Dropped Files | ZeroBOX
Name 595b0995ee464451_svchost.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\svchost.exe
Size 23.5KB
Processes 3204 (svchost.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 fb002bdf8ca98dc1b9c6c27e9f4a9eed
SHA1 52b1474b90d64d7243de1f1d0632cfd1eff2dd88
SHA256 595b0995ee464451d30bce4f097b4c47ec615a21bac069a14034cc6d1c5acf6c
CRC32 C808C184
ssdeep 384:ITWSEFDn65Egj6RGiYCINTY6xgXakh2oZDJmRvR6JZlbw8hqIusZzZ+4:gm7OM9YX0MRpcnuA
Yara
  • keylogger - Run a keylogger
  • Win_Backdoor_njRAT_Zero - Win Backdoor njRAT
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsNET_EXE - (no description)
  • IsWindowsGUI - (no description)
VirusTotal Search for analysis