Dropped Files | ZeroBOX
Name 77c7c10b4c860d5d_gpt.ini
Submit file
Filepath C:\Windows\SysWOW64\GroupPolicy\gpt.ini
Size 11.0B
Processes 2540 (WW20.exe)
Type ASCII text, with CRLF line terminators
MD5 ec3584f3db838942ec3669db02dc908e
SHA1 8dceb96874d5c6425ebb81bfee587244c89416da
SHA256 77c7c10b4c860d5ddf4e057e713383e61e9f21bcf0ec4cfbbc16193f2e28f340
CRC32 E4327249
ssdeep 3:1EX:10
Yara None matched
VirusTotal Search for analysis
Name 7ee927529f7108d8_BrowserMetrics-63327DF3-A54.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-63327DF3-A54.pma
Size 8.0MB
Type data
MD5 2f83a72f095bc42146a77940353d776c
SHA1 7b525857dbae3b79cce3f836475604f46d60008a
SHA256 7ee927529f7108d85841c07e1d05bafa82cb7d5a9a0db3ad9cf804c5a7b1632e
CRC32 1A7C42BC
ssdeep 6144:H9LG+zeL7c/lhRgdTTEDtsHVdUXaHmVGKPFIrgHkjdr:t6bcF
Yara None matched
VirusTotal Search for analysis
Name 60cae903e3e5d7b7_secure preferences
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Size 36.0KB
Processes 2540 (WW20.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 97eac3144d1c672146fa063112a23259
SHA1 35773a85e89eb1bb3b62df09648239b81c8ee71d
SHA256 60cae903e3e5d7b756fe136e767603bc52c63eb73a7a6364951fa7f0e9dfeea8
CRC32 6AC85EB1
ssdeep 768:gaYRdUQm7LHLOL75V1kXqKf/pUZNCgVLH2Hfg7ur6Rj0nut/oplw:gRmprOL3An/E
Yara None matched
VirusTotal Search for analysis
Name 041f891934add728_g8nybexvwyvz5q97arupa5ld.exe
Submit file
Filepath C:\Users\test22\Pictures\Minor Policy\g8NyBEXVWyvZ5Q97arupA5LD.exe
Size 161.0KB
Processes 2540 (WW20.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a19ba7f0bf808aefee30b29e8f84fc83
SHA1 a339f81ccc84ab7c1f93a8f6add6e08fa64a46ef
SHA256 041f891934add72852c8fda245c95da959d7f98cc580383d198e42f2de039634
CRC32 EBE308E2
ssdeep 3072:hi45BjzKAwpzSmWDeGv9qbiFodx9riWesp60sqhxeOhO6bQRKAcTcwFvhD9ck:hvO+GiviRDrOEQcTDH
Yara
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 92bbaf30871bd32d_gpt.ini
Submit file
Filepath C:\Windows\System32\GroupPolicy\gpt.ini
Size 272.0B
Processes 2540 (WW20.exe)
Type ASCII text, with CRLF line terminators
MD5 7d7b2946708e5254b8996d3ae964e0a7
SHA1 01e350de5cf78dd1ba5e8686fee884ff0f240e95
SHA256 92bbaf30871bd32d6fe34a6df757ad8acd375552918a80c45c935091c9df729e
CRC32 71B0380C
ssdeep 6:1WsMzYHxbnvEcvg+5Rnn3jGoanMzYHxbnPonn3k:1q0Hxbnt4UaM0HxbnX
Yara None matched
VirusTotal Search for analysis
Name 69ab28aff7a6636d_debug.log
Submit file
Filepath C:\Program Files (x86)\Google\Chrome\Application\debug.log
Size 272.0B
Processes 2792 (chrome.exe)
Type ASCII text
MD5 f2b418e74272bdfb08a21d5555ede49e
SHA1 4dcb62e222b1923fed92c7fc3fa7aba493bd310b
