Dropped Files | ZeroBOX
Name 512e4e95427a8c66_tmp25B3.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmp25B3.tmp
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3021000
MD5 f4c540f52d5c08d24a79805eda1d7abf
SHA1 22be46826df7693f58736adb232ab2da790f2571
SHA256 512e4e95427a8c66b2993b27bb23d99cdab2ebd6e9e8937c7f6a39ed8c6a5b94
CRC32 95C9FB3A
ssdeep 24:TLmg/5UcJOyTGVZTPaFpEvg3obNmCFk6Uwcc85fB34444z:T5/ecVTgPOpEveoJZFrU1cQB34444z
Yara None matched
VirusTotal Search for analysis
Name aad1c9be17f64d77_background.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\background.js
Size 596.0B
Processes 2772 (RegSvcs.exe)
Type ASCII text
MD5 aa0e77ec6b92f58452bb5577b9980e6f
SHA1 237872f2b0c90e8cbe61eaa0e2919d6578cacd3f
SHA256 aad1c9be17f64d7700feb2d38df7dc7446a48bf001ae42095b59b11fd24dfcde
CRC32 E178B0F4
ssdeep 12:8/ACiDfZISRZLWxicmFGW8NkzCIzvWkE5rBQNFBajVDGwgI/:8ICi9IyLWxHyGWMjIzWccMFG
Yara None matched
VirusTotal Search for analysis
Name f07f2253ea7fe6fb_icon.png
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\icon.png
Size 6.3KB
Processes 2772 (RegSvcs.exe)
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 d263f71812c3f4a7ce58df7ac7e8b775
SHA1 8ba2d02b9ac3b2e6704a9e9ef7b7fb00899bc32d
SHA256 f07f2253ea7fe6fbc0a6a59e25dfe6a590bb1848003bbe4100ce1f1410ff628c
CRC32 F91AF896
ssdeep 192:8oMFYK7tVPiqoVTZP36k5LP5fGf9cCEjIO:zKx0qG/6k5FuFcCC/
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name dfce2d4d06de6452_protect544cd51a.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Protect544cd51a.dll
Size 742.5KB
Processes 2572 (software.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 544cd51a596619b78e9b54b70088307d
SHA1 4769ddd2dbc1dc44b758964ed0bd231b85880b65
SHA256 dfce2d4d06de6452998b3c5b2dc33eaa6db2bd37810d04e3d02dc931887cfddd
CRC32 94895C27
ssdeep 12288:wCMz4nuvURpZ4jR1b2Ag+dQMWCD8iN2+OeO+OeNhBBhhBBgoo+A1AW8JwkaCZ+36:wCs4uvW4jfb2K90oo+C8JwUZc0
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2aafd1356d876255_manifest.json
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\manifest.json
Size 569.0B
Processes 2772 (RegSvcs.exe)
Type UTF-8 Unicode text
MD5 2835dd0a0aef8405d47ab7f73d82eaa5
SHA1 851ea2b4f89fc06f6a4cd458840dd5c660a3b76c
SHA256 2aafd1356d876255a99905fbcafb516de31952e079923b9ddf33560bbe5ed2f3
CRC32 91CD567C
ssdeep 12:flNAuCONn3Ao19aHuDFRJIbpmxbuvWB0vXY:flVCONQo1XabpWuvPvXY
Yara None matched
VirusTotal Search for analysis
Name 0b15bd7053982b69_secure preferences
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Size 35.3KB
Processes 2772 (RegSvcs.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 254aa09964bc64d853dcf6de416b9735
SHA1 5b5d12b2cef58a48b6aa794769d07c7f686bae78
SHA256 0b15bd7053982b695f8645a355ab0188bd885b522a25f6712c56832b546e1f8d
CRC32 E783B1B3
ssdeep 768:gaYRdUQm7LHLOL7vM1kXqKf/pUZNCgVLH2HfCr6Rj0nX65/opl0:gRmprOLjAnTo
Yara None matched
VirusTotal Search for analysis
Name 24262baafef17092_jquery.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\jquery.js
Size 93.5KB
Processes 2772 (RegSvcs.exe)
Type ASCII text, with very long lines
MD5 3c9137d88a00b1ae0b41ff6a70571615
SHA1 1797d73e9da4287351f6fbec1b183c19be217c2a
SHA256 24262baafef17092927c3dafe764aaa52a2a371b83ed2249cca7e414df99fac1
CRC32 25F43FB9
ssdeep 1536:/PEkjP+iADIOr/NEe876nmBu3HvF38sEeLHFoqqhJ7SerN5wVI+xcBmPv7E+nzmQ:ENMyqhJvN32cBC7M6Whca98Hrp
Yara None matched
VirusTotal Search for analysis
Name 7f34c431c6b1455c_content.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\content.js
Size 4.1KB
Processes 2772 (RegSvcs.exe)
Type ASCII text
MD5 c78433084d2a17b77d6ea4e78190abf4
SHA1 ec10f2a5ee369c4f2f210392de37402b38f7ef9d
SHA256 7f34c431c6b1455c7f47e77e5652f64c22e9317c1a8efca616eb2647aadad407
CRC32 55A27562
ssdeep 96:51OURMthjvfC7SkJSahpS/iBLQab6QabfU:51ORHvfCJhk4LQaWQaQ
Yara None matched
VirusTotal Search for analysis