Dropped Files | ZeroBOX
Name 56510920355a5531_Microsoft Corporation.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe
Size 93.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e9987ac76debe4d7c754f30cec95d618
SHA1 7678e6011456d26f579c7dcdd238ff651cfa4edd
SHA256 56510920355a5531d174cb55ebe86f4b0d85c748d0e15dd78849a29f0f3763d1
CRC32 2B6C31C5
ssdeep 1536:GYqUZFRPmGvMzLsvOnjEwzGi1dDvDogS:GYRRPmGvMzIvOMi1dXR
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 711a6108ba2ce6ca_fransescopast.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\FransescoPast.txt
Size 6.0B
Processes 1872 (mod.exe) 2168 (server.exe)
Type ASCII text, with no line terminators
MD5 3905d7917f2b3429490b01cfb60d8f5b
SHA1 f78a71af8bbf8cc2f6f313549d4da14bd3771359
SHA256 711a6108ba2ce6ca93dd47d6817f2361db10d8ab6eec89460b2dfc2c325efabe
CRC32 873586F3
ssdeep 3:IA:9
Yara None matched
VirusTotal Search for analysis
Name f87e55f1a423b65f_autorun.inf
Submit file
Filepath C:\autorun.inf
Size 55.0B
Processes 2168 (server.exe)
Type Microsoft Windows Autorun file, ASCII text, with CRLF line terminators
MD5 40b1630be21f39cb17bd1963cae5a207
SHA1 63c14bd151d42820dd45c033363fa5b9e1d34124
SHA256 f87e55f1a423b65fd639146f71f6027dbd4d6e69b65d9a17f1744774aa6589e1
CRC32 903049B1
ssdeep 3:It1KV2PHQCyK0x:e1KAwCyD
Yara None matched
VirusTotal Search for analysis
Name 80ad1cc7b3a784da_app
Submit file
Filepath C:\Users\test22\AppData\Roaming\app
Size 5.0B
Processes 1872 (mod.exe) 2168 (server.exe)
Type UTF-8 Unicode (with BOM) text, with no line terminators
MD5 d43c5b07c128b116b7bc8faf7b8efa9d
SHA1 dd3540ad4ae14b21b665d108cf4570c2dfa6a6fa
SHA256 80ad1cc7b3a784dad618a445af0c8cf3efa903f82a814756f2aaa7b57f45791f
CRC32 4D70D254
ssdeep 3:k:k
Yara None matched
VirusTotal Search for analysis