Dropped Files | ZeroBOX
Name 5b0263857106fa94_poolworker.config.ini
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\poolworker.config.ini
Size 98.0B
Processes 1208 (x11.exe)
Type ASCII text, with CRLF line terminators
MD5 1cff20fc77835e110b62445be05114c2
SHA1 7981667914201cf92fbcceb6d42a05de8a87f451
SHA256 5b0263857106fa941b4fd3df40e3f2ade971a75f6b4847226aa150c620704595
CRC32 FE261795
ssdeep 3:GRLYm5cQ4RCoqkMkS0uiBLyo/yuUqvovy:85kRJ7Sfi0LuUqvovy
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_10913937
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\__tmp_rar_sfx_access_check_10913937
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name c035c371f1ad9a96_k1.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\k1.exe
Size 3.9MB
Processes 1208 (x11.exe)
Type PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
MD5 692d72923747be1ed2c05cd6b4118bf4
SHA1 046050976d2fa16cf25e10f4895011e066414b0e
SHA256 c035c371f1ad9a96b51f28fbe9e6f7a402bf10cd1ca2d82aabbc78ba07c7703f
CRC32 038AE7AC
ssdeep 49152:A+W0qUi3UHScrb/THvO90d7HjmAFd4A64nsfJRsjcaH7ALfSadLLfrXHz8LbHpD5:Y32S4j1cE/oOX
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis