Dropped Files | ZeroBOX
Name 960ccaa55014d5a3_content.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\content.js
Size 4.1KB
Processes 2428 (RegAsm.exe)
Type ASCII text
MD5 baba7019c06b272b757a56c051bb2b6d
SHA1 5465a404be64ad8c9ae4f26d0f1ecc2cdffbe71e
SHA256 960ccaa55014d5a359f756a0b2d930c437213fd3f4efc1e90527ef2d33a60a06
CRC32 7AF436EA
ssdeep 96:B1OURMthjvfC7SkJSahpS/iBLQab6QabfU:B1ORHvfCJhk4LQaWQaQ
Yara None matched
VirusTotal Search for analysis
Name aad1c9be17f64d77_background.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\background.js
Size 596.0B
Processes 2428 (RegAsm.exe)
Type ASCII text
MD5 aa0e77ec6b92f58452bb5577b9980e6f
SHA1 237872f2b0c90e8cbe61eaa0e2919d6578cacd3f
SHA256 aad1c9be17f64d7700feb2d38df7dc7446a48bf001ae42095b59b11fd24dfcde
CRC32 E178B0F4
ssdeep 12:8/ACiDfZISRZLWxicmFGW8NkzCIzvWkE5rBQNFBajVDGwgI/:8ICi9IyLWxHyGWMjIzWccMFG
Yara None matched
VirusTotal Search for analysis
Name f07f2253ea7fe6fb_icon.png
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\icon.png
Size 6.3KB
Processes 2428 (RegAsm.exe)
Type PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
MD5 d263f71812c3f4a7ce58df7ac7e8b775
SHA1 8ba2d02b9ac3b2e6704a9e9ef7b7fb00899bc32d
SHA256 f07f2253ea7fe6fbc0a6a59e25dfe6a590bb1848003bbe4100ce1f1410ff628c
CRC32 F91AF896
ssdeep 192:8oMFYK7tVPiqoVTZP36k5LP5fGf9cCEjIO:zKx0qG/6k5FuFcCC/
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name dfce2d4d06de6452_protect544cd51a.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Protect544cd51a.dll
Size 742.5KB
Processes 1952 (hv.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 544cd51a596619b78e9b54b70088307d
SHA1 4769ddd2dbc1dc44b758964ed0bd231b85880b65
SHA256 dfce2d4d06de6452998b3c5b2dc33eaa6db2bd37810d04e3d02dc931887cfddd
CRC32 94895C27
ssdeep 12288:wCMz4nuvURpZ4jR1b2Ag+dQMWCD8iN2+OeO+OeNhBBhhBBgoo+A1AW8JwkaCZ+36:wCs4uvW4jfb2K90oo+C8JwUZc0
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2aafd1356d876255_manifest.json
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\manifest.json
Size 569.0B
Processes 2428 (RegAsm.exe)
Type UTF-8 Unicode text
MD5 2835dd0a0aef8405d47ab7f73d82eaa5
SHA1 851ea2b4f89fc06f6a4cd458840dd5c660a3b76c
SHA256 2aafd1356d876255a99905fbcafb516de31952e079923b9ddf33560bbe5ed2f3
CRC32 91CD567C
ssdeep 12:flNAuCONn3Ao19aHuDFRJIbpmxbuvWB0vXY:flVCONQo1XabpWuvPvXY
Yara None matched
VirusTotal Search for analysis
Name c8fec39dac61657c_secure preferences
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Size 35.3KB
Processes 2428 (RegAsm.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 043c1c3e51cc07ad7dc4601604469715
SHA1 85cd2eb5c294121d54a8f58f7d1016a2889f3957
SHA256 c8fec39dac61657c6a9f54dae77082ceb450f337fa55cbd1639432a090e4f16b
CRC32 8F9D3A6B
ssdeep 768:laJRugQcIL4ALZLlfM1kXqKf/pUZNCgVLH2HfLrUdRHnb62T/ogl9:iR1abZL4nHnCu
Yara None matched
VirusTotal Search for analysis
Name 24262baafef17092_jquery.js
Submit file
Filepath C:\ProgramData\GoogleDriveAdvodrs\jquery.js
Size 93.5KB
Processes 2428 (RegAsm.exe)
Type ASCII text, with very long lines
MD5 3c9137d88a00b1ae0b41ff6a70571615
SHA1 1797d73e9da4287351f6fbec1b183c19be217c2a
SHA256 24262baafef17092927c3dafe764aaa52a2a371b83ed2249cca7e414df99fac1
CRC32 25F43FB9
ssdeep 1536:/PEkjP+iADIOr/NEe876nmBu3HvF38sEeLHFoqqhJ7SerN5wVI+xcBmPv7E+nzmQ:ENMyqhJvN32cBC7M6Whca98Hrp
Yara None matched
VirusTotal Search for analysis
Name edb006e05cfa8501_tmpF816.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tmpF816.tmp
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 3f5ca3e29b1b60e298aeca0a32164c03
SHA1 f9b5ee59c31a3b06a6b8e476b22d2d7cf1fa8b66
SHA256 edb006e05cfa85015aa76c758d6298c279fd318cff0dbb286927c7ad45105488
CRC32 E1ACA097
ssdeep 24:TL2C0RlPbXaFpEO5bNmISHdL6UwcOxvo5:TYLOpEO5J/KdGU1Eo5
Yara None matched
VirusTotal Search for analysis