Dropped Files | ZeroBOX
Name 191640e0be19e828_csrss.exe
Submit file
Filepath C:\ProgramData\Microsoft\csrss.exe
Size 1.8MB
Processes 2672 (66e579d0cbf2d_win.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
MD5 049d2f0e9e03c057d906287c2003331b
SHA1 89b7da67d641237e2734edb2c1f5542b38946ea4
SHA256 191640e0be19e828563b27d2f20f57a31eb8291e4ecb68567ab95b41fe35e002
CRC32 C5AC62F8
ssdeep 49152:KDmghls3y1+XfWL6Vcp5/oTUjcikfZCIQ8qeXQR/Z:wmghls5Bq/HkZQGi
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis