Dropped Files | ZeroBOX
Name 9f7afff27cce47c6_remotepcprinter.exe
Submit file
Filepath C:\Users\test22\Documents\NordVPNnetworkTAP\Lang\RemotePCPrinter.exe
Size 128.0MB
Processes 2544 (4909_7122.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 891fe751513f2d4ce7217786db07b92a
SHA1 d41ec4004e8252950dfce7f100f5461d2c48e35e
SHA256 14ad16bcb8a4a61e4b70c9a9577a0081c7d8e04b981d2d4ec9e6047727881ef0
CRC32 841F0AA7
ssdeep 49152:fT2Wd4IbtCaIZ+SgnCxaC+1R5oWjhRSTp8Z2WTWw/10ttew:SW5QxajvOWM8UWTWw/It
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • ftp_command - ftp command
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis