Dropped Files | ZeroBOX
Name 1f16772f9b57ac99_pbngpffj.url
Submit file
Filepath C:\Users\Public\Libraries\pbngpffJ.url
Size 100.0B
Processes 2312 (vbc.exe)
Type MS Windows 95 Internet shortcut text (URL=<file:"C:\\Users\\Public\\Libraries\\\\Jffpgnbp\\Jffpgnbp.exe">), ASCII text, with CRLF line terminators
MD5 bbf42a9b6159bf1fdf660cda0e5ca4d5
SHA1 1f08da40ea0aa0313f936dfe8deb983946f42f04
SHA256 1f16772f9b57ac99948b3faa85c04d7af613368c172955d82106321b82f97dbf
CRC32 78AD150E
ssdeep 3:HRAbABGQYmTWAX+rSF55i0XMDDMz1bMzLHysGKd5ov:HRYFVmTWDyzag5o3Ssb5y
Yara None matched
VirusTotal Search for analysis
Name 8db032a108bfbc9b_jffpgnbp.exe
Submit file
Filepath C:\Users\Public\Libraries\Jffpgnbp\Jffpgnbp.exe
Size 918.0KB
Processes 2312 (vbc.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 91fb23dcf91534e17f881f58d5aa746c
SHA1 467458812be736f7868740128e17804ad4d2e9da
SHA256 8db032a108bfbc9b5d4d2be6f466add20a81685196253867b99e6456e02adadf
CRC32 7651C012
ssdeep 6144:xZEcZy5taWXTZBSG5fB/i/goaOeD32RFbLCdF9ae8FvSxUjewQhM4kqlPyn+lP3:P857TZBpL5jeFWFQeYjdGdkAPya
Yara
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis