Dropped Files | ZeroBOX
Name 18c5c9be898c65c5_id.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\id.txt
Size 9.0B
Processes 732 (customer3.exe)
Type ASCII text, with no line terminators
MD5 033f7f6121501ae98285ad77f216d5e7
SHA1 6df036de595c98ba47361a68c18f0fa2f97854ed
SHA256 18c5c9be898c65c5e5c51ac3e94feacff0b991f8463a3a18eb524e9f7e6131a8
CRC32 148F0FB1
ssdeep 3:2uG:rG
Yara None matched
VirusTotal Search for analysis
Name 4021df68f91881e7_error[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\error[1]
Size 3.2KB
Processes 752 (mshta.exe)
Type HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 7d46fb61e9b1b0d57df00e1b3d392e33
SHA1 5b14562e288d76851164bd8a65d13d987d6da375
SHA256 4021df68f91881e7e4bf54d6795f9186ccab9a3813f5c4358c1b5a81560da891
CRC32 BAD674A7
ssdeep 96:CwhabJ/1xjqDbT2pftwEjlddFBdd5w3dddDzMddv+dd8WfFhllhX4PyAvdh:TcC2pTnsPkIDll4KIh
Yara None matched
VirusTotal Search for analysis
Name 86f76a78e6a047e7_plugins-edge.crx
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\plugins-edge.crx
Size 216.1KB
Processes 732 (customer3.exe)
Type Google Chrome extension, version 3
MD5 27e209eb09b3b189a7b1404c167287c1
SHA1 3675c6c6254f48280ae3a1c528ddab2663efb0f7
SHA256 86f76a78e6a047e7078b56c61c9d65826a727ab2bc0f2d421c5ffb41e60a4dbc
CRC32 D30DC47F
ssdeep 6144:h8m9xpcRpztb+rAxb04NyNKVLoSSaLw70QD08Hbwl5:Sm9LcRbb+Y0wyNGoSSaDQACi5
Yara None matched
VirusTotal Search for analysis
Name a5d1355faa6ccdcc_id-edge.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\id-edge.txt
Size 32.0B
Processes 732 (customer3.exe)
Type ASCII text, with no line terminators
MD5 61a1097d8931a08711609a2547c94272
SHA1 58b8b23b7ba2b9c194bdd7297beee92c2f0ed4c3
SHA256 a5d1355faa6ccdcc223fc792efbb0f02abbd7c2455abb43150af455737ade895
CRC32 707AEC0B
ssdeep 3:2OJaCNYCDEsCn:2mJyAWn
Yara None matched
VirusTotal Search for analysis
Name b142632ccb968e4d_chrome64.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\chrome64.bat
Size 197.0B
Processes 732 (customer3.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 431927c4715b4e73c9b68ff675515391
SHA1 17bd1a044f85f1776fe932c01b8e707110d44f9c
SHA256 b142632ccb968e4d404827499ea7895f578e809ce9778ff263ae1d68f8234861
CRC32 01AE462A
ssdeep 6:hRzLvGC2HEmiVPMFwNDDbzPHEi1wPTEzw9AJn:HnNvVP4wNDDbzPEi1nz+AJn
Yara None matched
VirusTotal Search for analysis
Name a60f167cc8ae4c83_edge64.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\edge64.bat
Size 198.0B
Processes 732 (customer3.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 034f32918b9a82d1b9a6093da084c18c
SHA1 a6707689018d044f343767a908991dbf182e466b
SHA256 a60f167cc8ae4c8387c459796252feaa5bee8b5562b3c096ba475af3547798ae
CRC32 6441D4F2
ssdeep 6:hRzLvGC2HEmiVPMFwNDDbzPHEi/sUKo+UM:HnNvVP4wNDDbzPEi/sUV+X
Yara None matched
VirusTotal Search for analysis
Name b4310364823b3c55_debug.log
Submit file
Filepath C:\Program Files (x86)\Google\Chrome\Application\debug.log
Size 198.0B
Processes 1444 (chrome.exe)
Type ASCII text
MD5 1bd8c79893cc8df4fef6c8f6792c3adb
SHA1 c87d3f3379ae20de73832766a7032f43e8fb06b2
SHA256 b4310364823b3c55d1ff0d032ed32729b1cc34e467f42eff440f58768697a1a1
CRC32 C117752C
ssdeep 6:qWGvj8RU4LGGmm3V4v89vj8RU4LGGmm3V4vF:UYRU4LGBm3V6mYRU4LGBm3V6F
Yara None matched
VirusTotal Search for analysis
Name f49551a01cfafab7_chrome7.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\chrome7.bat
Size 195.0B
Processes 732 (customer3.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 7ef7773c254443450f54987d3c274064
SHA1 1ec753356808523b2d6f675f38f58e7cba8797f3
SHA256 f49551a01cfafab752f234299fda793d87a536126ce865d0f003c288534e71e8
CRC32 A8377566
ssdeep 6:hRzLvGC2HEmiVPMFwNDDbzPHKzHhwPTEzw9AJn:HnNvVP4wNDDbzPmz+AJn
Yara None matched
VirusTotal Search for analysis
Name f8bc270449ca6bb6_vcruntime140_1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\vcruntime140_1.dll
Size 35.9KB
Processes 732 (customer3.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 ab03551e4ef279abed2d8c4b25f35bb8
SHA1 09bc7e4e1a8d79ee23c0c9c26b1ea39de12a550e
SHA256 f8bc270449ca6bb6345e88be3632d465c0a7595197c7954357dc5066ed50ae44
CRC32 36920A2E
ssdeep 384:diWe6RE3c6lqst5nZvS05fJjPXR51RWmbzw+XfeDky85xHrwB2BWrYKW4dHRN7qp:at3csN7xPXdRdP/ve6HrEUSKZz
Yara
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • IsPE64 - (no description)
  • IsDLL - (no description)
  • IsConsole - (no description)
  • HasOverlay - Overlay Check
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check
VirusTotal Search for analysis
Name 0e3dc4ccd259716b_settings.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Size 40.0B
Processes 2772 (chrome.exe)
Type data
MD5 62325aa04f35880232330f344df8018c
SHA1 58fe9532ee8d96e8d12448408cf3ccf9d0542543
SHA256 0e3dc4ccd259716b24376fddb4ee07a6c227f8bcb2532a7dd75bb36a4290e7cc
CRC32 6F0BEA7C
ssdeep 3:FkXJRYcTUM:+wcTb
Yara None matched
VirusTotal Search for analysis
Name dcf7f7f405d6a188_chrome.reg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\chrome.reg
Size 414.0B
Processes 732 (customer3.exe) 1556 (main.exe)
Type Windows Registry text (Win2K or above)
MD5 ffa3d9e74e84f0b398cd7d16ef655f64
SHA1 fefb7280c354a7f9301c24d3a767fa2a42dc3c82
SHA256 dcf7f7f405d6a188c075c7a8a43c04ded41e19ad1164ccbaacc08f2824720bec
CRC32 C96982E0
ssdeep 12:jBJ0SK0JLsALUThR+q25PSbLJwrALUThR+q25PSv:jBJtJo7TTwKblwr7TTwKv
Yara None matched
VirusTotal Search for analysis
Name 4efe3f9a2d748444_edge86.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\edge86.bat
Size 204.0B
Processes 732 (customer3.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 beed94f2506fb6e82079ccc77978e902
SHA1 d5c731e836b202f90bada731aa1d5ede55369be5
SHA256 4efe3f9a2d7484443ad82063be9627d7f91068e01316aff4d3d1912f5f5d0d5c
CRC32 CCB3493F
ssdeep 6:hRzLvGC2HEmiVPMFwNDDbzPHEifgG+sUKo+UM:HnNvVP4wNDDbzPEi4ZsUV+X
Yara None matched
VirusTotal Search for analysis
Name b98f6cc05e7a64fa_edge.reg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\edge.reg
Size 148.0B
Processes 732 (customer3.exe)
Type Windows Registry text (Win2K or above)
MD5 84ca171b5ca3d26e4fed7a32025f3907
SHA1 d6e38106f659001fa06089fccb6e3f3bc8f6138d
SHA256 b98f6cc05e7a64fa43ca94b573cc5ddf274879e7002d85e7b1b9cf8f002d4023
CRC32 2A253C16
ssdeep 3:jBJ0nMWXZ6RKZFNKo1qp2YR3so3KRfg0cgTuLGkTXwL6AFnSZLtn:jBJ0nMhRKLNKoN83tuTcgTuLGCXMSvn
Yara None matched
VirusTotal Search for analysis
Name 4b60226dce9dac7c_plugins-chrome.crx
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\plugins-chrome.crx
Size 216.1KB
Processes 732 (customer3.exe)
Type Google Chrome extension, version 3
MD5 b76a448d15029df55127cdf2ae9e350d
SHA1 8f7cd0366ca1592b254dab83bd5ebbe58f0455de
SHA256 4b60226dce9dac7c5e8791903c1f93a08e4a45448f925c683be7bf740a64abe2
CRC32 AE1E2BB0
ssdeep 6144:c8m9xpcRpztb+rAxb04NyNKVLoSSaLw70QD08HbwlE:pm9LcRbb+Y0wyNGoSSaDQACiE
Yara None matched
VirusTotal Search for analysis
Name e04fdcd2d1d1e7ea_15ff4248-f9e3-481d-9f1f-ee763326d2b2.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\15ff4248-f9e3-481d-9f1f-ee763326d2b2.dmp
Size 809.0KB
Processes 1444 (chrome.exe)
Type Mini DuMP crash report, 10 streams, Sat Mar 27 08:06:48 2021, 0x0 type
MD5 8c153887dba9a28484b76b8142b3fedf
SHA1 6f696d6d8777d1242369d3f65b15052c7e2c6756
SHA256 e04fdcd2d1d1e7eab45983bf394125605ad9822e626162c4c9a1d75a93b22103
CRC32 B9641746
ssdeep 3072:mnJ7SgfcwG414rVT/o1VmqPxZaRxQgt7zpstFaWMNogevPNV4aXw:ebjFE8QaM40aXw
Yara None matched
VirusTotal Search for analysis
Name 6b01add656de1f80_id-chrome.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\id-chrome.txt
Size 32.0B
Processes 732 (customer3.exe)
Type ASCII text, with no line terminators
MD5 0167419b601a93258aeb85fc6e775893
SHA1 0a144617b0dd5c5cd4aee3afa8e950f19fda15e8
SHA256 6b01add656de1f80a188fb7407856c06b54c39946642a949c2eba2ee5801ca07
CRC32 C0485AE4
ssdeep 3:BwP2DtCHznh40:FcHznh40
Yara None matched
VirusTotal Search for analysis
Name 0b0b869acf51621d_main.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\main.exe
Size 555.0KB
Processes 732 (customer3.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 5c71e31e6e3dfca45c77321bb3c2b41c
SHA1 caf54ffa0b213013a6a22203eebcd347664dd6c6
SHA256 0b0b869acf51621d8f59eb6612265843ad44077a1811d96c5bb10c8b29db13df
CRC32 75A5F0BA
ssdeep 12288:2595d2lBHBv5308BUNe/tdakEVDxSuAcq3i5WK:2595ev530Y+e/iBN058WK
Yara
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • network_tcp_socket - Communications over RAW socket
  • network_dns - Communications use DNS
  • win_registry - Affect system registries
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
  • IsPE64 - (no description)
  • IsWindowsGUI - (no description)
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check
VirusTotal Search for analysis
Name e3b0c44298fc1c14___tmp_rar_sfx_access_check_5349562
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_5349562
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name d5542791f99ece3f_metadata
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
Size 114.0B
Processes 1444 (chrome.exe)
Type data
MD5 964d504d1e32bc9e89a8827fd81812f5
SHA1 d1ca666d4195abaeab85266972880167a485df4d
SHA256 d5542791f99ece3fb0bd54bfa3aeb623426f281cba84890d036cb059009f50f5
CRC32 1D5AD235
ssdeep 3:mTll+Xl9GNW5lklKp/vlp5Xh+ignB4l:mTlEbs8xT
Yara None matched
VirusTotal Search for analysis
Name 447d61413d5994cd_chrome86.bat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\chrome86.bat
Size 203.0B
Processes 732 (customer3.exe)
Type DOS batch file, ASCII text, with CRLF line terminators
MD5 b93ce87e5520944913a3df67914b8540
SHA1 41dceeaa7f5f81e716522ac109e8540df448b4bd
SHA256 447d61413d5994cd441187ce798e33c094ee91c0d0f5a1766acd4141a480909b
CRC32 94ECDE87
ssdeep 6:hRzLvGC2HEmiVPMFwNDDbzPHEifTbPTEzw9AJn:HnNvVP4wNDDbzPEibUz+AJn
Yara None matched
VirusTotal Search for analysis
Name 9d82451d22500c27_chrome-set.reg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\chrome-set.reg
Size 913.0B
Processes 732 (customer3.exe) 1556 (main.exe)
Type Windows Registry text (Win2K or above)
MD5 3e340776563dabf93d6facd415dc014c
SHA1 99c220b33423ce5307405a23507f4d4023b256f0
SHA256 9d82451d22500c2723d18e096971989902ddef5cbf6bc2215f26e9f95e8f5390
CRC32 6762C867
ssdeep 24:jBJtJyK2STxP2fLgTxP2cTxPCvSTxPCvfLgTxPCvcTl:9JDyK2m2Y2IKmKYKy
Yara None matched
VirusTotal Search for analysis
Name 19607490a1222efb_edge-set.reg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RarSFX0\edge-set.reg
Size 222.0B
Processes 732 (customer3.exe)
Type Windows Registry text (Win2K or above)
MD5 0db2ffa87a4b4887fccbe3690ce480a7
SHA1 2795597cd2d7a1cedbdf44232d6bab291565cfa6
SHA256 19607490a1222efbc6c7746e3c2fcfd28a9049a1d518b6b07be76072c629d7ac
CRC32 14115FCA
ssdeep 6:jBJ0nMhRKLNKomLx78zTcgTuLVVqJJnwLx78zTcgTuLVVnr:jBJ0SK0JLh8zJumQLh8zJuTr
Yara None matched
VirusTotal Search for analysis