Dropped Files | ZeroBOX
Name ac5c92fe6c51cfa7_nss3.dll
Submit file
Filepath C:\ProgramData\nss3.dll
Size 2.0MB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1cc453cdf74f31e4d913ff9c10acdde2
SHA1 6e85eae544d6e965f15fa5c39700fa7202f3aafe
SHA256 ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5
CRC32 7DC07205
ssdeep 49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 5923793c30acf902_test22aecfcaaecb.exe
Submit file
Filepath C:\Users\test22AECFCAAECB.exe
Size 192.0KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 70567fae269796bf407322d0a4435054
SHA1 e11eddf4f0ce6d5288d8187005d34eee6efba046
SHA256 5923793c30acf9026a872fcb8ce04a671fa194bb4f73eef165d687ae97683047
CRC32 7355E768
ssdeep 6144:HQOkLP/rabJ2k24h3ErKsHJHOwiZ8byukEO:JcP/rFkLqrKQJEueukEO
Yara
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 5136a49a682ac8d7_msvcp140.dll
Submit file
Filepath C:\ProgramData\msvcp140.dll
Size 439.5KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 5ff1fca37c466d6723ec67be93b51442
SHA1 34cc4e158092083b13d67d6d2bc9e57b798a303b
SHA256 5136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062
CRC32 FE675AE5
ssdeep 12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 353871b38bb73ffb_test22hcaehdhdak.exe
Submit file
Filepath C:\Users\test22HCAEHDHDAK.exe
Size 321.0KB
Processes 2144 (RegAsm.exe) 2868 (RegAsm.exe)
Type PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 087f21847d13d50158683c834471728c
SHA1 6e0caf480014eb6239cbe757f9a75e4b5594ae69
SHA256 353871b38bb73ffb940b773c92849796c4c71949d5ffc9ea55103a8f41dabb74
CRC32 B3ABEED4
ssdeep 6144:zKKOAlrAtx7WiWOdkUsn18kq1viAXMFTd7r9pq8CG6UKBqdx7EO:zKLYUtcrOs1yeFRPzbCGQYx7EO
Yara
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name edd043f2005dbd59_freebl3.dll
Submit file
Filepath C:\ProgramData\freebl3.dll
Size 669.3KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 550686c0ee48c386dfcb40199bd076ac
SHA1 ee5134da4d3efcb466081fb6197be5e12a5b22ab
SHA256 edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fa
CRC32 085C6D2B
ssdeep 12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ba06a6ee0b15f5be_mozglue.dll
Submit file
Filepath C:\ProgramData\mozglue.dll
Size 593.8KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c8fd9be83bc728cc04beffafc2907fe9
SHA1 95ab9f701e0024cedfbd312bcfe4e726744c4f2e
SHA256 ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196a
CRC32 28C04754
ssdeep 12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 74ebbac956e519e1_softokn3.dll
Submit file
Filepath C:\ProgramData\softokn3.dll
Size 251.8KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4e52d739c324db8225bd9ab2695f262f
SHA1 71c3da43dc5a0d2a1941e874a6d015a071783889
SHA256 74ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5a
CRC32 1CE2A51D
ssdeep 6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8934aaeb65b6e6d2_vcruntime140.dll
Submit file
Filepath C:\ProgramData\vcruntime140.dll
Size 79.0KB
Processes 2144 (RegAsm.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a37ee36b536409056a86f50e67777dd7
SHA1 1cafa159292aa736fc595fc04e16325b27cd6750
SHA256 8934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825
CRC32 A23699DD
ssdeep 1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 824fae3331b95e2f_fcfieh
Submit file
Filepath C:\ProgramData\HCAEHDHDAKJE\FCFIEH
Size 40.0KB
Processes 2868 (RegAsm.exe)
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 41c19a9e8541fcb934c13c075bf47721
SHA1 648a7622d533d79b9a0bb31dc370134ec3a75ed7
SHA256 824fae3331b95e2f88ca60c87a6c9569086906ec76fc1db8d6dee9adddc4e80c
CRC32 560F7642
ssdeep 48:+35TqYzDGF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:Ulce7mlcwilGc7Ha3f+u
Yara None matched
VirusTotal Search for analysis