SHA256 69ab28aff7a6636d3a31cd2f86ac5778c266a9b6174ce867373a90260dee1471
CRC32 F301B663
ssdeep 6:qcUmSlNoqYlO6URU4LGGmm3V4vMURU4LGGmm3V4vF:nyyqYlO3RU4LGBm3V6ZRU4LGBm3V6F
Yara None matched
VirusTotal Search for analysis
Name 7ea0bf4c6aedea55_verified_contents.json
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\_metadata\verified_contents.json
Size 2.5KB
Processes 2540 (WW20.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 a7ab3b26ce7440334b6c629c0942bccd
SHA1 6bf37c068e1d7bd160ea8be3ba9ccf583602270b
SHA256 7ea0bf4c6aedea556e4c8ff9ae6780b9a798160bdb017e57f269d84df93de65c
CRC32 AEAA61E7
ssdeep 48:p/hHEOqvgxyYLANXTaVneMkWObUW1gKvsFCI1TpC9NZkakd7k64u/z//Kk6eA5yL:RaOcbYLANWNkWa1bsFXTbaMQiuvf5yvD
Yara None matched
VirusTotal Search for analysis
Name ebab1c7bd7862362_2FzJ7F6c35BhCU0ceDud5nhG
Submit file
Filepath C:\Users\test22\Pictures\Minor Policy\2FzJ7F6c35BhCU0ceDud5nhG
Size 64.3KB
Processes 2540 (WW20.exe)
Type Google Chrome extension, version 3
MD5 0b9997160126ca2a6e2ccbbcbb77e96e
SHA1 15d738369d1b3574e73d61f5ade04c658b3cea59
SHA256 ebab1c7bd78623624ea30b83e8f23b948302b906a531d7fc02be802825118193
CRC32 051F3D55
ssdeep 1536:JUe1Le6V6s3EX+BPmjPEW8HgfEoqnJcGnnsvk4CM8gncZr:KSL9VjEO4jCgfXqFsc4/8Br
Yara None matched
VirusTotal Search for analysis
Name 550bb391de36341f_icon64.png
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\icon64.png
Size 894.0B
Processes 2540 (WW20.exe)
Type PNG image data, 64 x 64, 8-bit/color RGBA, interlaced
MD5 c26ebef247e149f64e7ca779199f86a9
SHA1 b5da3b312cd6b8aba9771672355ab7270188baa0
SHA256 550bb391de36341ff363c2dc1f1733ec6b1441fa09dc184aa009d1282766cee1
CRC32 5085CC8C
ssdeep 24:VTn4sxdeY0FCdpWTWczaZjQUzHoRjlGsHpJ5JxRX43joj:5n4gdeY0wpozay0oRpxbooj
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8735f32860bfc070_BrowserMetrics-63A01ACF-ABC.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-63A01ACF-ABC.pma
Size 8.0MB
Type data
MD5 22edf398e1bb631d335cb372c9a9a46e
SHA1 b9219ff145e957ff2319aca91426cbff0abaf06d
SHA256 8735f32860bfc07036a24a5158f15c7ea28327c522a70fa93d0854a182511290
CRC32 AC33D5B5
ssdeep 96:biW3Hu3M05KJF1LelP8sN5Mo9CpynMpNKW1v66O2nvOSk7Qc5G4b7qLkUwEkLqOR:Reh5KH1LepNQy1zakSAhEkLZ9S7P6IQ
Yara None matched
VirusTotal Search for analysis
Name 5a3ec8851acd1bb6_CrashpadMetrics.pma
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
Size 1.0MB
Type data
MD5 aea7ffdba870ea9d59d542f890fecc8c
SHA1 2efe83750eebdfacc148d376cc4edfdf8e5d2ac9
SHA256 5a3ec8851acd1bb62d270e9bdca9625da9f34df69ef39608bc2ce3de68960056
CRC32 CB7B9D10
ssdeep 12:bHiZXAVMMOKEKSCemJKlkQPdl/JG89Hy3aJ0oMFgigpCbUycIXuYJ05:bwQOMzBS+Mk0/JvWoMeigp1y5eYW
Yara None matched
VirusTotal Search for analysis
Name e50411577472fbff_git.pdn
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\git.pdn
Size 8.5KB
Processes 2540 (WW20.exe)
Type Paint.NET image data
MD5 f6ea1049aef13cf93cbcf720e577481e
SHA1 2c4074f98b2ad47f16d2d66325afad0be294cb2d
SHA256 e50411577472fbff88ce38a5d8f49045ddd1f3d863800d41edb06130702bbe68
CRC32 6D708F59
ssdeep 192:7wTPla6nbRNyS62JkeE6BsK1E6YE6bOFR0lbW17b3FkQ/l8cmaE6yyY3/lUE6CGJ:ynbzQEE6BtE6YE6o0W5lNmaE6mUE61nJ
Yara None matched
VirusTotal Search for analysis
Name 466336b1a9861ed8_metadata
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
Size 114.0B
Processes 2792 (chrome.exe)
Type data
MD5 a2cc92676f40dc2a922ed19eb53d5916
SHA1 8214fcd3950fd463cb6f6485519e7867a1ad6068
SHA256 466336b1a9861ed8101437da5de55f1d9fcd77226759ca3f134dec23b8e56d05
CRC32 6AB296D4
ssdeep 3:mTll+XlJMk+gt/W/lzX9l8MTIVqQf4l:mTlEBFqzXHE064l
Yara None matched
VirusTotal Search for analysis
Name 98ff909d00b0c220_jquery362.js
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\js\jquery362.js
Size 87.8KB
Processes 2540 (WW20.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 326a07128e7bf6172285f706543884d6
SHA1 14b2d90e06e46c7cbd6097238ea3cda7ad27e66c
SHA256 98ff909d00b0c220432538f13e6855f40997573108e4e5ec23348e39a49c5c53
CRC32 009C8A35
ssdeep 1536:7NjxXUcrnxD9o5EZxkMVC6YLtg7HtDuU3zh8cmnPMEgWzJvBQUmkm4M5gPtcNRQA:7hqmCU3zhINzfmR4lb3e34UQ47GKb
Yara None matched
VirusTotal Search for analysis
Name c85a48c47cd32370_index.css
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\css\index.css
Size 1.9KB
Processes 2540 (WW20.exe)
Type ASCII text
MD5 c1b92acc31f0ead2b33fa4e58689da76
SHA1 2d3096f7f4912d3a8c6008adf12633edee86a754
SHA256 c85a48c47cd32370752e8752c422c6454db852ee39c35b61b10b406235b3b4b0
CRC32 EC2A7BB3
ssdeep 48:e0xCUoL9jB8Qqmd6OtKCeTzFus3ktiG89n:ePU29jB04e/FusUtfE
Yara None matched
VirusTotal Search for analysis
Name 857192361731ac41_newtab_script.js
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\js\newTab_script.js
Size 1.0KB
Processes 2540 (WW20.exe)
Type ASCII text, with CRLF line terminators
MD5 5d83cc54062b2721442d09445a0ec03b
SHA1 fd5a5cfdd636f0c64b7f5606ce264d152efa8432
SHA256 857192361731ac419d1629a630a349430cc5df64cac4f615b882267a13164e22
CRC32 6F94AE78
ssdeep 24:29AoxEFOuCO0X9F+4y4+wCRN0kxRzSwpxShLbopAJ:t5hRakjttC
Yara None matched
VirusTotal Search for analysis
Name 826172f90aa17ba8_registry.pol
Submit file
Filepath C:\Windows\System32\GroupPolicy\Machine\Registry.pol
Size 6.2KB
Processes 2540 (WW20.exe)
Type data
MD5 05c4079110b8f65ec083182e2d870e04
SHA1 0b2d16dd8575c6f87c6bd66267cdf8eaba363a11
SHA256 826172f90aa17ba887682da7277b444c06513177653d727acbb146a2308af3a7
CRC32 8B58FA6A
ssdeep 192:FlRRCDN74hvoD5KL0+fLfYT7CcAzXEP0IhYY4WwDiZ:nRRCDN74hvoDEL0+fLf27CcAzXEP02Y0
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 285f7c23e6e9ecec_icon128.png
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\icon128.png
Size 1.6KB
Processes 2540 (WW20.exe)
Type PNG image data, 128 x 128, 8-bit/color RGBA, interlaced
MD5 0d3ef5c4c2d807bce3aedf6e3f3fba19
SHA1 8eb433ab62974a6e40c529494c15ea3e8eda3159
SHA256 285f7c23e6e9ecec74948ab343587de194f4e004c1c1ddd4031d6cf7c3e957c2
CRC32 DBDEFEE1
ssdeep 48:UyIYZB0cadP9JDSMGvh63cVlCJspNqq/f:UvSB0cal1CUyCJs/qq/f
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name fe8163ea61d58a25_index.html
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\index.html
Size 1.8KB
Processes 2540 (WW20.exe)
Type HTML document, UTF-8 Unicode text, with very long lines
MD5 58800b243d298e4dcb9fc14868afef19
SHA1 f5a769ef49e410379473f75ed33c232ea4de4c24
SHA256 fe8163ea61d58a25a3740e2559a4ef014b0699a7155db6fe3ef2f0e65a0ad23b
CRC32 6E0D71DB
ssdeep 24:hYMuHPNVnAVI6FNbfBN5U/Xu3fuDiOXgS29g+o+w77dW2a0H9t1EAsg7:SHPt6rb/K/ufpO/D7dW2a0dt1EPg7
Yara None matched
VirusTotal Search for analysis
Name d252e80eacb76934_dqbakwkbrb3j7nnoflaz4gei.exe
Submit file
Filepath C:\Users\test22\Pictures\Minor Policy\DQBAKWkBRb3J7NnOFLAz4GEi.exe
Size 172.0KB
Processes 2540 (WW20.exe)
Type HTML document, Non-ISO extended-ASCII text, with very long lines, with LF, NEL line terminators
MD5 5de14d00ca4a7208f35a7128a96f01e3
SHA1 90e5925ccb25aa68128a9f8341017a9ba45cba06
SHA256 d252e80eacb76934120d1872bf2a05757ade3e1acea9a10194c4c6d13edc5ef8
CRC32 A731F11D
ssdeep 1536:QMS9k4UlBGtKZPxMD+tTXyVKTfhk9fS2N50BMd/IKIDxkjqKtZS4n2TsNCmrBd3n:QSlaB870FywmQcwU82lq5yU
Yara None matched
VirusTotal Search for analysis
Name 8a397c229b8046f5_background.js
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\js\background.js
Size 452.0B
Processes 2540 (WW20.exe)
Type ASCII text
MD5 f434162d002340d88b4826dab8b9a449
SHA1 0df91e17de14b6fb5f5a6ee4a806bd980e490ab6
SHA256 8a397c229b8046f566260c19bf2d3672ec74a7781bb3fe3c03766210dc047b87
CRC32 CE377F01
ssdeep 12:019oOBtVBwM1DVYMzSK8ZcViu38F3nxXb3mLM:0/x0M1DVfzSK8LuMF3npmLM
Yara None matched
VirusTotal Search for analysis
Name d777497e8fdff4b6_logo.png
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\logo.png
Size 9.3KB
Processes 2540 (WW20.exe)
Type PNG image data, 400 x 100, 8-bit/color RGBA, interlaced
MD5 54143e7c9a34b3c90208e31ec89784db
SHA1 b35c9578ad47ca6fb21ba5c9df2b43a5d6aa67fe
SHA256 d777497e8fdff4b68f52dc3f1b80ed8b175d621505f1a0946d270330617671aa
CRC32 87F48A1B
ssdeep 192:SGHAd/N1RzouvdUyuDjghelcFaxZI44rP08wjLlNXZnykEfkeYIL:SjlUuCyYblcFaxZI44Q8wjLKfDYIL
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 9eac634bf6c374e8_icon32.png
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\icon32.png
Size 948.0B
Processes 2540 (WW20.exe)
Type PNG image data, 32 x 32, 8-bit/color RGBA, interlaced
MD5 9ba4939dc93647e3af0aa92b98df5c41
SHA1 7fa2a98c20bc061763ff3a98001fe589cd040fa2
SHA256 9eac634bf6c374e8945527ee35a572c2ce0a67ae417bae5e405bc0482833d938
CRC32 7136960C
ssdeep 24:DABfIcd3ZpaSIScJseiakddVA/1nTXTDsA6b3IqnFZjnihJq:klIjSynBDsA84qnjYU
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8ed5837b345030ea_logojg.png
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\icons\logoJG.png
Size 8.6KB
Processes 2540 (WW20.exe)
Type PNG image data, 400 x 100, 8-bit/color RGBA, interlaced
MD5 753c6eaf7df33a2bea5dcbe95f2b682b
SHA1 c7ad4410846ee99874d200129069dd5a6e8e4022
SHA256 8ed5837b345030ea3279be42bb5027ca4ae5c5a9a406c27221430c9b8d31ebd5
CRC32 5224F9AB
ssdeep 192:sXETzn2YlWrwgcRGaQcmPWzGWiz+pWPEl0puSjRefB7:V/nirwFRGXxQciCdjYfB7
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 11efc7be317a5296_bc75ff5f-a049-4596-b624-23db42c50fe1.dmp
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\bc75ff5f-a049-4596-b624-23db42c50fe1.dmp
Size 889.5KB
Processes 2792 (chrome.exe)
Type Mini DuMP crash report, 10 streams, Mon Dec 19 08:03:38 2022, 0x0 type
MD5 04d25171a101a1daf5c12e9304998bf3
SHA1 aa9ac3e35383dfcf036451fbd9539b1c4c27067d
SHA256 11efc7be317a5296fc57260f01ecb4a2f91594f1e99e853afe5d8c77307d658b
CRC32 3C6E6BF7
ssdeep 3072:MFuLRr6ogIm+aa9o+U80kUPmoZXGiM3t/CS6nhL/ND9pgDT4ndNREEDP+7sJTOUF:b+xa9EkGcU+FBg
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e7307835b70cbfda_manifest.json
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhpphpanfghgfhmmdmcfndlfiecpmcmk\1.0.3_0\manifest.json
Size 954.0B
Processes 2540 (WW20.exe)
Type ASCII text, with CRLF, LF line terminators
MD5 6b155859a38badedcb7b08b1556c2a71
SHA1 17fe12d0cfe854d4dcae1b6683e31c4da77dc9fe
SHA256 e7307835b70cbfdacfca270badb877f4758e377f9d8deb8748de99884b0570e0
CRC32 0B4C3CCD
ssdeep 24:BX7t0B/GJUFDcpnnPJM4h23RoP9hb7kNUu1o9:RxY/G+FDwnP2o23g0e
Yara None matched
VirusTotal Search for analysis
Name d37fcb160d37cfdd_settings.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
Size 40.0B
Processes 2748 (chrome.exe)
Type data
MD5 a3122d4670c51912628b97bdd6fffb80
SHA1 45d2e3060e09f46071125d6125983c81ae4970a1
SHA256 d37fcb160d37cfddefea794094044b7e588d44c4883c72ba0ef1503e5f9c7d59
CRC32 77809701
ssdeep 3:FkXD3WyqUm:+ix
Yara None matched
VirusTotal Search for analysis