Dropped Files | ZeroBOX
Name 2d50185784755b53_dialog.scale200.jpg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\dialog.scale200.jpg
Size 643.4KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type JPEG image data, baseline, precision 8, 1001x633, frames 3
MD5 709351e45cc8f62830f58fd1b52179f3
SHA1 1271e2c3c3b3904f4844191ba32c2d223bc80de9
SHA256 2d50185784755b53625a315617f48d773f1402fc956769c2e80b9937a93cfc88
CRC32 479C4DF9
ssdeep 12288:Ai0xRDS8LQhlfHe9QqsmR4g2QXGlYajJPv3Lk7c0L:A9xS8LQhIQq1R+lYajJnLE
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 136e10c68a963c08_raidrive.service.x64.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.Service.x64.dll
Size 3.2MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 1f1a157a1aea2a4aaea238c03b81c3d3
SHA1 a79012103ccd3a71a2b0f8b7c7d00f68e97a425c
SHA256 136e10c68a963c087bee1be3f6233a6a4dcd57593d72288520120abd38b01012
CRC32 A0E633F7
ssdeep 98304:SCytkdeAl6hziTpNa+u2cv4jvFltvEIo:LYI6hzi1kzvytUI
Yara
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name c62ec6ab69ab02a7_raidrive.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.exe
Size 1.3MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 c97ab5a25d050007c966a801382d8462
SHA1 42406aef8d5e8768f821d69a53a8f0c48085d17d
SHA256 c62ec6ab69ab02a7583ee6b38cd4b97134ac45463a1e23792589ce693114b233
CRC32 61720C9A
ssdeep 24576:ffX8dQasMTshfD19J+FtdTUe5k41qgmkAz7wC7ba5iwA57w:ffsdQa8hf/1skam/z8Cq5iw9
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 5c83635e0437388a_raidrive.service.x64.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.Service.x64.exe
Size 163.0KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 3744a15be854ffdc803e1f76ec20d8cd
SHA1 8e6d486f7a1bc48cf6a290df6fb7af3afad6a7a1
SHA256 5c83635e0437388a22941d0484062d5940404191653e4d58f56121e254aa640b
CRC32 52786DDA
ssdeep 3072:78vbzyQ6Y1YXrbNK+3FRxacPEMk6n1QAhiW3+mBch:7szAXNK+3FZr1QyiWhB
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • ASPack_Zero - ASPack packed file
  • Malicious_Packer_Zero - Malicious Packer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 355eda5278a9e48d_lzmaextractor.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\lzmaextractor.dll
Size 22.3KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 17dd7ecbb68515799ef219c27751f38a
SHA1 a4ff08c0f5fb89d7ecfe2b9a30989a023cc66231
SHA256 355eda5278a9e48d4cbef33e40adf14c1b8fee9902ab2b4a7f72fe13fb583540
CRC32 C229FA6A
ssdeep 384:lOw0clp5NZrrcrj4zL0/zL0s+Y7h7X2Ip4vDqjdAA1m5wMvaSu7wGo:lOAlPxmx+Y7N2Ip4Lqxf1mlv2U7
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name d2a8106098a005af_msif51e.log
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSIF51E.LOG
Size 47.9KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type Little-endian UTF-16 Unicode text, with CRLF, CR, LF line terminators
MD5 5694d6a36d9f9fb40e5ff2897d5292d4
SHA1 17d634f5eeb22a1c3a27f898cb7c9d3f39883f04
SHA256 d2a8106098a005afafa565ef3ae05694d58b4c42e9a7285cfce00f83dbdb8ed9
CRC32 7DA07A41
ssdeep 768:/k6DdvgcmbhGnnuiAIIBMiEEqjU3tNjOTpUquAU/qRTyZzIJF6M3z5CjG8mgV3pW:86RvgcmbhGnuiAhPEEqjU3tNjOTpUquU
Yara None matched
VirusTotal Search for analysis
Name b980c67b11cc39f0_MSIBD4.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSIBD4.tmp
Size 1.1MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 8e3862ecc7a591df93cb916906eae863
SHA1 1c9f1f80be421f8c87662b5ab11749dd7604fcf2
SHA256 b980c67b11cc39f006535303151273749e4ca69dd370cf45b6110a0b5af77b68
CRC32 C5387F0A
ssdeep 24576:cBbmgYewSBprKpygTqkg0z/f2sbQEiwiUt5KTD54qQc3w0RZqTkqMUM0zVQZA:cBflKp/Dz/f2sbQEidUt5K35Bz3w0RZg
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • Antivirus - Contains references to security software
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e728f79439e07df1_tabback
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\tabback
Size 854.0B
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PC bitmap, Windows 3.x format, 1 x 200 x 24
MD5 4c3dda35e23d44e273d82f7f4c38470a
SHA1 b62bc59f3eed29d3509c7908da72041bd9495178
SHA256 e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
CRC32 E63877CC
ssdeep 24:kUGGGGGGGGjg/QUVdLbCKKKKKKWqqqqqqr:kGUVdnCKKKKKKWqqqqqqr
Yara
  • bmp_file_format - bmp file format
VirusTotal Search for analysis
Name 4e64f4e40d8cbff0_new
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\New
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 1e80de80cefee55d7cfda0df2edcf3b2
SHA1 6e567d732354bbb21f9a57bbb72730c497f35380
SHA256 4e64f4e40d8cbff082b37186c831af4b49e3131c62c00a0cf53e0a6e7e24ac2b
CRC32 43BCFB0B
ssdeep 96:+f+OFx/DgstjfDaf///////aorGbaX8PSccl1q12xfnW1orsKc:+WqDgOQ///////aoZsP+/qAVnWursKc
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 22cfdc73f6b1866e_netfirewall.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\NetFirewall.dll
Size 345.3KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 fd4c73245936b9050d8d22e651f191f1
SHA1 6b314d781c234b13ed25c4f5b03c0f873d5fcae0
SHA256 22cfdc73f6b1866e2c8419be4c350de4f1ae4d4c73e8b5a510deed4cf6baee3b
CRC32 1627E561
ssdeep 6144:f4xsB95xMzgFkesmW1XAORoUSUU+eVWRAItCc9:f4xC95xMMFd88UyWRAIUc9
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 8c0423b41fa16360_raidrive.thumbnailhandler.x64.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.ThumbnailHandler.x64.dll
Size 47.0KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 8e01621f6acfeb3d3da63dbfe683a634
SHA1 8015ad500414f92a020c2700a88e8259dac79d8d
SHA256 8c0423b41fa163603b7c2974ec1de5044c15fac09bfff009e297fb4767ca76df
CRC32 C8F4BE5B
ssdeep 768:KoWwq9UGYVjOiOSEOUgrdglAJfq6YiKAMxkEx:KoMyV7fHUVlAJfq67oxl
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 39fd8d36f8e5d915_MSIF751.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSIF751.tmp
Size 588.3KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 b7a6a99cbe6e762c0a61a8621ad41706
SHA1 92f45dd3ed3aaeaac8b488a84e160292ff86281e
SHA256 39fd8d36f8e5d915ad571ea429db3c3de6e9c160dbea7c3e137c9ba4b7fd301d
CRC32 8CD41BF2
ssdeep 6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 031ed0378f819926_completi
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\completi
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 c23af89757665bc0386fd798a61b2112
SHA1 fd4958b62f83edf6774fcf7c691cc3270b82aa0b
SHA256 031ed0378f819926d7b5b2c6c9367a0fb1cbae40e1a3959e2652fe30a47d52f2
CRC32 7A7BAAEF
ssdeep 48:+728OQ6YxsPq7v8N+2RdHKb80000000000000000000000000MqfqF2Nnnu8jgLe:+72LQWPq7vEFXVCVKuM4expgz
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 4dd265237add8e8a_externaluicleaner.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\ExternalUICleaner.dll
Size 190.8KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0eac3a39681989c8cf86351d28ce5a77
SHA1 510cc35f1b38da02d2cd6b5f4808944712de2275
SHA256 4dd265237add8e8a7cc51b83c0f024356a40c0bad16c5fdda097911c1fbef87c
CRC32 0B4300BC
ssdeep 3072:uYioJUAoM8hWgOme/Nxe4mPS0TUTn0QOInIXcVjjjjOAg0FuDuoFE5Yc/WnSD1+:bsOJePGn0QfQAOk5d+nSB
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 0e22bc2bf7184dfd_custicon
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\custicon
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 be6d2f48aa6634fb2101c273c798d4d9
SHA1 21d1b2e7bca49fe727e1c3a505e28e609ec53cc7
SHA256 0e22bc2bf7184dfdb55223a11439304a453fb3574e3c9034a6497af405c628ef
CRC32 B32F97A8
ssdeep 48:+728OQ6UfPsw8PX4E0000000000000000000000000rggggj88jgLiqYTqfI0008:+72LQpPswSXtA4vJbvi
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 3071af6be43a2611_MSIC23.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSIC23.tmp
Size 736.3KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 8dd026145833182777a182a646df81f3
SHA1 4f5cb840193eea97df088c83a794fb6e8f67ab07
SHA256 3071af6be43a2611db45205f0d3f1f25aba05acf5f70992fce2fffd63ee9c85d
CRC32 BE787677
ssdeep 12288:sXWV44ngBNmhAzLUhfVdrjpuG1PE0I7+avw4UbY6t5rXf63Rfklet:KWV4zHzLUdVB1n1PE0Yw4Ubz5rXf63hL
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name c452712e51270430_1042.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\1042.dll
Size 26.0KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 d82f4060ed4260291dd8b3929c4ba950
SHA1 f3f20b918661e4ac23316ecabfc9eb46ebab976c
SHA256 c452712e51270430208ae705b9be31a0a966aca00304be1525ba6115ed3d5b43
CRC32 99325EE2
ssdeep 384:BkpnIB369q2z8WETKIYicSWgLc6UAM+o/8E9VF0Ny7kRD:Bkp9f8T3YijGAMxkEOD
Yara
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name dcf3c4f6024313ee_webview2loader.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\WebView2Loader.dll
Size 156.5KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 1ba96800bad54c6019fdb6fe41fca592
SHA1 b443b01719c3046d9107e93d181d5da38e6650aa
SHA256 dcf3c4f6024313eeb6f775ed343265d73be1ce1d5dde2f92195dbc32310c7fc9
CRC32 738665FB
ssdeep 3072:5fSjk2nJwnL9/a/vck4L3Ke1+Y6hUR8SAoTCMrEtnczzrND/jY3:y2nL9//dWc6h0Etczs
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name f864e8640c98b65c_insticon
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\insticon
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 eac3781ba9fb0502d6f16253eb67b2b4
SHA1 5eff4fcdc405732702432008ab43164ca6f37101
SHA256 f864e8640c98b65c6c1b9b66a850661e8397ed6e66b06f4424396275488af1be
CRC32 5D1A7445
ssdeep 96:+7d0iiiiiiiuiiiiiiiZiiiiii0DMiiiiiiZiiiiiPiiiiiDfiiiiiMiiiii1Ji3:+TB4Gds1E2fVE5MF+mJwnwewO
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 90a9ac38b2b4cbe1_cbfs.cab
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\driver\cbfs.cab
Size 1.6MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type Microsoft Cabinet archive data, 1645252 bytes, 16 files
MD5 29fadf572f61c66da8395ed45b27da7d
SHA1 fabd817b6e2185ea586aeba038068553f75d1a62
SHA256 90a9ac38b2b4cbe125d9658012cf0d76152f7d572d239ea34d73746814f42113
CRC32 373725A7
ssdeep 49152:rgrA2TTqAe9xg4Roe3nDDOh0sXCjM8tbK1UnC3DWufGyf8ysd9pc:8rA2GDtR9D6usU3Ev33fQTc
Yara
  • CAB_file_format - CAB archive file
VirusTotal Search for analysis
Name 1cd1121517e3f36a_raidrive_2023.9.0_x64.msi
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive_2023.9.0_x64.msi
Size 8.4MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 949, Title: Installation Database, Subject: RaiDrive, Author: OpenBoxLab Inc., Keywords: Installer, MSI, Database, Comments: RaiDrive ., Create Time/Date: Fri Sep 1 14:49:04 2023, Name of Creating Application: RaiDrive, Security: 0, Template: x64;1033, Last Saved By: x64;1042, Revision Number: {E029C1F7-1A1F-48E1-959F-DC657DCDAD94}2023.9.0;{E029C1F7-1A1F-48E1-959F-DC657DCDAD94}2023.9.0;{1709FE5D-6D85-415A-9C71-45C3FB0E9E4C}, Number of Pages: 200, Number of Characters: 63
MD5 44f333f792ef360d71f956ffd74f5eab
SHA1 a19bb3c3963a2405c692c8567f7cc88a2e6f1ec2
SHA256 1cd1121517e3f36a818c8a9f2615d2747b5fda585c108e8ad22d76466791b685
CRC32 1719E0B5
ssdeep 196608:z7cAOqEBfMEt7cAOqt/ibp5Sw67cAOq3:z7yHBfMEt7yUibnSx7yS
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Antivirus - Contains references to security software
  • Microsoft_Office_File_Zero - Microsoft Office File
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 865b031b2c344b55_banner.svg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\banner.svg
Size 28.2KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type SVG Scalable Vector Graphics image
MD5 a92209231c43a871925d546c6dc5c244
SHA1 15b5f39938ff9718eef83862f4ee1f6e7272e1d3
SHA256 865b031b2c344b5558f7712e1424251631247c86a7d835ae263ad948016a35a0
