Dropped Files | ZeroBOX
Name 6934b3ed84f5141d_wmk521cv.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\wmk521cv.dll
Size 8.5KB
Processes 2704 (csc.exe) 2548 (pixel.exe)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 17c5c83b3ee75dd9f3148a4babd44060
SHA1 0df3460eb216af3afd469f17a744b1d0eb9e01e8
SHA256 6934b3ed84f5141df6a971ff90586685b55cd8ed31828b0d9ba1a7488cfc2a4d
CRC32 AEDE258D
ssdeep 192:CxhVsIlJlHlHlHlHldlglfbflnldICNuBaZMg5Mqdexd:61lJlHlHlHlHldlglfbflnljABu5MqEv
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
VirusTotal Search for analysis
Name ae11144f426028e5_wmk521cv.0.cs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\wmk521cv.0.cs
Size 8.9KB
Processes 2548 (pixel.exe)
Type C++ source, UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 58b10ef6ba0da88788f1aac56ce7e2db
SHA1 48221936b98aac14ead7c4589513d074365414ec
SHA256 ae11144f426028e50e77d64a66aeb954e169f627f8abfe403791032594834520
CRC32 07EB5779
ssdeep 96:JO1vYGpHKU5fZBDeXWuaLN0lWeCAaEjcqQDJ7iiLYkhxdP7NFa/COAoTOyt13IPw:AaGu7vpcfDFfckhxdP7NA/CxoSytSPf4
Yara None matched
VirusTotal Search for analysis
Name be562c1f1d849a7e_CSC9871E7C4CEA542F6AFFA46AB4717B8F8.TMP
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\CSC9871E7C4CEA542F6AFFA46AB4717B8F8.TMP
Size 652.0B
Processes 2704 (csc.exe)
Type MSVC .res
MD5 f4bfc3d784c4a469c64e3cee9316a81a
SHA1 51af13200e3d0a37810e0c8103d95a80de7f4410
SHA256 be562c1f1d849a7e9e87752cbb9122e86ff0780f3a36b2cf81bdb941dc60d805
CRC32 BA21EF3F
ssdeep 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryaxak7Ynqq32PN5Dlq5J:+RI+ycuZhNeakSmPNnqX
Yara None matched
VirusTotal Search for analysis
Name 5912f43eaf458619_wmk521cv.cmdline
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\wmk521cv.cmdline
Size 188.0B
Processes 2548 (pixel.exe)
Type UTF-8 Unicode (with BOM) text, with no line terminators
MD5 276e0073d554145de4d947401b291a45
SHA1 d87cd9dc7d620dfa14d4f15d74e8adb01a88bba8
SHA256 5912f43eaf45861952ecc8bbad64dd21bef0b5e246398759aa8d2bd1f8ff39dc
CRC32 13F5530C
ssdeep 3:0HXEXA8F+H2R5BJiWR5mKWLRRmWxpcL4E2J5xAI/+iQCIFRVRMxTPImWxpcL4E2T:pAu+H2L/6K2mQpcLJ23f/+zxszImQpcG
Yara None matched
VirusTotal Search for analysis
Name d8402b43fc505bd0_RES22D.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\RES22D.tmp
Size 1.3KB
Processes 2764 (cvtres.exe) 2704 (csc.exe)
Type Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x48e, 9 symbols
MD5 0df3c66e647c82c4a9a0e7f5a9e80580
SHA1 9c51cd9c100440ea7279e1a1cbaae3c55fea882f
SHA256 d8402b43fc505bd0045905ebfb18f5fad5efeec01b4d98be5c10a7d045dd0b42
CRC32 E6CBB26F
ssdeep 24:H0gzW99/VGt4HBLFwrUeKnxfII+ycuZhNeakSmPNnqw2d:a/VnhLUfKnxg1ulea3aqwG
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_wmk521cv.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\wmk521cv.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name c5e4b6c1200c0bdd_wmk521cv.out
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\wmk521cv.out
Size 444.0B
Processes 2548 (pixel.exe)
Type UTF-8 Unicode (with BOM) text, with CRLF, CR line terminators
MD5 b7eae0e76fb6d8f0af661c51be9b547e
SHA1 57ae36bc928f3c7e0eba9fe4eb92ac4e396c27b4
SHA256 c5e4b6c1200c0bdd1e05d799829647cf28deb79296dd4f4ab206e9e8f4996eaa
CRC32 2DF55FF1
ssdeep 12:K4OLM9qR37L/6KQOLMeXOLMyKa8GIKO5SBFN+y:K+9qdn6K2WyKa2KoSDQy
Yara None matched
VirusTotal Search for analysis