Dropped Files | ZeroBOX
Name a54fbd60bf9802f1_f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c
Size 3.3KB
Processes 2928 (firefox.exe) 2856 (crashreporter.exe)
Type ASCII text, with very long lines
MD5 b7f6024c50f80312284e8d568a118dc6
SHA1 ce7c04304b36b83470dada03d1c5abbb46b88154
SHA256 a54fbd60bf9802f196b726d4de90ad138abe39ab5e96ad03f30b84a1a6f19bf7
CRC32 8346BD5F
ssdeep 48:RQodHQ7B9OhCbxRgjyi54SiUe/Mg67kpKCtsfCFBULcPfq19Tv/7vgAvJIfLv6Xy:Co2b+CFRcr5rUS7cAfCML5v/7IvuAWi
Yara None matched
VirusTotal Search for analysis
Name b0bcbebba3f0a4b7_scriptCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\scriptCache.bin
Size 9.2MB
Type data
MD5 7fcd6694c7418071bb6f0e1c879bf833
SHA1 022fdf4208fba1c4dd34c6bb1444591529509cf2
SHA256 b0bcbebba3f0a4b75f692e5c955707ad67e4312590330b97e987638eb72d0b11
CRC32 46CB710E
ssdeep 49152:SfNsfR/eXfWVAoIgPm6t7eh+3R8ViGUrilbASvzmj/YDNM3eckIOehICZ3ZkF:SfNyYOVi6Fa2vraASvz6GMu2hIF
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • RedLine_Stealer_b_Zero - RedLine stealer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 06287f7994000545_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 69.4KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 47e6d32f4902227382c588d4f8e3df44
SHA1 66b1a85d778e841c4ab15623259d995ed9755c21
SHA256 06287f7994000545db9768598c3455a88bcabdc9705f76668efd4bd9109908ba
CRC32 46D847D1
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgri:eHCtlDUDXsL+JhlunUPxmP
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name ac5c92fe6c51cfa7_nss3.dll
Submit file
Filepath C:\ProgramData\nss3.dll
Size 2.0MB
Processes 1476 (b936c46ad4.exe) 2928 (firefox.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1cc453cdf74f31e4d913ff9c10acdde2
SHA1 6e85eae544d6e965f15fa5c39700fa7202f3aafe
SHA256 ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5
CRC32 7DC07205
ssdeep 49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 37257ddb1a6f309a_b936c46ad4.exe
Submit file
Filepath C:\Users\test22\1000010002\b936c46ad4.exe
Size 187.5KB
Processes 2320 (svoutse.exe) 3060 (cmd.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 278ee1426274818874556aa18fd02e3a
SHA1 185a2761330024dec52134df2c8388c461451acb
SHA256 37257ddb1a6f309a6e9d147b5fc2551a9cae3a0e52b191b18d9465bfcb5c18eb
CRC32 35387B04
ssdeep 3072:/k9W0KFj5qj6o8KaxfE54HnnGqaKl+b2n8O43tIFmpKa:/kE/j5K62aOanGqCbAq3SFAKa
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 85af2e0d952983d0_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 68.9KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 9e51ffa04e057b7e8100376530543707
SHA1 641cc30e5e73413b84d638c7082031987cf9c0f3
SHA256 85af2e0d952983d0da12b1dc2b6bb1e440140d42c199793ca0943ac6e33aca4c
CRC32 DB6D6A2D
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgr:eHCtlDUDXsL+JhlunUPxm
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name c119a54b6bef3a48_AEGIJKEH
Submit file
Filepath C:\ProgramData\AEGIJKEH
Size 80.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 255929949dea51a2f43a1f40e63764ec
SHA1 8f32ab419264fdad05f4f3828db3c1cd38d919fd
SHA256 c119a54b6bef3a48234950dc07fe70f73b69d1390ef0235e66481faa1048ead6
CRC32 F7A79605
ssdeep 96:5Bc7fYLKYZCIdE8XwUWaPdUDg738Hsa/NhuK0l0q8oc5PyWTJereWb3lxzasq9u4:5BPOUNlCTJMb3rEDFAa6E/
