Dropped Files | ZeroBOX
Name e3b0c44298fc1c14_msbjefz5.err
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.err
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name da6d98d815beefe9_RESBB2E.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RESBB2E.tmp
Size 1.2KB
Processes 1272 (cvtres.exe) 504 (csc.exe)
Type Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x406, 9 symbols
MD5 3a87ba3c5f3a4d150b09b83ccc3c6e10
SHA1 abc275572d798770688d10032c622abbf9eb07ff
SHA256 da6d98d815beefe9d3d0c110c49b81a468a59d8b405e378e78f1b5e16e5c7001
CRC32 F2D26392
ssdeep 24:HoJ9Yern4/pmH1iUnhKLI+ycuZhNdYakSKNPNnqjtd:Jern4hmbnhKL1ulOa3qqjH
Yara None matched
VirusTotal Search for analysis
Name 506baa497a2396ed_CSCBAB0.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\CSCBAB0.tmp
Size 652.0B
Processes 504 (csc.exe)
Type MSVC .res
MD5 9d958cd38c30782fb91559e9e3470f9b
SHA1 d89f8dc792667b3da247a5ee78b3b78c806c11a4
SHA256 506baa497a2396edcbca1336019699bb898739de9610d18084671b74d0d3a88b
CRC32 522A710C
ssdeep 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryUUYak7YnqqNUNPN5Dlq5J:+RI+ycuZhNdYakSKNPNnqX
Yara None matched
VirusTotal Search for analysis
Name 44e8aa0601fffe82_590aee7bdd69b59b.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\590aee7bdd69b59b.customdestinations-ms
Size 7.8KB
Processes 1384 (powershell.exe)
Type data
MD5 ee6cfd78f72f03663db2a7df0c696dd7
SHA1 56126e81a5f6577f8e24a890185d0c9eb600fa02
SHA256 44e8aa0601fffe82c494bbc7d7280aa3bc5e90effe2aee2d716d5716e1d6b568
CRC32 F27137C4
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCworu4tDHXyGlUVul:EtCgXoRtCgbHnorBTyY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name d70c50dc2d5adbbf_msbjefz5.cmdline
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.cmdline
Size 311.0B
Processes 1384 (powershell.exe)
Type UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators
MD5 beda249a703faf0c93a713cdb4bcfdc3
SHA1 60d352e1af1474bd8f9e314642ec5fcb90995a2e
SHA256 d70c50dc2d5adbbf6f5d827212d34cb70af7acc2ef882f82b6bbc7233f59e4f0
CRC32 D5E6CEF3
ssdeep 6:pAu+H2LvFJDdq++bDdqBnmQpcLJ23f/HnQmGsSAE2NmQpcLJ23f/hH:p37LvXOLMwnPAE2xOLMhH
Yara None matched
VirusTotal Search for analysis
Name 33fadddca440a938_msbjefz5.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.dll
Size 3.5KB
Processes 504 (csc.exe) 1384 (powershell.exe)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 b0734155ac0a51ccd738ae6fffec0b37
SHA1 d0c6115e063f2ff8a373b3fc16332159534c59f5
SHA256 33fadddca440a938c052e6b83a666a2a74acc7b916912d390ede2c9efe79e2bb
CRC32 DD30C7CE
ssdeep 24:etGSZNOHGuEw+7ZXw0kOVNXHRUbdPtkZfAyyVYlbO1QpYsmI+ycuZhNdYakSKNPE:66swUNXRMuJAfVY0Kif1ulOa3qq
Yara
  • Network_Downloader - File Downloader
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
VirusTotal Search for analysis
Name 2b551eba164541c7_msbjefz5.out
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.out
Size 598.0B
Processes 1384 (powershell.exe)
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
MD5 09660a1f172748019c37a9f53081b113
SHA1 db1d503ead40d8e78624a61c7c6af49b5f445f39
SHA256 2b551eba164541c7aa7c2a9c34536f338cc3eadad4c2350b0f83756167dc0d72
CRC32 1679D2E8
ssdeep 12:K4X/NzR37LvXOLMwnPAE2xOLMhOKai31bIKIMBj6I5BFR5y:KyNzd3BwnIE2nhOKai31bIKIMl6I5Dvy
Yara None matched
VirusTotal Search for analysis
Name fe35a1c25bb8a00e_msbjefz5.0.cs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.0.cs
Size 465.0B
Processes 1384 (powershell.exe)
Type C++ source, UTF-8 Unicode (with BOM) text, with very long lines
MD5 41a875294cfa8b38e88aeb2cb2181132
SHA1 e9d4ed20896e7c3a24ce66de0edd20a7a1ccfd8b
SHA256 fe35a1c25bb8a00ec77e3d414cf5095afd4e5c000ee885088a0acf039b23f213
CRC32 38D81B1F
ssdeep 6:V/DsYLDS81zucyeNemMgQXReKJ8SRHy4HCxcgbCfOZNqT265wy:V/DTLDfukMrXfHu9+oNOWy
Yara
  • Network_Downloader - File Downloader
VirusTotal Search for analysis
Name c036c6c6fdf629c2_msbjefz5.pdb
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\msbjefz5.pdb
Size 7.5KB
Processes 504 (csc.exe) 1384 (powershell.exe)
Type MSVC program database ver 7.00, 512*15 bytes
MD5 aecc1b30637d6eda34a91939862a7e17
SHA1 7df6abc004510a0758a4e1aa22cb01a97935b90a
SHA256 c036c6c6fdf629c25721a6ea9e97253fa37d3dddf5bc4799cf2cae5194a4945a
CRC32 FF10BBB2
ssdeep 6:zz/BamfXllNS/FKC1mllxrS/77715KZYXcK6oGggksl/3YXBGQu+e0KWEi+:zz/H1W/0GSXS/pwU6mqRi
Yara None matched
VirusTotal Search for analysis