CRC32 22E889E8
ssdeep 768:0PQxoVfMd6xviLJGSinZ1IHVRe0lnh/dbsX5JS:0Ja64sSQZ1IAJY
Yara None matched
VirusTotal Search for analysis
Name e22582d4fd59cc53_raidrive.shellextension.x64.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.ShellExtension.x64.dll
Size 105.0KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 3903d5aee0577bac940c661c169a6d3b
SHA1 4d3446af1c1d01c6ffb1bcdfd1adc5b2a561ee2b
SHA256 e22582d4fd59cc53b156e82940533aea44b868458f04530218bbefbbd992e5eb
CRC32 519CA9D2
ssdeep 3072:JTCijLEQTz0TXhhbJ6PgdzeovL403zzHR:0ijLEQTgTXXTB3z
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 475fe6e4ea33a884_raidrive.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.dll
Size 6.8MB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 ef0d5ab9170ab0fc5872c6bd4c4f0149
SHA1 4963f3bebcf91c9320b7de933c1ebd3d00546d75
SHA256 475fe6e4ea33a884590d385087a78556e0b14bb061ff227dcd14cf3ffede23f2
CRC32 6492C516
ssdeep 98304:fbmKzCI2TGYNOQQcGwgtdaV00Ogj5/vyODaGsixeDpACcWNl1WZOIc:fKKGIu/z0wgfau0Oe5/vd+pFcWNCZOI
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 27f13c4829994b21_info
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\info
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 8595d2a2d58310b448729e28649443d6
SHA1 08c1df6fbf692f21157b2276eb1988ac732ff93c
SHA256 27f13c4829994b214bb1a26eef474da67c521fd429536cb8421ba2f7c3e02b5f
CRC32 2E742BFA
ssdeep 192:+h7OMtMrJbDG0UDLHMrhmZ1galQpAAAAAAAAAAAS55qjOlr9n:+6g0uyi1ZQpAAAAAAAAAAASXqjOp9n
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name be83c8592906fd96_banner.jpg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\banner.jpg
Size 4.4KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x59, frames 3
MD5 d5a55a78cd38f45256807c7851619b7d
SHA1 9d8269120d1d096e9ab0192348f3b8f81f5f73d9
SHA256 be83c8592906fd9651634b0823a2f45abe96aae082674568944c639b5b4a95dc
CRC32 45123A87
ssdeep 96:gf2mCSVa8l5M3QXr1yFk1Erk/Sp3ErJE97KT6Avg+y5rls/Xx:I88oAXQk1Erk/Sp3ErcAvBy/wh
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name c269353d19d50e26_up
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\Up
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 fd64f54db4cbf736a6fc0d7049f5991e
SHA1 24d42fb471aaa7bcd54d7ccb36480f5add9b31d4
SHA256 c269353d19d50e2688db102fef8226ca492db17133043d7eb5420ee8542d571c
CRC32 A8934B4F
ssdeep 192:+n5lkX/1//AJffffPTb6ylHJxnSfFN5pM2C:+5lkX/K
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 1eca0f0c70070aa8_raidrive.service.x64.runtimeconfig.json
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\RaiDrive.Service.x64.runtimeconfig.json
Size 372.0B
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type ASCII text, with CRLF line terminators
MD5 d94cf983fba9ab1bb8a6cb3ad4a48f50
SHA1 04855d8b7a76b7ec74633043ef9986d4500ca63c
SHA256 1eca0f0c70070aa83bb609e4b749b26dcb4409784326032726394722224a098a
CRC32 8BAC5DAB
ssdeep 6:3Hp/hdNyhAkI/X5BXmJe5S1sHRvXmJbJccVHdS1sHNAQ6NOCUo+K8EkNTy:dFk2BEe01sxvEbJc11slex+K8Es2
Yara None matched
VirusTotal Search for analysis
Name 0416b1888148611c_banner.scale150.jpg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\banner.scale150.jpg
Size 9.1KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 938x111, frames 3
MD5 a766139160c43af73563adbd3a38bd5f
SHA1 37a3817c61ed5516b6bbfe4d6cc458e166ce4d0a
SHA256 0416b1888148611c4716cbbe253c8f73f075e4f926c3cc4f93d38d230ef7b4a1
CRC32 A4722CE0
ssdeep 192:Pp8Szx7Uw+7PL209joqlIZ6remeV81MCoOLqTrz:Pp8WJj8L209rKyp3qVOLqfz
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name 0a86152e05522f2a_cbfs6net.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\CBFS6Net.dll
Size 356.0KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (DLL) (GUI) x86-64 Mono/.Net assembly, for MS Windows
MD5 2cfd47e5f95fbf26bfcb7673bf88f7c9
SHA1 61978d1540fa775018b566fac7540a3430bc2efd
SHA256 0a86152e05522f2ace6b97c01c14526ecfe8d306e014bd82f7a7773ee374f387
CRC32 883B321A
ssdeep 3072:ATwTuEHBFVhCenCurcvwloBe6cbvld0KitTeTOY9lXxkcUg46h5ECgXlOlB9hLr3:AM62Qj4loBXKiPLl6PEa/Lrf1
Yara
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • IsPE64 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 7f0121322785c107_cmdlinkarrow
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\cmdlinkarrow
Size 2.8KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
MD5 983358ce03817f1ca404befbe1e4d96a
SHA1 75ce6ce80606bbb052dd35351ed95435892baf8d
SHA256 7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
CRC32 8648B17A
ssdeep 48:QFFZ+f+zd+kHeNTM9/+Xz++++++++YWWS0i6I:QFFEw4Xc+D++++++++ypi9
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 45791627ae8e67e6_removico
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\removico
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 1fffe5c3cc990d0c012a428a59b2ae46
SHA1 fae8042826087d9bb4cd4194e7453d56a773ea64
SHA256 45791627ae8e67e6b616117cf21f04da381722faf08d07c0c25e0f28c9b8f82b
CRC32 BBAF5C7C
ssdeep 96:+SqmR4fTBOTPsbZX78rXSEUFJVkKuCWGDiPlBaBR6J/g/ic9teKUwj11FQ:+SqmiTXZLPjkKuCNU7wic6PR
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name 3c081097dca98557_banner.scale125.jpg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\banner.scale125.jpg
Size 5.6KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 625x74, frames 3
MD5 479576299075c0b85e0de2afe4040c25
SHA1 3ff55dd79d8e4cafa2f8755c90d14524dc75c8ee
SHA256 3c081097dca98557b27c1949496cedc94f1b8f6a952d6b106e312e0239bc5b21
CRC32 64FCAFC5
ssdeep 96:g8h6ZVa8lNgYZMlOIdrPf1XkgrieyIGkJcFm2qkC:Z18MYmQ27lDGLLqkC
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name f8429073c7a83377_exclamic
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\exclamic
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 3fbb7ddbc13edf109e3acaa7a4a69a4e
SHA1 bf53201d998ed6e6f2e07584efda9585113aeb0e
SHA256 f8429073c7a83377ad754824b0b81040d68f8c1350a82ff4dccf8bc4bf31f177
CRC32 47D71552
ssdeep 96:+jsnrGWGIxANQAI2DZ4uHnIdUsbTgvCh3gs//oUvz4tbr4/w:+YzxkQAj4eIdqv8T//3+bsw
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis
Name e97ae3e95fb944b9_ijwhost.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\OpenBoxLab Inc\RaiDrive 2023.9.0\install\DCDAD94\Ijwhost.dll
Size 148.6KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 04f827c3e8cae748a37c9541b50c4734
SHA1 20398a0c84f2da417fd1f660a62905a7a5c65213
SHA256 e97ae3e95fb944b96da4c899c109cfab85c45276b663f9c8818df2292b6e2105
CRC32 6FF18344
ssdeep 3072:3600XZFBejo/4DHdBNkefwH0NtyRmveTljyOcUldYS4CnU2:3GXfBejo/vefiRQUl71
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 033171062cd540ec_banner.scale200.jpg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\banner.scale200.jpg
Size 22.4KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1875x222, frames 3
MD5 38ad4b10ac19a240d93e04d383822381
SHA1 4af7ad089328dcccdda6886a94d7e7cd638f359f
SHA256 033171062cd540ec84ce4998719d0dcae564aa69646d437dc4dc4cd8efd0f6fa
CRC32 3A0D4A72
ssdeep 384:I8gCPeBbgnF6tldimQ4PWuug1S2iwoIy/SPO7sfvzoFVmft7LHlwor:I83WBbQF6rUg1S2iww/Afv0FVml7ior
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name bf21b2bc3e725396_repairic
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\AI_EXTUI_BIN_2620\repairic
Size 14.7KB
Processes 2620 (RaiDrive_2023.9.0_x64.exe)
Type MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
MD5 915e40a576fa41dc5f8486103341673e
SHA1 528cf57f3775638e721c20a6988dbd322fb39273
SHA256 bf21b2bc3e7253968405f3d244cdb1c136672a5bdb088b524a333264898a2d11
CRC32 2537829B
ssdeep 96:+7mrhLDFPIc+Q0VDnSOVKaZ8y4mV4pZeJh:+OhHFPvJurSV24mVb
Yara
  • icon_file_format - icon file format
VirusTotal Search for analysis