Dropped Files | ZeroBOX
Name 0b8607fdf72f3e65_BGHJJDGHCBGDHIECBGIDAEHCGD
Submit file
Filepath C:\ProgramData\BGHJJDGHCBGDHIECBGIDAEHCGD
Size 96.0KB
Type SQLite 3.x database, user version 12, last written using SQLite version 3038003
MD5 d367ddfda80fdcf578726bc3b0bc3e3c
SHA1 23fcd5e4e0e5e296bee7e5224a8404ecd92cf671
SHA256 0b8607fdf72f3e651a2a8b0ac7be171b4cb44909d76bb8d6c47393b8ea3d84a0
CRC32 842B3569
ssdeep 12:DQAwfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAwff32mNVpP965Ra8KN0MG/lO
Yara None matched
VirusTotal Search for analysis
Name 3a45cfe5fa8eed2d_1a89e6be-7a47-455c-9541-3c3b3330f95e
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\1a89e6be-7a47-455c-9541-3c3b3330f95e
Size 843.0B
Processes 2884 (firefox.exe)
Type ASCII text, with very long lines
MD5 4278d7e6ee86abbb0bf64c56b4d1dfb4
SHA1 2672fc645b22fd80422a49e07b7300e270a19a57
SHA256 3a45cfe5fa8eed2d2bc60f62cb17cb31dca11a7cd8d54d4f4ba6ad9c49b00d78
CRC32 0F38E43F
ssdeep 12:8+cdWvc5QTvJih4yKBS4zQqMuSHOJiFgpyZKTjJxpQwijpQJiH8gi3Xn:cdWvdkmyK7v96ybpympQwijpQJiH8gG
Yara None matched
VirusTotal Search for analysis
Name ebc3505b215704c3_9af36891-14e2-4960-9330-28c2e6c4cdd4
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\crashes\events\9af36891-14e2-4960-9330-28c2e6c4cdd4
Size 815.0B
Processes 2208 (firefox.exe)
Type ASCII text, with very long lines
MD5 067731f9931f5e0614e0fc5177b3b690
SHA1 bba737819a5147e32e289eb46afbfa1011592386
SHA256 ebc3505b215704c3e764c547bb14b1abf20b1a0654d89fa98f589d5688381ed6
CRC32 9E783DD9
ssdeep 12:8HAJHpTvJih4yKBS4zQqMuSH/NJiFBFpAKTjJxpQK+IijpQJilKF8bn:AABtkmyK7v96/X4pBpQKJijpQJi+8b
Yara None matched
VirusTotal Search for analysis
Name 7abd30de1c4a1a64_3f42309d-df3c-45c3-9182-d32d2d3f5808
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\3f42309d-df3c-45c3-9182-d32d2d3f5808
Size 817.0B
Processes 2600 (firefox.exe)
Type ASCII text, with very long lines
MD5 d0a0bbaa28789a9c1acf3e32f62ffbbc
SHA1 37271e46771d9a32b086179169d30e15b181141d
SHA256 7abd30de1c4a1a6454cbef84dd4a7ac40ca9781989d0b79d2cd7a740d17c27bf
CRC32 5132FD34
ssdeep 12:8NeXTvJih4yKBS4zQqMuSHBJiFEpITjJxpQjTijpQJicRpa8tn:2eDkmyK7v96rbpCpQnijpQJicRpa8t
Yara None matched
VirusTotal Search for analysis
Name acf32626e6358436_9af36891-14e2-4960-9330-28c2e6c4cdd4.extra
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\minidumps\9af36891-14e2-4960-9330-28c2e6c4cdd4.extra
Size 754.0B
Processes 2208 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 2cc0dcc72d7fe1f6abab59d7c3adf67c
SHA1 548d7c9688b2569a5807bfd108d09bae9aae155a
SHA256 acf32626e6358436136af5d52f5cbd5554055a97933e1983ac9109620183e20e
CRC32 1ABC456A
ssdeep 12:YNTvJih4yKBS4zQqMuSH/NJiFBFpAKTjJxpQfcijpQJiKF8Hn:YRkmyK7v96/X4pBpQkijpQJiKF8H
Yara None matched
VirusTotal Search for analysis
Name 538449b466e6b957_1ad1df49-1767-4777-81d0-942a4e0e0de9
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\1ad1df49-1767-4777-81d0-942a4e0e0de9
Size 845.0B
Processes 184 (firefox.exe)
Type ASCII text, with very long lines
MD5 2309710ba0101a750ad550007290a57e
SHA1 107813476debafb918dd9d0fb6175c2a561b8635
SHA256 538449b466e6b95729dc81b339dd1d1d81857bee7f32d881db902b97d9ba7752
CRC32 8271AD89
ssdeep 12:8Q1ETvJih4yKBS4zQqMuSHhpJiFWQp4IXpTjJxpQXfKcijpQJiPqBw8UaEi33Un:HMkmyK7v961ipdpQXfKcijpQJiPww8Oh
Yara None matched
VirusTotal Search for analysis
Name ac5c92fe6c51cfa7_nss3.dll
Submit file
Filepath C:\ProgramData\nss3.dll
Size 2.0MB
Processes 2588 (376da640f6.exe) 2600 (firefox.exe) 2208 (firefox.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 1cc453cdf74f31e4d913ff9c10acdde2
SHA1 6e85eae544d6e965f15fa5c39700fa7202f3aafe
SHA256 ac5c92fe6c51cfa742e475215b83b3e11a4379820043263bf50d4068686c6fa5
CRC32 7DC07205
ssdeep 49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name c130b8b540df32f9_9bd80c9c-b09a-47ab-a61a-f24b47a41f96.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\9bd80c9c-b09a-47ab-a61a-f24b47a41f96.extra
Size 782.0B
Processes 1044 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 6ce95daf0f237b46b47dc9bdf9449730
SHA1 563e456c1229b652b9d11eae0299c8567d4a671f
SHA256 c130b8b540df32f9dc2e609952784fd75f20d5d63b7466df2d509d309e188ddc
CRC32 A7E19468
ssdeep 12:YNTvJih4yKBS4zQqMuSHmnGJiFBFpUOKTjJxpQPHijpQJix8Pi3hn:YRkmyK7v96IK4pUOApQPHijpQJix8Pk
Yara None matched
VirusTotal Search for analysis
Name c83041771fc601f0_05835e05-6121-4708-9111-fa231fd15bbd.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\05835e05-6121-4708-9111-fa231fd15bbd.dmp
Size 86.6KB
Processes 2184 (firefox.exe) 1044 (firefox.exe) 2880 (firefox.exe) 2884 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Sat Sep 21 12:16:35 2024, 0x820 type
MD5 b1f7e9ecdef97f1e15da065c37303ad3
SHA1 39359edbd603c7c0b5bd55e692f1f5a1fc23eede
SHA256 c83041771fc601f052f76d419075025fd3d8359e5aa11e3accb849303adc2149
CRC32 47A34FCB
ssdeep 384:52FDEL4Ily3fSjXltVXmyhDVsqYn85IVj9pzoZ0pRICV94kOIOFbPvlk:cFYL9lDjXltVXJDopzoGpRCC
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 5cfb285497fbb771_svoutse.job
Submit file
Filepath C:\Windows\Tasks\svoutse.job
Size 272.0B
Processes 1488 (random.exe)
Type VAX-order 68k Blit mpx/mux executable
MD5 b0174c22a551b976f6f6cbb542d98589
SHA1 5644165e7b92924249647992a85fc55b98a902ea
SHA256 5cfb285497fbb771ae0f167002fc3df8303a34ce88ca3d2a22daf74fedf54d09
CRC32 A6803046
ssdeep 6:79wQzbXE///UEZ+lX1Qye6YctI4y0lbqut0:7rrk//Q1214Vmut0
Yara None matched
VirusTotal Search for analysis
Name 4c5d3a6eb838ee84_05835e05-6121-4708-9111-fa231fd15bbd
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\05835e05-6121-4708-9111-fa231fd15bbd
Size 845.0B
Processes 2184 (firefox.exe)
Type ASCII text, with very long lines
MD5 f43259d17094432899cb43caf31997a8
SHA1 fb6cb6ab96206325b2fbb95047962e155f98855e
SHA256 4c5d3a6eb838ee848b8ace4007660b13bcfbabf02cf9635bd8943eddf4d1f817
CRC32 777C8942
ssdeep 24:F7qX7XrCRkmyK7v96h4pCpQ7ijpQJiV8oJpTl:FqX7jm5gQuNQo9R
Yara None matched
VirusTotal Search for analysis
Name e39c464ba75141d4_bbf14a46-52db-4c51-a02d-9c4a3e7ad641
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\bbf14a46-52db-4c51-a02d-9c4a3e7ad641
Size 845.0B
Processes 1212 (firefox.exe)
Type ASCII text, with very long lines
MD5 0bf8943d8c6215f53dd0bf7e1eabbf22
SHA1 8b4648e7508dc0e6a95675ca200042dc48709d4e
SHA256 e39c464ba75141d495f0d9fd5a535f8b5ad175f6e533fa15c82db24b12536507
CRC32 8E9AB761
ssdeep 12:8y6TvJih4yKBS4zQqMuSHAJiFgpITjJxpQUycijpQJiDE8G9Ti3yn:tUkmyK7v96cbpCpQwijpQJiQ8G9TT
Yara None matched
VirusTotal Search for analysis
Name 6b86b273ff34fce1_telemetry.failedprofilelocks.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\Telemetry.FailedProfileLocks.txt
Size 1.0B
Processes 724 (firefox.exe)
Type very short file (no magic)
MD5 c4ca4238a0b923820dcc509a6f75849b
SHA1 356a192b7913b04c54574d18c28d46e6395428ab
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
CRC32 83DCEFB7
ssdeep 3:U:U
Yara None matched
VirusTotal Search for analysis
Name 95cb5c9ce49edd11_fe950943-fc74-4339-9743-298b6f4d5f6e
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\fe950943-fc74-4339-9743-298b6f4d5f6e
Size 816.0B
Processes 2296 (firefox.exe)
Type ASCII text, with very long lines
MD5 34940028933f34a15f773e057faecad2
SHA1 7a30735db6771367c97e3db0e1d1b52a0c6c413c
SHA256 95cb5c9ce49edd11614c811d9b4a47efc9f416edb1c9e7e5f9ddd91087268715
CRC32 A2CA9FEF
ssdeep 24:9V5ykmyK7v96sFjpzApQvvvijpQJieG8j+:9VHmROQvSNQoei
Yara None matched
VirusTotal Search for analysis
Name 6d962df111fcb941_9bd80c9c-b09a-47ab-a61a-f24b47a41f96.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\9bd80c9c-b09a-47ab-a61a-f24b47a41f96.dmp
Size 82.8KB
Processes 1044 (firefox.exe) 2208 (firefox.exe) 2184 (firefox.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Sat Sep 21 12:16:32 2024, 0x820 type
MD5 a80604a959157cc59ebcf96bbbd825fa
SHA1 72f54427e6351ba4850fe1ea521a4bc5865029eb
SHA256 6d962df111fcb9411d09a85da22420a794ea158137b24ab056e221ce801b8d1c
CRC32 6078FD3F
ssdeep 384:jn8Aly3fmI0jnRmywDRX785dH66ErqOQ86ht5ktjlLPfC:jnhlLI0jnRYDW5dH6flQaJm
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 5136a49a682ac8d7_msvcp140.dll
Submit file
Filepath C:\ProgramData\msvcp140.dll
Size 439.5KB
Processes 2588 (376da640f6.exe) 2600 (firefox.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 5ff1fca37c466d6723ec67be93b51442
SHA1 34cc4e158092083b13d67d6d2bc9e57b798a303b
SHA256 5136a49a682ac8d7f1ce71b211de8688fce42ed57210af087a8e2dbc8a934062
CRC32 FE675AE5
ssdeep 12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14_cookies.sqlite-wal
Empty file or file not found
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite-wal
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name b3dfa692f7da19ee_BKJEHCAKFBGDGCAAAFBGCGIIDA
Submit file
Filepath C:\ProgramData\BKJEHCAKFBGDGCAAAFBGCGIIDA
Size 5.0MB
Type SQLite 3.x database, user version 69, last written using SQLite version 3038003
MD5 c395620f9a8337341636a78a98f5b3d9
SHA1 97700ec4db7362e02a56df5e70dd828ad9823d24
SHA256 b3dfa692f7da19eede9aa2fe2ac76052cfaa32a7d30cc53b88ea5ef23ec32624
CRC32 476CDB88
ssdeep 192:StsqHQnwkYjcoBMc+uySBQies13A29D+oBpp0:StsbwVTBMc+uySOiJ3Z
Yara None matched
VirusTotal Search for analysis
Name fafd69985915744d_1a89e6be-7a47-455c-9541-3c3b3330f95e.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1a89e6be-7a47-455c-9541-3c3b3330f95e.extra
Size 782.0B
Processes 2884 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 0bc5e4b921b7ea15f7041ea8c5d35ce9
SHA1 b436f0db8bba1d5010b1e0cc76527de46948aaf2
SHA256 fafd69985915744dfe52b87f9c0d20682e64de15918282fbf8bc9ee51c8859f4
CRC32 CAA8FC84
ssdeep 12:YNTvJih4yKBS4zQqMuSHOJiFgpyZKTjJxpQPKcijpQJiIF8si3Xn:YRkmyK7v96ybpympQPVijpQJiS8sG
Yara None matched
VirusTotal Search for analysis
Name a6628bcd500e502a_bbf14a46-52db-4c51-a02d-9c4a3e7ad641.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\bbf14a46-52db-4c51-a02d-9c4a3e7ad641.dmp
Size 85.1KB
Processes 1212 (firefox.exe) 2556 (minidump-analyzer.exe) 2936 (minidump-analyzer.exe) 3472 (minidump-analyzer.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Sat Sep 21 12:17:29 2024, 0x820 type
MD5 70e869c9866294769f3788946d41fc8f
SHA1 e09554f2adeb48a02341a3ba7f301e5897c26154
SHA256 a6628bcd500e502a26f598e764f378c587f2cfef6c777fac37108c23620d1028
CRC32 724828F1
ssdeep 384:HU8Qly3TlwIQsNdShrXmygDpSbAQOVG8cvLqWHcqKgQptjlLPfe:HUFl0wIQsNdShrX4D1VG8cvLqWHQJq
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name fd4c9fda9cd3f9ae_cookies.sqlite-shm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\cookies.sqlite-shm
Size 32.0KB
Type data
MD5 b7c14ec6110fa820ca6b65f5aec85911
SHA1 608eeb7488042453c9ca40f7e1398fc1a270f3f4
SHA256 fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
CRC32 DDC506B6
ssdeep 3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
Yara None matched
VirusTotal Search for analysis
Name d820603eb308a436_FBGIDHCAAKEBAKFIIIEB
Submit file
Filepath C:\ProgramData\FBGIDHCAAKEBAKFIIIEB
Size 12.0KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 0647d44f50372ccfa8f1e56b37e9fe76
SHA1 5e7fac4675932c1faa55f925c958ca1c75324a20
SHA256 d820603eb308a43651cc248106d188c1602f5de460de659300721f03cd863dbc
CRC32 A8996995
ssdeep 192:O6nHM58sK1zjyPySpI+JpVgxXhKQuylvICf/eEoBqIrv0bEHa+n:O6sPPZIcpmxO3BqIr0IH/n
Yara None matched
VirusTotal Search for analysis
Name cecf59649ccf1d76_EGIIIECBGDHJJKFIDAKJ
Submit file
Filepath C:\ProgramData\EGIIIECBGDHJJKFIDAKJ
Size 8.8KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 07951590532d8114ea1caca9ed7e0a39
SHA1 7a4bebc2f20ead9546fa5749aafe739ad5f551de
SHA256 cecf59649ccf1d7668ad3c7119bf9b380d6d5c339d7f0faeb2f29f163fd3f3ee
CRC32 E3F3A320
ssdeep 192:ZDnijRILMMdaWaLbFlp/PuFbylfFw8AxSwSO:pmsy7wIO
Yara None matched
VirusTotal Search for analysis
Name 83b382590dd33f1f_561157fcb2.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000048001\561157fcb2.exe
Size 900.0KB
Processes 2336 (svoutse.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bed5a31137c8f14547c95972266ee03a
SHA1 cb60f287f6b8ca6a09027d1e1ddd60bb59e83d31
SHA256 83b382590dd33f1ffa15780965d110c2deb01891d5014c5134e55dd5a8f0f46c
CRC32 F702E17A
ssdeep 12288:yqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDga+T3:yqDEvCTbMWu7rQYlBQcBiT6rprG8am3
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 824fae3331b95e2f_KEHDHIDAEHCFHJJJJECA
Submit file
Filepath C:\ProgramData\KEHDHIDAEHCFHJJJJECA
Size 40.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 41c19a9e8541fcb934c13c075bf47721
SHA1 648a7622d533d79b9a0bb31dc370134ec3a75ed7
SHA256 824fae3331b95e2f88ca60c87a6c9569086906ec76fc1db8d6dee9adddc4e80c
CRC32 560F7642
ssdeep 48:+35TqYzDGF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:Ulce7mlcwilGc7Ha3f+u
Yara None matched
VirusTotal Search for analysis
Name 0b4fa57eec7a102e_9af36891-14e2-4960-9330-28c2e6c4cdd4.dmp
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\1pfa5s83.default-release\minidumps\9af36891-14e2-4960-9330-28c2e6c4cdd4.dmp
Size 91.3KB
Processes 2208 (firefox.exe) 2296 (firefox.exe) 2184 (firefox.exe) 2556 (minidump-analyzer.exe) 1044 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Sat Sep 21 12:16:15 2024, 0x820 type
MD5 d6ca002fab1615275411f5d76a29819b
SHA1 4154a94772f066b8d914e1568a020d787099f34e
SHA256 0b4fa57eec7a102e63aeebaf04ce1362eb7102b1184030a8f658200af30514e5
CRC32 26709D57
ssdeep 384:cAYnN1yly3CYAaeq+aioimyeD+G9SXghHcE+G7C8JnFqdi1zSQxmSsNtTji:cAE1ylWeRaioimD+zgR0G7C8JF+AxYw
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name edb006e05cfa8501_FCFIEHCFIECBGCBFHIJJKEGHIE
Submit file
Filepath C:\ProgramData\FCFIEHCFIECBGCBFHIJJKEGHIE
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 3f5ca3e29b1b60e298aeca0a32164c03
SHA1 f9b5ee59c31a3b06a6b8e476b22d2d7cf1fa8b66
SHA256 edb006e05cfa85015aa76c758d6298c279fd318cff0dbb286927c7ad45105488
CRC32 E1ACA097
ssdeep 24:TL2C0RlPbXaFpEO5bNmISHdL6UwcOxvo5:TYLOpEO5J/KdGU1Eo5
Yara None matched
VirusTotal Search for analysis
Name 8916fb1d76be83e4_HJJJJKEHCAKFBFHJKEHCFIIDAE
Submit file
Filepath C:\ProgramData\HJJJJKEHCAKFBFHJKEHCFIIDAE
Size 192.0KB
Type SQLite 3.x database, user version 4, last written using SQLite version 3031001
MD5 6b9c2ac2b5025e180231d8d38ece698c
SHA1 36f5cfe6ac59aaa7d7173555edeef5caa9bf61c6
SHA256 8916fb1d76be83e42cd2f7b41ee06706fe0adb936259ed7a7daa4dbcb4c51fcb
CRC32 95ACFD74
ssdeep 12:DBl/lkf12Of5LZWfY0xpMujuHWMu6N2OHjWOzMbdym/eRgBoQFmgW2FOmO6Mz6LX:DLlI1x7WxHaiSlMxosJF/Ezo
Yara None matched
VirusTotal Search for analysis
Name 071b05714aeb238d_3f42309d-df3c-45c3-9182-d32d2d3f5808.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\3f42309d-df3c-45c3-9182-d32d2d3f5808.dmp
Size 85.5KB
Processes 2600 (firefox.exe) 2588 (376da640f6.exe) 2296 (firefox.exe) 1236 (explorer.exe)
Type Mini DuMP crash report, 11 streams, Sat Sep 21 12:16:03 2024, 0x820 type
MD5 e4a7d1625aebacba392b07f26868532e
SHA1 a662ef800433bb9714758532ba7f3161b9363404
SHA256 071b05714aeb238d74258cbf5276042e4d2d8072a8782f27de92be2dd51548e1
CRC32 ED59F5AB
ssdeep 384:ZFwjDEL4F6ly33YM+MeRmyw0DnsgeZfR20ZD3140rM1kOIOFbPvlg:HCYL+6lJM+MeRzDaZfR20ZD314du
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 5d9269b26e4c2eff_05835e05-6121-4708-9111-fa231fd15bbd.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\05835e05-6121-4708-9111-fa231fd15bbd.extra
Size 784.0B
Processes 2184 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 0dc86c5cc75cc04a2d37206cf944a045
SHA1 ddbc87054fb17966ccc817dd2981586761c461d6
SHA256 5d9269b26e4c2eff49377c8934a30b62485ee8b42a8342ba1b9812afa75e42d8
CRC32 C2B1AD06
ssdeep 24:YRkmyK7v96h4pCpQhvijpQJiPqF8oJzTl:YKm5gQ8NQoPaz
Yara None matched
VirusTotal Search for analysis
Name 169c04331f72fe4a_DHJKJKKKJJJKJKFHJJJJECBFCG
Submit file
Filepath C:\ProgramData\DHJKJKKKJJJKJKFHJJJJECBFCG
Size 5.0MB
Type SQLite 3.x database, user version 53, last written using SQLite version 3031001
MD5 f77930486de1b1bb4b397d5d8f3cd124
SHA1 e3f5727a0774c7cba17f0b10569012dcea24cb55
SHA256 169c04331f72fe4ae9958da09e1b28ec5910f7ea523d6105b7e4ad521b2baaee
CRC32 D85072F9
ssdeep 96:Dm8j5PnH6xY2Wi+67tH2iB4q2xfX7ZbiZzdFzb4PPwI3A7:l5/IYOTAlQzdFzaDm
Yara None matched
VirusTotal Search for analysis
Name 64308fda3f0566fb_svoutse.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\0e8d0864aa\svoutse.exe
Size 1.8MB
Processes 1488 (random.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e0bb28202965797f022195320f3287d5
SHA1 d3091b477ff9a7f04bbe7008df1d16fb13876759
SHA256 64308fda3f0566fbbafed8d1bc257c957310a6dd1b3cc53f232d0b65e206dc24
CRC32 1534BB61
ssdeep 24576:U8zDHBGaCxNUfGac6MbjmsgGc+XIXQ3wpaJEgeqeqWcGM/eVnv0ySamsqMP6f:UOB9CxmoVPgGrIClgqMhnv0ySLs/Cf
Yara
  • themida_packer - themida packer
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 349cee7795e578b2_3f42309d-df3c-45c3-9182-d32d2d3f5808.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\3f42309d-df3c-45c3-9182-d32d2d3f5808.extra
Size 756.0B
Processes 2600 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 4fb7fcdd81b87d38bd9e7f5c6158d936
SHA1 14077c973fc33f142965684047ed6871ce7b0760
SHA256 349cee7795e578b232959a52385858fab893d4d36a5cd25708a2ab62da72cb2b
CRC32 D75F25C8
ssdeep 12:YNTvJih4yKBS4zQqMuSHBJiFEpITjJxpQZWijpQJiL8En:YRkmyK7v96rbpCpQIijpQJiL8E
Yara None matched
VirusTotal Search for analysis
Name 51e6e00317de7978_1a89e6be-7a47-455c-9541-3c3b3330f95e.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1a89e6be-7a47-455c-9541-3c3b3330f95e.dmp
Size 84.1KB
Processes 2884 (firefox.exe) 2716 (firefox.exe) 2556 (minidump-analyzer.exe) 184 (firefox.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Sat Sep 21 12:16:56 2024, 0x820 type
MD5 df28f0864370015c56287cd8ea7f0487
SHA1 c4e27a713a3029fa6ba2562afe8b42b5f17c01a0
SHA256 51e6e00317de7978cb6b00c30704cd0b6c481caf78f41edf47f7b6b2c02bec3a
CRC32 D38DF1BB
ssdeep 384:BrkCly3H4+kTbrgmyHDw+SYUxuelti8BYdCOokAaJmUz9R1vlY:BrflUlkTbrgfDWAeltiAYHmqo
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name f5c49c96fc41436d_9bd80c9c-b09a-47ab-a61a-f24b47a41f96
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\9bd80c9c-b09a-47ab-a61a-f24b47a41f96
Size 843.0B
Processes 1044 (firefox.exe)
Type ASCII text, with very long lines
MD5 e9677e7acae2bcaef3afec09308a26e9
SHA1 759e5fd6a95ce2419da392e598e36ef794aad77f
SHA256 f5c49c96fc41436d3cc885557d31703eb43174f9e17abc08459402e95badc201
CRC32 82223B8A
ssdeep 24:VBtUkmyK7v96IK4pUOApQq3ijpQJiL8kk:zJm1DUFQqyNQoI
Yara None matched
VirusTotal Search for analysis
Name edd043f2005dbd59_freebl3.dll
Submit file
Filepath C:\ProgramData\freebl3.dll
Size 669.3KB
Processes 2588 (376da640f6.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 550686c0ee48c386dfcb40199bd076ac
SHA1 ee5134da4d3efcb466081fb6197be5e12a5b22ab
SHA256 edd043f2005dbd5902fc421eabb9472a7266950c5cbaca34e2d590b17d12f5fa
CRC32 085C6D2B
ssdeep 12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name ba06a6ee0b15f5be_mozglue.dll
Submit file
Filepath C:\ProgramData\mozglue.dll
Size 593.8KB
Processes 2588 (376da640f6.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 c8fd9be83bc728cc04beffafc2907fe9
SHA1 95ab9f701e0024cedfbd312bcfe4e726744c4f2e
SHA256 ba06a6ee0b15f5be5c4e67782eec8b521e36c107a329093ec400fe0404eb196a
CRC32 28C04754
ssdeep 12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 50ce6ac65396e9f0_88a6e7e5-4d1d-473e-9946-722f2f3b3f49.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\88a6e7e5-4d1d-473e-9946-722f2f3b3f49.extra
Size 784.0B
Processes 3328 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 8da25102b121e27e686f6fa354bd7e06
SHA1 1b1c74a5c63a2b60afff38c2eab9035347113b71
SHA256 50ce6ac65396e9f0017c0e90c29af8562a9836dd7b59709802c4431d72f89294
CRC32 6FF10013
ssdeep 24:YRkmyK7v96lSoKipympQ7dijpQJiLO8EEzU:YKm7oBdQINQoLUV
Yara None matched
VirusTotal Search for analysis
Name 64a2307e7c880db2_fe950943-fc74-4339-9743-298b6f4d5f6e.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\fe950943-fc74-4339-9743-298b6f4d5f6e.extra
Size 755.0B
Processes 2296 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 ce5af66998b5000726bc944782b5db01
SHA1 433e149730e9af9883eb75a80a37ab1e6797d563
