317_compatibility.ini
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\compatibility.ini
Size 200.0B
Processes 1712 (firefox.exe) 2600 (firefox.exe)
Type Windows WIN.INI, ASCII text, with CRLF line terminators
MD5 63f28ee6c5768202c31eaf82725b64c2
SHA1 edc0b0c87aaa262a0aba6e6b29b2c31cc04fcf39
SHA256 cacb3b090bd98317500f593712c4bf51b5197c7aa9e07b6e10cab50144339ff0
CRC32 D70ADABB
ssdeep 3:tZAQU6oEl1mE12NE2aT/P4WX1rDZjrEFwHQ3ZjrEFwslyy:VoKmbbabN1rDVEFycVEFL
Yara None matched
VirusTotal Search for analysis
Name f048ccac6781c9a5_8bc9ea3c13.exe
Submit file
Filepath C:\Users\test22\1000037002\8bc9ea3c13.exe
Size 2.5MB
Processes 2232 (explorti.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0cf98c250ee26096d91e5248b3721acc
SHA1 bc2185a5f73c3abf54eac03c11555d3f31564058
SHA256 f048ccac6781c9a52c029724c4b866febcb7b95187008be9c48be6d8c6b25cac
CRC32 9651E342
ssdeep 49152:P+BiS73lhaHsT3kqLBQNSJg/irxnhMbVp3H2y3sSROvGrUZDY:P+BiS7lYMT3/BQNSC/irxnhMbX3H2ycs
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • EnigmaProtector_IN - EnigmaProtector
VirusTotal Search for analysis
Name 46c89d49db878cd9_feb1d719-5d37-4d6f-814f-ef095b02b421.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\feb1d719-5d37-4d6f-814f-ef095b02b421.extra
Size 4.6KB
Processes 2868 (firefox.exe) 2104 (minidump-analyzer.exe) 2060 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 8454699d76395c38015d3fc77d488404
SHA1 2dbe2ba2c73679d0117d55026e28bbe22ad83f8c
SHA256 46c89d49db878cd99c6ec15517b9ef233516c65ee62a00b5865ff9abd6f73bd4
CRC32 B8DA3A0A
ssdeep 96:DodMMDgEYbNYabcr5rlBtC7LlDmy6yBcim:Dod0pY+LlSmm
Yara None matched
VirusTotal Search for analysis
Name 74ebbac956e519e1_softokn3.dll
Submit file
Filepath C:\ProgramData\softokn3.dll
Size 251.8KB
Processes 3048 (356feeff4e.exe) 2104 (minidump-analyzer.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4e52d739c324db8225bd9ab2695f262f
SHA1 71c3da43dc5a0d2a1941e874a6d015a071783889
SHA256 74ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5a
CRC32 1CE2A51D
ssdeep 6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8934aaeb65b6e6d2_vcruntime140.dll
Submit file
Filepath C:\ProgramData\vcruntime140.dll
Size 79.0KB
Processes 3048 (356feeff4e.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a37ee36b536409056a86f50e67777dd7
SHA1 1cafa159292aa736fc595fc04e16325b27cd6750
SHA256 8934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825
CRC32 A23699DD
ssdeep 1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name b3dfa692f7da19ee_AAAEBAFBGIDHCBFHIECFCBGHIE
Submit file
Filepath C:\ProgramData\AAAEBAFBGIDHCBFHIECFCBGHIE
Size 5.0MB
Type SQLite 3.x database, user version 69, last written using SQLite version 3038003
MD5 c395620f9a8337341636a78a98f5b3d9
SHA1 97700ec4db7362e02a56df5e70dd828ad9823d24
SHA256 b3dfa692f7da19eede9aa2fe2ac76052cfaa32a7d30cc53b88ea5ef23ec32624
CRC32 476CDB88
ssdeep 192:StsqHQnwkYjcoBMc+uySBQies13A29D+oBpp0:StsbwVTBMc+uySOiJ3Z
Yara None matched
VirusTotal Search for analysis