Yara None matched
VirusTotal Search for analysis
Name 63e02015af0699aa_scriptCache-child.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\scriptCache-child.bin
Size 824.1KB
Type data
MD5 19421dc0192e633eec157df491fd8c13
SHA1 adeb399426e11cb6de823cc8f5269e9f2f3e657f
SHA256 63e02015af0699aa0c1a90951bd36f1f62a10746c7e5eb004e29d27d3d80ab23
CRC32 C98B88C5
ssdeep 6144:jLv50b7rtyuRMAMgDh6QbZpZltg2ebfhAFgMWM/OB48SuTSBWobB2PLtPkZ:X5ctdD15PgMWM/OXnSBWob4tcZ
Yara None matched
VirusTotal Search for analysis
Name 5136a49a682ac8d7_msvcp140.dll
Submit file
Filepath C:\ProgramData\msvcp140.dll
Size 439.5KB
Processes 1476 (b936c46ad4.exe) 2928 (firefox.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 5ff1fca37c466d6723ec67be93b51442
SHA1 34cc4e158092083b13d67d6d2bc9e57b798a303b
SHA256 5136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062
CRC32 FE675AE5
ssdeep 12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14_D099.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\D099.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name fd4c9fda9cd3f9ae_cookies.sqlite-shm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite-shm
Size 32.0KB
Type data
MD5 b7c14ec6110fa820ca6b65f5aec85911
SHA1 608eeb7488042453c9ca40f7e1398fc1a270f3f4
SHA256 fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
CRC32 DDC506B6
ssdeep 3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
Yara None matched
VirusTotal Search for analysis
Name 159cea1687da4304_f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c.dmp
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c.dmp
Size 93.7KB
Processes 2928 (firefox.exe) 1476 (b936c46ad4.exe) 2856 (crashreporter.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:15:39 2024, 0x820 type
MD5 aa8018e66f934620c0652ea8b0fd5e74
SHA1 8dfe1f2cc33591cf769f24c7f459f9da9d66320e
SHA256 159cea1687da43040baddb75ce82f04a29a178da95726dc17be168919c6c9fc2
CRC32 0881BC01
ssdeep 384:+ewGr1ply3rzrQHcmyqDOHmT7zrpIGkv40b8P+If/SEIr0PWKXnqC8yxsxZshtT2:+ep1pl25iDphc40b8RSDYPWKXnFxashw
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 0f4aa68d4124bd2d_f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c-submission
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c-submission
Size 73.0B
Processes 2856 (crashreporter.exe)
Type ASCII text
MD5 511ef0c38a77d89c9bfdc2d1e93c8f9a
SHA1 fca804099f4a3bd43eddcb9353217f3065b88521
SHA256 0f4aa68d4124bd2d83aba6641dda9721c9485196c2c9d6d045003808b4f8b834
CRC32 4914499A
ssdeep 3:RIRL/zdEFvPdASHkxXCcP59Xb9Hvn:e0F3d3kxXCcP59r9Hvn
Yara None matched
VirusTotal Search for analysis
Name b3dfa692f7da19ee_GIECFIEGDBKJKFIDHIECGDGIEB
Submit file
Filepath C:\ProgramData\GIECFIEGDBKJKFIDHIECGDGIEB
Size 5.0MB
Type SQLite 3.x database, user version 69, last written using SQLite version 3038003
MD5 c395620f9a8337341636a78a98f5b3d9
SHA1 97700ec4db7362e02a56df5e70dd828ad9823d24
SHA256 b3dfa692f7da19eede9aa2fe2ac76052cfaa32a7d30cc53b88ea5ef23ec32624
CRC32 476CDB88
ssdeep 192:StsqHQnwkYjcoBMc+uySBQies13A29D+oBpp0:StsbwVTBMc+uySOiJ3Z
Yara None matched
VirusTotal Search for analysis
Name 1278b6f916fb6e9b_lastcrash
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\LastCrash
Size 10.0B
Processes 2928 (firefox.exe)
Type ASCII text, with no line terminators