SHA256 64a2307e7c880db25dc417aae4584c13b9fe7327087551dc607db173381dd1e2
CRC32 92DBFCD5
ssdeep 12:YNTvJih4yKBS4zQqMuSHQJiFcjpBdTjJxpQDijpQJir18cRv+n:YRkmyK7v96sFjpBppQDijpQJih8u+
Yara None matched
VirusTotal Search for analysis
Name 1514d63b3d26ecbe_bbf14a46-52db-4c51-a02d-9c4a3e7ad641.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\bbf14a46-52db-4c51-a02d-9c4a3e7ad641.extra
Size 784.0B
Processes 1212 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 5988e12e09adb3563ac9279af856c2c8
SHA1 5c184361e0e51e68f07ca1c01ca373b952cdfd74
SHA256 1514d63b3d26ecbe5c59844b1acef9357219d9b059d4de2fd68585a6849e453f
CRC32 20DF8666
ssdeep 12:YNTvJih4yKBS4zQqMuSHAJiFgpITjJxpQwkvvijpQJiD6G18GNTi3yn:YRkmyK7v96cbpCpQvXijpQJiOG18GNTT
Yara None matched
VirusTotal Search for analysis
Name be2dfd26ff8afc25_1ad1df49-1767-4777-81d0-942a4e0e0de9.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1ad1df49-1767-4777-81d0-942a4e0e0de9.dmp
Size 83.7KB
Processes 184 (firefox.exe) 724 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Sat Sep 21 12:17:10 2024, 0x820 type
MD5 a7c0b5c169e114c6744953f1ea000eab
SHA1 9d4434cc87e7c319438636ac413a1c872a6ed206
SHA256 be2dfd26ff8afc2593028f15119ee73c2c38f5e3606909ce66d702626060a3bb
CRC32 353EFF12
ssdeep 384:MqlDEL4Fly3bix+1x0KNImymDzlMtaOu1nUyhHa8R6ihiGQJvkOIOFbPvls:DlYLIlfx+1x0KNI+Detm1nhhHa8heJta
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name dac908bd55b370fe_lastcrash
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\LastCrash
Size 10.0B
Processes 2600 (firefox.exe) 2296 (firefox.exe) 2208 (firefox.exe) 1044 (firefox.exe) 2184 (firefox.exe) 2884 (firefox.exe) 184 (firefox.exe) 1212 (firefox.exe) 3328 (firefox.exe)
Type ASCII text, with no line terminators
MD5 0a2d2eda7636444edc47ecf0d22ec0a8
SHA1 8818e1734acaa88c344347335fb1375e609805be
SHA256 dac908bd55b370fe643deed8b4483e514fe6275d43d16054eacdddc0b88da145
CRC32 EE08DE60
ssdeep 3:LDcXTX:v8X
Yara None matched
VirusTotal Search for analysis
Name f09a4a1704bbb54d_88a6e7e5-4d1d-473e-9946-722f2f3b3f49.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\88a6e7e5-4d1d-473e-9946-722f2f3b3f49.dmp
Size 86.8KB
Processes 3328 (firefox.exe)
Type Mini DuMP crash report, 11 streams, Sat Sep 21 12:17:43 2024, 0x820 type
MD5 2888a6d8c5e1f320b8fe650e205ed3fd
SHA1 eab1319e5e4f07aaf915013f80ef2282d90d5abd
SHA256 f09a4a1704bbb54dd0a97f75e53bf4abc43a012bb8e97be01907ba0ddc7214eb
CRC32 8B55BE34
ssdeep 384:41utQly3xqgriyGFEmyw4v7cHccdKZYWz4NFRVsM/FoCfZHxVGzBR1vlc:41gQlZgriyGFEY4sNVsM/FgM
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 5b524b971d4f1019_1ad1df49-1767-4777-81d0-942a4e0e0de9.extra
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1ad1df49-1767-4777-81d0-942a4e0e0de9.extra
Size 784.0B
Processes 184 (firefox.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 38a61fccc046d0c92fb1509da74a5a99
SHA1 184964ba3f8f102fd76266be32da7a3caa6ace14
SHA256 5b524b971d4f1019dc5b585f96e1b1b6f54992bff19edf0e84704e56d86ad07d
CRC32 50DB5B22
ssdeep 12:YNTvJih4yKBS4zQqMuSHhpJiFWQp4IXpTjJxpQ0cijpQJiPBh8Ujji33Un:YRkmyK7v961ipdpQ0cijpQJiPBh80h
Yara None matched
VirusTotal Search for analysis
Name 37226c0f7fb3065b_88a6e7e5-4d1d-473e-9946-722f2f3b3f49
Submit file
Filepath C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\88a6e7e5-4d1d-473e-9946-722f2f3b3f49
Size 845.0B
Processes 3328 (firefox.exe)
Type ASCII text, with very long lines
MD5 0f4eea6b92097c865628a743d6ca55dd
SHA1 f52df34cd9de6c1efea704545664734a4bb3e5a9
SHA256 37226c0f7fb3065bfea35117891c37a5748bf44593104eed506abc74c244a133
CRC32 ED41D269
ssdeep 24:DaWAykmyK7v96lSoKipx7/pQpijpQJib86mWsuzU:om7oBxtQINQolG
Yara None matched
VirusTotal Search for analysis
Name 74ebbac956e519e1_softokn3.dll
Submit file
Filepath C:\ProgramData\softokn3.dll
Size 251.8KB
Processes 2588 (376da640f6.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 4e52d739c324db8225bd9ab2695f262f
SHA1 71c3da43dc5a0d2a1941e874a6d015a071783889
SHA256 74ebbac956e519e16923abdc5ab8912098a4f64e38ddcb2eae23969f306afe5a
CRC32 1CE2A51D
ssdeep 6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8934aaeb65b6e6d2_vcruntime140.dll
Submit file
Filepath C:\ProgramData\vcruntime140.dll
Size 79.0KB
Processes 2588 (376da640f6.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a37ee36b536409056a86f50e67777dd7
SHA1 1cafa159292aa736fc595fc04e16325b27cd6750
SHA256 8934aaeb65b6e6d253dfe72dea5d65856bd871e989d5d3a2a35edfe867bb4825
CRC32 A23699DD
ssdeep 1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name deb1bd627ce6aa31_376da640f6.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\1000042001\376da640f6.exe
Size 2.7MB
Processes 2336 (svoutse.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5ff1e3119a10f4eb493cdafeeda60dba
SHA1 018852ae388c5fbc47d85d306f861d26d5e0ea31
SHA256 deb1bd627ce6aa3176c16ca5270eca5dda7a7e9ba7f56d510a1dceaba620e05d
CRC32 AD6C0139
ssdeep 49152:Rl68GDom6tjk2COMp3SkZPfwniZGMigc:Rl68GDoRjTCJp3hZHwnD7
Yara
  • themida_packer - themida packer
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name c119a54b6bef3a48_JJECAAEH
Submit file
Filepath C:\ProgramData\JJECAAEH
Size 80.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 255929949dea51a2f43a1f40e63764ec
SHA1 8f32ab419264fdad05f4f3828db3c1cd38d919fd
SHA256 c119a54b6bef3a48234950dc07fe70f73b69d1390ef0235e66481faa1048ead6
CRC32 F7A79605
ssdeep 96:5Bc7fYLKYZCIdE8XwUWaPdUDg738Hsa/NhuK0l0q8oc5PyWTJereWb3lxzasq9u4:5BPOUNlCTJMb3rEDFAa6E/
Yara None matched
VirusTotal Search for analysis
Name ca890ebecdedc9f4_fe950943-fc74-4339-9743-298b6f4d5f6e.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\fe950943-fc74-4339-9743-298b6f4d5f6e.dmp
Size 85.7KB
Processes 2296 (firefox.exe) 2208 (firefox.exe) 2184 (firefox.exe) 1044 (firefox.exe)
Type Mini DuMP crash report, 11 streams, CheckSum 0x00000004, Sat Sep 21 12:16:15 2024, 0x820 type
MD5 fd8cfc6665db73322ed8b06eb0e7a1b1
SHA1 b7fb853be0a9078b908ae93a041acc15c28b10ee
SHA256 ca890ebecdedc9f40e9e85e359676e272ee2554c54ffffdcaf87ef211a2f2f44
CRC32 49642D07
ssdeep 384:2rkZly3bDkX+v2tmy6DZ4swj5jSWO/K4LMCh7vxrR9R1vlY:2rQltX+v2tyDujSWORDxZo
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 88f9dc0b9a633e43_BGHJJDGHCBGDHIECBGIDAEHCGD
Submit file
Filepath C:\ProgramData\BGHJJDGHCBGDHIECBGIDAEHCGD
Size 512.0KB
Type SQLite 3.x database, user version 11, last written using SQLite version 3031001
MD5 dd47ebe6866ad2ab59d0caa1de28d09e
SHA1 afdf6eb7a01bb7ef4c9d768b65abbbeae5ba2663
SHA256 88f9dc0b9a633e43c6d2c6fae136e782c15aa38c1601dcff948987f1c2a391c3
CRC32 8DEE9EEA
ssdeep 24:DQHtJl32mNVpP965hKN0MG/lZpNjCKRIaU5BnCMOkC0JCpL3FYay:DQfrbWTTTqtStLm
Yara None matched
VirusTotal Search for analysis