Dropped Files | ZeroBOX
Name 57d89a52061d70d8_sqlite3.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\sqlite3.dll
Size 910.4KB
Processes 2996 (runonce.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 d79258c5189103d69502eac786addb04
SHA1 f34b33681cfe8ce649218173a7f58b237821c1ef
SHA256 57d89a52061d70d87e40281f1196d53273f87860c4d707d667a8c7d9573da675
CRC32 513FD198
ssdeep 24576:Rbv4aZ7CJa5zzDfVoOLVizxd4c0ReY/kCq:RkhKzzrpLVizxdzYK
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 512e4e95427a8c66_6511-iOQ--
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\6511-iOQ--
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 f4c540f52d5c08d24a79805eda1d7abf
SHA1 22be46826df7693f58736adb232ab2da790f2571
SHA256 512e4e95427a8c66b2993b27bb23d99cdab2ebd6e9e8937c7f6a39ed8c6a5b94
CRC32 95C9FB3A
ssdeep 24:TLmg/5UcJOyTGVZTPaFpEvg3obNmCFk6Uwcc85fB34444z:T5/ecVTgPOpEveoJZFrU1cQB34444z
Yara None matched
VirusTotal Search for analysis
Name f8d05b76dffb3d65_x.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\x.exe
Size 331.5KB
Processes 2560 (powershell.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 6f4096ce716d8842658c18792441c7f9
SHA1 bbe04f6dcd8c1de6d5b666b55f8da15fbdd90bba
SHA256 f8d05b76dffb3d653b029d87a05ce2d20015209bbaf2728eebb07ee6aca33ace
CRC32 5E352954
ssdeep 6144:ZmEvlM6zq/UKroWt5hKz3RT49wn757Qzz9DQcb0l6c9iF91wLJ3Tif701ZyD7de:8Evq6R+5MR42n7az9kcQl6c9iFA93TiU
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • Is_DotNET_EXE - (no description)
  • ConfuserEx_Zero - Confuser .NET
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name b7c225ef3cc3e875_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 2560 (powershell.exe)
Type data
MD5 81ca4510272caf505e8091e9a28cb716
SHA1 71414aeec9f1e4a6f5a461b01700cc9cc992cd9e
SHA256 b7c225ef3cc3e87506150eb140e7b9cc127a3469c50a808854acac71a53d98bf
CRC32 FC31E90F
ssdeep 96:EtuCcBGCPDXBqvsqvJCwoRtuCcBGCPDXBqvsEHyqvJCwor/47HwxGlUVul:EtCgXoRtCgbHnorLxY
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 876db29840f16bd7_sqlite3.def
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\sqlite3.def
Size 5.5KB
Processes 2996 (runonce.exe)
Type ASCII text
MD5 1652ae49c99bc78dfc018aa848f9be43
SHA1 846c61da64eec0b2213542fba9c4157a717229d0
SHA256 876db29840f16bd747cff18bbd5dd1b2c0594c8a9409479e944fa243fde4229e
CRC32 DE7D86B2
ssdeep 96:GcuN/gR+7Ogn9XRMcGM3KOGOF++hwIMtvQENw+Y0aR:E/Q+7Ogn9RKOBF++eHvQENw+cR
Yara None matched
VirusTotal Search for analysis