MD5 d93e0eebe635567bd55e1880cc0caf24
SHA1 0320b0ac84cc8f103085bc1a2da85fcee1c54043
SHA256 1278b6f916fb6e9bc54b16a2e87a04f91c91a38b35da3ba411dc8fa16c631279
CRC32 DD63E1D4
ssdeep 3:LBVsRc:tVp
Yara None matched
VirusTotal Search for analysis
Name 3af268ebe55b69df_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 68.5KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 d571285e7eda7e97588295db732efed5
SHA1 90ae1ca65d9c5dae7c39ab3e680a669ce259fb6b
SHA256 3af268ebe55b69dfdf63efea6e54fa2f71a76ad53cd3d88857a0f7644b733259
CRC32 86C07FA1
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgr0:eHCtlDUDXsL+JhlunUPxm9
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 0e3dc4ccd259716b_settings.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Size 40.0B
Processes 2668 (chrome.exe)
Type data
MD5 62325aa04f35880232330f344df8018c
SHA1 58fe9532ee8d96e8d12448408cf3ccf9d0542543
SHA256 0e3dc4ccd259716b24376fddb4ee07a6c227f8bcb2532a7dd75bb36a4290e7cc
CRC32 6F0BEA7C
ssdeep 3:FkXJRYcTUM:+wcTb
Yara None matched
VirusTotal Search for analysis
Name 8916fb1d76be83e4_KKFHJJDHJEGHJKECBGCFHDBFIE
Submit file
Filepath C:\ProgramData\KKFHJJDHJEGHJKECBGCFHDBFIE
Size 192.0KB
Type SQLite 3.x database, user version 4, last written using SQLite version 3031001
MD5 6b9c2ac2b5025e180231d8d38ece698c
SHA1 36f5cfe6ac59aaa7d7173555edeef5caa9bf61c6
SHA256 8916fb1d76be83e42cd2f7b41ee06706fe0adb936259ed7a7daa4dbcb4c51fcb
CRC32 95ACFD74
ssdeep 12:DBl/lkf12Of5LZWfY0xpMujuHWMu6N2OHjWOzMbdym/eRgBoQFmgW2FOmO6Mz6LX:DLlI1x7WxHaiSlMxosJF/Ezo
Yara None matched
VirusTotal Search for analysis
Name 6496525e8c4f550d_5c887e602a.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000009001\5c887e602a.exe
Size 206.5KB
Processes 2320 (svoutse.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 17c17bbf39fb2afd08ced301cc8fbedd
SHA1 62a83f819faed02490147b9c6891e4606efc89b3
SHA256 6496525e8c4f550d6bcf09e015b9179fc8b1f8f93eb6cbfd74a62663beece45c
CRC32 F029BC2F
ssdeep 6144:13ZKLDoJcBErT7FYjl6prC57iSVS4pXNHeyEO:13ZKin7eAo575VJR9eyEO
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name febd3af0bf2b6e47_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 68.8KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 2e41d9cd30df19e200630581c24ad3c7
SHA1 6e29374d8232682874fb918e65317f4780e5b9fb
SHA256 febd3af0bf2b6e470f6028e9616b2aa44875dd06af88bee49bfb9a60da3c4c1d
CRC32 42741D5E
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgrG:eHCtlDUDXsL+JhlunUPxmP
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name b87beb4bbc429f0c_webext.sc.lz4
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\webext.sc.lz4
Size 105.5KB
Type data
MD5 86f4fe26175341c830af0ae6353d41db
SHA1 a1449571cf2014cac60a7f3dd7cab8a55380be81
SHA256 b87beb4bbc429f0c98428686eb04b7692f12d53385ab5a3d324bf094bef0c29d
CRC32 D9310E97
ssdeep 3072:igI+rushnjZa9uB1StrmnZI1wwZPxUwwc9ifT:0+rNjc9b+Zet1S08L
Yara None matched
VirusTotal Search for analysis
Name 88f9dc0b9a633e43_HCFBFBAEBKJKEBGCAEHCFCBAEH
Submit file
Filepath C:\ProgramData\HCFBFBAEBKJKEBGCAEHCFCBAEH
Size 512.0KB
Type SQLite 3.x database, user version 11, last written using SQLite version 3031001
MD5 dd47ebe6866ad2ab59d0caa1de28d09e
SHA1 afdf6eb7a01bb7ef4c9d768b65abbbeae5ba2663
SHA256 88f9dc0b9a633e43c6d2c6fae136e782c15aa38c1601dcff948987f1c2a391c3
CRC32 8DEE9EEA
ssdeep 24:DQHtJl32mNVpP965hKN0MG/lZpNjCKRIaU5BnCMOkC0JCpL3FYay:DQfrbWTTTqtStLm
Yara None matched
VirusTotal Search for analysis
Name 0b8607fdf72f3e65_CFHIIJDBKEGIDHIDAFCFBGHIJD
Submit file
Filepath C:\ProgramData\CFHIIJDBKEGIDHIDAFCFBGHIJD
Size 96.0KB
Type SQLite 3.x database, user version 12, last written using SQLite version 3038003
MD5 d367ddfda80fdcf578726bc3b0bc3e3c
SHA1 23fcd5e4e0e5e296bee7e5224a8404ecd92cf671
SHA256 0b8607fdf72f3e651a2a8b0ac7be171b4cb44909d76bb8d6c47393b8ea3d84a0
CRC32 842B3569
ssdeep 12:DQAwfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAwff32mNVpP965Ra8KN0MG/lO
Yara None matched
VirusTotal Search for analysis
Name 8e1169dc03185bb1_b49fdb64-c04c-4640-b40b-6a4df12e2268.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\b49fdb64-c04c-4640-b40b-6a4df12e2268.dmp
Size 518.7KB
Processes 2788 (chrome.exe) 2968 (minidump-analyzer.exe)
Type Mini DuMP crash report, 10 streams, Mon Aug 19 08:16:17 2024, 0x0 type
MD5 9ed62f9e64d5c0e67666d1f2bc7e78f4
SHA1 9be956bb97be187dd9abe7eb810d6e3494e6861d
SHA256 8e1169dc03185bb16d579c539e5b4232e28371dc35a1ceb2254c795d8ac45ba1
CRC32 CCA416A2
ssdeep 3072:L4PptUC/rTvsIwGi0+bhmDZ56kec+M9SrVrOUF0RzNiqEkim:MPrUYkG5u3wNWkz
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 169c04331f72fe4a_GCGHIIDHCGHCAAAAAFIJEGHJDH
Submit file
Filepath C:\ProgramData\GCGHIIDHCGHCAAAAAFIJEGHJDH
Size 5.0MB
Type SQLite 3.x database, user version 53, last written using SQLite version 3031001
MD5 f77930486de1b1bb4b397d5d8f3cd124
SHA1 e3f5727a0774c7cba17f0b10569012dcea24cb55
SHA256 169c04331f72fe4ae9958da09e1b28ec5910f7ea523d6105b7e4ad521b2baaee
CRC32 D85072F9
ssdeep 96:Dm8j5PnH6xY2Wi+67tH2iB4q2xfX7ZbiZzdFzb4PPwI3A7:l5/IYOTAlQzdFzaDm
Yara None matched
VirusTotal Search for analysis
Name 26e7411800b5e6eb_f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c.extra
Submit file
Filepath c:\users\test22\appdata\roaming\mozilla\firefox\crash reports\pending\f68e7be3-9e2b-4ffe-97d7-a1ef27c9922c.extra
Size 4.6KB
Processes 2928 (firefox.exe) 2968 (minidump-analyzer.exe) 2856 (crashreporter.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 54a2b08c4c812f3833d4ddc07186a492
SHA1 b41a1ec8926a899b76f26922f231d0431d561b0c
SHA256 26e7411800b5e6ebfe4802615a128894d794ae7fc5de22c9571cb8292914655e
CRC32 6B328FDD
ssdeep 96:DoXIfDi+8bN+abcr5rUS7cAfCML5v/7IvuAW8:DoXFp+/73JLdL8
Yara None matched
VirusTotal Search for analysis
Name edd043f2005dbd59_freebl3.dll
Submit file
Filepath C:\ProgramData\freebl3.dll
Size 669.3KB
Processes 1476 (b936c46ad4.exe) 2928 (firefox.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 550686c0ee48c386dfcb40199bd076ac
SHA1 ee5134da4d3efcb466081fb6197be5e12a5b22ab
SHA256 edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fa
CRC32 085C6D2B
ssdeep 12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ba06a6ee0b15f5be_mozglue.dll
Submit file
Filepath C:\ProgramData\mozglue.dll
Size 593.8KB
Processes 1476 (b936c46ad4.exe) 2928 (firefox.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c8fd9be83bc728cc04beffafc2907fe9
SHA1 95ab9f701e0024cedfbd312bcfe4e726744c4f2e
SHA256 ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196a
CRC32 28C04754
ssdeep 12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 6d06eb35af4a584b_svoutse.job
Submit file
Filepath C:\Windows\Tasks\svoutse.job
Size 272.0B
Processes 1932 (rama.exe)
Type VAX-order 68k Blit mpx/mux executable
MD5 91a1fadf88b5c95e134f8ada5ffacd0b
SHA1 cbe257fa8206fc25281505d2b189872ad3b7c3e2
SHA256 6d06eb35af4a584b502566f63991cca3442952d0b24a74d85c33554f3981a895
CRC32 13BFA310
ssdeep 6:qMXE///UEZ+lX1Qye6YctI4y0lRXkdt0:qWk//Q1214VOt0
Yara None matched
VirusTotal Search for analysis
Name 6cf1fcf9f0aa7b1e_submit.log
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\submit.log
Size 228.0B
Processes 2856 (crashreporter.exe)
Type ASCII text, with CRLF line terminators
MD5 611d021fab3d34f8390430ecae29bb37
SHA1 b39ca05d840dc72d66a764d6f142cec3f291a656
SHA256 6cf1fcf9f0aa7b1e7337cc8379510cbec3c035f7957eeb77f2c62612b1e00600
CRC32 63CD5864
ssdeep 6:g8ahjz5d6Qw0HZAsCpYA6Dp6h8ahjz5d6Qw0HZAsCpYA6Dp7:VahRgQw0eTGDpBahRgQw0eTGDp7
Yara None matched
VirusTotal Search for analysis
Name fd1949a07dcc50de_2fd9b80b02.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000008001\2fd9b80b02.exe
Size 89.5KB
Processes 2320 (svoutse.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b050140e1db59e162e6fd1a839b228ea
SHA1 32061a41859bd7df726cadbc110a3ba2ea45881b
SHA256 fd1949a07dcc50de042a2b410cf1336b98116113843f3ee248fb36465a19cb05
CRC32 110BB810
ssdeep 1536:L7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfbxQQTO+:Hq6+ouCpk2mpcWJ0r+QNTBfb5
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 824fae3331b95e2f_GCAEHDBAAECBFHJKFCFB
Submit file
Filepath C:\ProgramData\GCAEHDBAAECBFHJKFCFB
Size 40.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 41c19a9e8541fcb934c13c075bf47721
SHA1 648a7622d533d79b9a0bb31dc370134ec3a75ed7
SHA256 824fae3331b95e2f88ca60c87a6c9569086906ec76fc1db8d6dee9adddc4e80c
CRC32 560F7642
ssdeep 48:+35TqYzDGF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:Ulce7mlcwilGc7Ha3f+u
Yara None matched
VirusTotal Search for analysis
Name 1d417807b94f958c_urlCache.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\urlCache.bin
Size 3.2KB
Type data
MD5 26c3ea73c6885eaea20b6a5a6280ce50
SHA1 32fb4a91b1f37d0228ff31c0f0d6c37a173e67f2
SHA256 1d417807b94f958c6a4069a9dedf24b001099a68936f8ac10ef7bc30a126af38
CRC32 7DB0ACAF
ssdeep 48:BAbHgqedXU753de/xJtISt3bqhJtgtkt0IbvVr9cHSWypBr/BWLaLWcbsyMJrls:BAMqedXUd3AIq3bucwbhcmVsXJr6
Yara None matched
VirusTotal Search for analysis
Name f31bba4e1f7e7cd1_debug.log
Submit file
Filepath C:\Program Files (x86)\Google\Chrome\Application\debug.log
Size 290.0B
Processes 2788 (chrome.exe)
Type ASCII text
MD5 ed3dfe988ad80db9350adc60215e6dad
SHA1 337278eac2cf861d0521124fb0a2db7074ef0513
SHA256 f31bba4e1f7e7cd1236cea113a03e845eddac513b6e837c3bee45e1ec96b53ae
CRC32 3C65435D
ssdeep 6:qS448TCGGDLeX/WyTHcRU4LGGFw3V4v8dEpERU4LGGFw3V4vF:OJOOWoHcRU4LG6w3V6M6ERU4LG6w3V6F
Yara None matched
VirusTotal Search for analysis
Name edb006e05cfa8501_GDGHIDBKJEGIECBGIEHCGIDBAA
Submit file
Filepath C:\ProgramData\GDGHIDBKJEGIECBGIEHCGIDBAA
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 3f5ca3e29b1b60e298aeca0a32164c03
SHA1 f9b5ee59c31a3b06a6b8e476b22d2d7cf1fa8b66
SHA256 edb006e05cfa85015aa76c758d6298c279fd318cff0dbb286927c7ad45105488
CRC32 E1ACA097
ssdeep 24:TL2C0RlPbXaFpEO5bNmISHdL6UwcOxvo5:TYLOpEO5J/KdGU1Eo5
Yara None matched
VirusTotal Search for analysis
Name 7835a26e3f5ea565_svoutse.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0e8d0864aa\svoutse.exe
Size 1.8MB
Processes 1932 (rama.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 304eb6432c7696e15f48eda1ffd469aa
SHA1 7835bb1b32456f2c9670fe97eddf0b10ab05bd19
SHA256 7835a26e3f5ea565c099b426c66838dbea8642cd7dcf51fdfc260b1cd9bde4a6
CRC32 4FDDB605
ssdeep 49152:/iCP6/ACHu1QT5Z17CXMuTsu03yMKtbyyIO0PWFiDsC2O:/il/ASZY8ysucyMm29OjFiwC2O
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name d820603eb308a436_KFBGCAKFHCFHJKECFIID
Submit file
Filepath C:\ProgramData\KFBGCAKFHCFHJKECFIID
Size 12.0KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 0647d44f50372ccfa8f1e56b37e9fe76
SHA1 5e7fac4675932c1faa55f925c958ca1c75324a20
SHA256 d820603eb308a43651cc248106d188c1602f5de460de659300721f03cd863dbc
CRC32 A8996995
ssdeep 192:O6nHM58sK1zjyPySpI+JpVgxXhKQuylvICf/eEoBqIrv0bEHa+n:O6sPPZIcpmxO3BqIr0IH/n
Yara None matched
VirusTotal Search for analysis
Name 2639bd76b0d09d88_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 69.0KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 8ad7e765e1d57e10ac571404bc90a8a2
SHA1 b1ae76c58c24ee76f49e92b753fbedca333626fe
SHA256 2639bd76b0d09d886b6446ceedfad3d71e827ef0f83fc53924775b9beb5166d2
CRC32 5909571E
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgrc:eHCtlDUDXsL+JhlunUPxmt
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 6e78ed850413b46f_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 69.3KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 09aba9566975b1e34a8b9c3b3d41c96b
SHA1 69ce275fdfccc13b951ba74b39887c2956069984
SHA256 6e78ed850413b46fa1ce4befd6c40cc5e0ca98594a2fe600df246e0a48caddce
CRC32 7AF8F749
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgrU:eHCtlDUDXsL+JhlunUPxmp
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 63f5a75bc6e48a60_startupCache.8.little
Submit file
Filepath C:\Users\test22\AppData\Local\Mozilla\Firefox\Profiles\1pfa5s83.default-release\startupCache\startupCache.8.little
Size 7.4MB
Type data
MD5 366cb8639aeb3f55c7d6999a7fbac41d
SHA1 5c763f6a53320c8282fa1c648111fd2e68d34145
SHA256 63f5a75bc6e48a60722f5b706b3f3953f8139e31c3d81eff92f8aad6943dac01
CRC32 CF035B97
ssdeep 98304:LXEV8Jzl6VPltC/8Toxmu5RTRPG/D79MJRGDx/s3:LE89l2mYFu5HsD72idk
Yara
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name cacb3b090bd98317_compatibility.ini
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\compatibility.ini
Size 200.0B
Processes 1152 (firefox.exe)
Type Windows WIN.INI, ASCII text, with CRLF line terminators
MD5 63f28ee6c5768202c31eaf82725b64c2
SHA1 edc0b0c87aaa262a0aba6e6b29b2c31cc04fcf39
SHA256 cacb3b090bd98317500f593712c4bf51b5197c7aa9e07b6e10cab50144339ff0
CRC32 D70ADABB
ssdeep 3:tZAQU6oEl1mE12NE2aT/P4WX1rDZjrEFwHQ3ZjrEFwslyy:VoKmbbabN1rDVEFycVEFL
Yara None matched
VirusTotal Search for analysis
Name 752a176e12900c9f_D0AB.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\D099.tmp\D09A.tmp\D0AB.bat
Size 2.8KB
Processes 2520 (2fd9b80b02.exe)
Type ASCII text, with CRLF line terminators
MD5 31c09b550c61042384ef240a1cd226df
SHA1 731fbe63179f646915f8fa37ca9f8c85fdb9b48a
SHA256 752a176e12900c9f3cf947bc36d506e360f86da00a2dbc1e5fa821f2584c75db
CRC32 7C5572DC
ssdeep 48:N0K2U7V5rN81fN80XUbaOUb5OzQ/iqzQ/hXDTjODAKpxVgXDOev0W:rrrN81fN80Ebanb5OzQ/iqzQ/hTTj+Av
Yara None matched
VirusTotal Search for analysis
Name 74ebbac956e519e1_softokn3.dll
Submit file
Filepath C:\ProgramData\softokn3.dll
Size 251.8KB
Processes 1476 (b936c46ad4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4e52d739c324db8225bd9ab2695f262f
SHA1 71c3da43dc5a0d2a1941e874a6d015a071783889
SHA256 74ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5a
CRC32 1CE2A51D
ssdeep 6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8934aaeb65b6e6d2_vcruntime140.dll
Submit file
Filepath C:\ProgramData\vcruntime140.dll
Size 79.0KB
Processes 1476 (b936c46ad4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a37ee36b536409056a86f50e67777dd7
SHA1 1cafa159292aa736fc595fc04e16325b27cd6750
SHA256 8934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825
CRC32 A23699DD
ssdeep 1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name cecf59649ccf1d76_JKEHIIJJECFHJKECFHDG
Submit file
Filepath C:\ProgramData\JKEHIIJJECFHJKECFHDG
Size 8.8KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 07951590532d8114ea1caca9ed7e0a39
SHA1 7a4bebc2f20ead9546fa5749aafe739ad5f551de
SHA256 cecf59649ccf1d7668ad3c7119bf9b380d6d5c339d7f0faeb2f29f163fd3f3ee
CRC32 E3F3A320
ssdeep 192:ZDnijRILMMdaWaLbFlp/PuFbylfFw8AxSwSO:pmsy7wIO
Yara None matched
VirusTotal Search for analysis
Name 402a11d878b72a72_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 68.9KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 96a345f53155ddc242887c9ee1c0ab1c
SHA1 0cfaed8ae7a0f0897b3ab58cc2edd8e04fe54f30
SHA256 402a11d878b72a72fa535b3c3aef395723acdcd097d931b1e70936e0260ded28
CRC32 D3BEF3EB
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgrF:eHCtlDUDXsL+JhlunUPxm0
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 8e30a67ef2e61b23_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 68.9KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 fcda57e4b7dc15501b1d16abbb048961
SHA1 64feca96e52bce9b19c999cc82b16ad2c30ac38f
SHA256 8e30a67ef2e61b23d7cf4d85b564cb57ea1b0ba8c629b5bfcaefca61c37546a5
CRC32 95983AA6
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgrz:eHCtlDUDXsL+JhlunUPxmi
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name b2cfb7fefcecda6d_metadata
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
Size 114.0B
Processes 2788 (chrome.exe)
Type data
MD5 5537d5fdd9259625c847e8e1c7a7ff82
SHA1 3eb9b57862d78bfd16392e2702fde85a323a15e2
SHA256 b2cfb7fefcecda6d55bfd32398d87efd697063549a885bae004962f0127bb9f0
CRC32 100598A6
ssdeep 3:mTll+Xlw6P/X0slin5//lnl6DV1fRqV7DUQHtBo:mTlEwC/XHE5/CDbfU0QN6
Yara None matched
VirusTotal Search for analysis
Name 0ad63b28b945cac3_a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\a3725f7e-4ddb-4088-bc9b-fb1f6f52b823.dmp
Size 69.1KB
Processes 1948 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Mon Aug 19 08:17:12 2024, 0x820 type
MD5 157c43fe964c8442b706925848344119
SHA1 a3b31bde99ac6b025aa54b4d21394b23a1de3e1a
SHA256 0ad63b28b945cac363334b7d7634185c860fff73525eb662d23e4e82cdd4926c
CRC32 90BCF563
ssdeep 384:elxC4Cply3unmyV2DbTM5oQCEJQFJSchlELnUCNsx4xgr3:eHCtlDUDXsL+JhlunUPxm+
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis