Dropped Files | ZeroBOX
Name b72e9013a6204e9f_StdUtils.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsoFB49.tmp\StdUtils.dll
Size 100.0KB
Processes 2660 (node.js.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c6a6e03f77c313b267498515488c5740
SHA1 3d49fc2784b9450962ed6b82b46e9c3c957d7c15
SHA256 b72e9013a6204e9f01076dc38dabbf30870d44dfc66962adbf73619d4331601e
CRC32 9B0322B4
ssdeep 3072:WNuZmJ9TDP3ahD2TF7Rq9cJNPhF9vyHf:WNuZ81zaAFHhF9v
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 897ceb95fb164640_libEGL.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\libEGL.dll
Size 470.0KB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 1eecfb04c4434f5a813c8f0c0c8f2c88
SHA1 6dc3ca4b3f72e7fb33ba26fa488de323edb59add
SHA256 897ceb95fb164640ddd2426673997b5f6fc2619fd916b038b575a70a0682a706
CRC32 4A650C82
ssdeep 6144:F9L2FFtoVsruIzUEzUST6uHKw+BubaOQ74PlqF8:F9CGafznzUSTRY70I
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 53a803724bbf2e7f_zh-CN.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\zh-CN.pak
Size 345.8KB
Processes 2660 (node.js.exe)
Type data
MD5 20f315d38e3b2edc5832931e7770b62a
SHA1 2390bd585dec1e884873454bb98b6f1467dcf7bb
SHA256 53a803724bbf2e7f40aab860325c348f786eeca1ea5ca39a76b4c4a616e3233f
CRC32 CEE25C97
ssdeep 6144:gchsAAfyrtJw99jEaZx79+vKK4/+kTme5zBNCJ7GAmlv:gAAfyrtJAoaZ+vKK4/ye5zBNCJ7C
Yara None matched
VirusTotal Search for analysis
Name 0eee8e751b5b0af1_hi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\hi.pak
Size 900.1KB
Processes 2660 (node.js.exe)
Type data
MD5 1766a05be4dc634b3321b5b8a142c671
SHA1 b959bcadc3724ae28b5fe141f3b497f51d1e28cf
SHA256 0eee8e751b5b0af1e226106beb09477634f9f80774ff30894c0f5a12b925ac35
CRC32 427EE8D7
ssdeep 3072:zGFGsUtYgPLdROwJgdkFSvf4QAEm5dmGhsYK/GR3TX4/NMdpqdYnLsuFQdXPtg8y:zGEAgT/Zu5J57JtK
Yara None matched
VirusTotal Search for analysis
Name 4bd7e466cb5f5b0a_sr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\sr.pak
Size 644.7KB
Processes 2660 (node.js.exe)
Type data
MD5 cbb817a58999d754f99582b72e1ae491
SHA1 6ec3fd06dee0b1fe5002cb0a4fe8ec533a51f9fd
SHA256 4bd7e466cb5f5b0a451e1192aa1abaaf9526855a86d655f94c9ce2183ec80c25
CRC32 7754618E
ssdeep 12288:oLNvoUKEuNI0I4Ki1eg82ATs+Hc549x4moW037LJzk/k/N:xrnqJc5Axjw
Yara None matched
VirusTotal Search for analysis
Name c5566b661675b613_es.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\es.pak
Size 411.5KB
Processes 2660 (node.js.exe)
Type data
MD5 a36992d320a88002697da97cd6a4f251
SHA1 c1f88f391a40ccf2b8a7b5689320c63d6d42935f
SHA256 c5566b661675b613d69a507cbf98768bc6305b80e6893dc59651a4be4263f39d
CRC32 CDD00B91
ssdeep 6144:fILAyMcQXU0+/3IgsC5pN+v6Idj3J5Orj7FQoz7L66PZqS:ALAyNQCsupUv6gj3J5OrmoznGS
Yara None matched
VirusTotal Search for analysis
Name 523d141e59095da7_lv.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\lv.pak
Size 445.2KB
Processes 2660 (node.js.exe)
Type data
MD5 e4f7d9e385cb525e762ece1aa243e818
SHA1 689d784379bac189742b74cd8700c687feeeded1
SHA256 523d141e59095da71a41c14aec8fe9ee667ae4b868e0477a46dd18a80b2007ef
CRC32 2DFF62B7
ssdeep 6144:GOQDGtu4e+D8NHtVFHTPq7K4vHo4q3sb3755ZanXDEG9Aarl4zxmEA5QXls14:GOQUZ2Gu4vTqw75KEGGmEs14
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 6d6d095a1b39c38c_sw.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\sw.pak
Size 395.0KB
Processes 2660 (node.js.exe)
Type data
MD5 39277ae2d91fdc1bd38bea892b388485
SHA1 ff787fb0156c40478d778b2a6856ad7b469bd7cb
SHA256 6d6d095a1b39c38c273be35cd09eb1914bd3a53f05180a3b3eb41a81ae31d5d3
CRC32 5EBCDD14
ssdeep 12288:icM47G565vqimUwbQuBndO8gJGgnATm5A1vZcsToe4t2ht:iy7GsP5Ar
Yara None matched
VirusTotal Search for analysis
Name b393f05e8ff919ef_nsis7z.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsoFB49.tmp\nsis7z.dll
Size 424.0KB
Processes 2660 (node.js.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 80e44ce4895304c6a3a831310fbf8cd0
SHA1 36bd49ae21c460be5753a904b4501f1abca53508
SHA256 b393f05e8ff919ef071181050e1873c9a776e1a0ae8329aefff7007d0cadf592
CRC32 DB6CC985
ssdeep 6144:aUWQQ5O3fz0NG3ucDaEUTWfk+ZA0NrCL/k+uyoyBOX1okfW7w+Pfzqibckl:an5QEG39fPAkrE4yrBOXDfaNbck
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 6629e68c45780662_nl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\nl.pak
Size 385.8KB
Processes 2660 (node.js.exe)
Type data
MD5 181d2a0ece4b67281d9d2323e9b9824d
SHA1 e8bdc53757e96c12f3cd256c7812532dd524a0ea
SHA256 6629e68c457806621ed23aa53b3675336c3e643f911f8485118a412ef9ed14ce
CRC32 32216359
ssdeep 6144:9V01rV7gSsX5SEHDpaQe3D+qnRVd5qYx1Gp7KhaPW:96NFgSsX5S1V7d5qYx1Gp7KcPW
Yara None matched
VirusTotal Search for analysis
Name 5eebb23221aebcf0_vi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\vi.pak
Size 476.8KB
Processes 2660 (node.js.exe)
Type data
MD5 3fe6f90f1f990aed508deda3810ce8c2
SHA1 3b86f00666d55e984b4aca1a5e8319ffa8f411ff
SHA256 5eebb23221aebcf0be01bfc2695f7dd35b17f6769be1e28e5610d35c9717854b
CRC32 78B7AD8D
ssdeep 12288:gzLBn6cDgszBm0JXbwS1LcxzIJj758+UIi0+UELbzi830l:gpdDgsz00JrwSNizS5Hti0+UUvi830l
Yara None matched
VirusTotal Search for analysis
Name 7353f25dc5cf84d0_d3dcompiler_47.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\d3dcompiler_47.dll
Size 4.7MB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 2191e768cc2e19009dad20dc999135a3
SHA1 f49a46ba0e954e657aaed1c9019a53d194272b6a
SHA256 7353f25dc5cf84d09894e3e0461cef0e56799adbc617fce37620ca67240b547d
CRC32 F77BDAFC
ssdeep 49152:KCZnRO4XyM53Rkq4ypQqdoRpmruVNYvkaRwvhiD0N+YEzI4og/RfzHLeHTRhFRNc:xG2QCwmHPnog/pzHAo/A6l
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 439f7d6c23217c96_sk.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\sk.pak
Size 432.7KB
Processes 2660 (node.js.exe)
Type data
MD5 c6c7396dbfb989f034d50bd053503366
SHA1 089f176b88235cce5bca7abfcc78254e93296d61
SHA256 439f7d6c23217c965179898754edcef8fd1248bdd9b436703bf1ff710701117a
CRC32 57DCA3D7
ssdeep 6144:vQt/WMWyqiLJcPXPk5ELALWaQlKDEmLFGR:vQYfyqiWPXM5ELALWaQlwdLE
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name e8df9a74417c5839_ml.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ml.pak
Size 1.0MB
Processes 2660 (node.js.exe)
Type data
MD5 8b38c65fc30210c7af9b6fa0424266f4
SHA1 116413710ffcf94fbfa38cb97a47731e43a306f5
SHA256 e8df9a74417c5839c531d7ccab63884a80afb731cc62cbbb3fd141779086ac7d
CRC32 86DAE696
ssdeep 12288:AYtrLnsoR47/R7nUwmoMmWDcZubSA/d+8di3ethK5d/7dxOt3ab:lt0oNwMi3eG5d/7Ot3c
Yara None matched
VirusTotal Search for analysis
Name 8c9acde13edcd40d_ko.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ko.pak
Size 415.6KB
Processes 2660 (node.js.exe)
Type data
MD5 b4fbff56e4974a7283d564c6fc0365be
SHA1 de68bd097def66d63d5ff04046f3357b7b0e23ac
SHA256 8c9acde13edcd40d5b6eb38ad179cc27aa3677252a9cd47990eba38ad42833e5
CRC32 075F123B
ssdeep 12288:4Y3l9B6CI1zt8OhrJRFJCqM5T718I8Mtmq7hUoBAA:aZJo5D8GAA
Yara None matched
VirusTotal Search for analysis
Name 297e3647eaf9b3b9_fi.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\fi.pak
Size 380.0KB
Processes 2660 (node.js.exe)
Type data
MD5 d4b776267efebdcb279162c213f3db22
SHA1 7236108af9e293c8341c17539aa3f0751000860a
SHA256 297e3647eaf9b3b95cf833d88239919e371e74cc345a2e48a5033ebe477cd54e
CRC32 9C78CDD5
ssdeep 6144:nEbM+RtZ9eC6cMkohGZxGseSFOE/xaWEkLl5W5ucHiEi18OWUcrOShPGNgX1wL2:V+/upPgZxaS5W5xHiEi18OWUsU2
Yara None matched
VirusTotal Search for analysis
Name ad285800d276e0aa_Installer.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\Installer.exe
Size 128.0MB
Processes 2660 (node.js.exe)
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 24a9188766d99c9449e9e10dd1f7e2cb
SHA1 6b74a783aba83e748674e2c6c7f365aec44a33b6
SHA256 87d94a9ee552d66bee276f8b19694a8f034fb24f5306f24d623c71c6582065d5
CRC32 01D01CEC
ssdeep 1572864:yLBZB52nvuZ7wVuMbgR7Sp6kYdEctmhoLsPagBsgkx52HYhwj+vfIBUdoJnP9DjL:yypCmJctBjj2+C
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • RedLine_Stealer_b_Zero - RedLine stealer
  • Obsidium_Zero - Obsidium protector file
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 61a3daae72558662_ms.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ms.pak
Size 381.2KB
Processes 2660 (node.js.exe)
Type data
MD5 9b3e2f3c49897228d51a324ab625eb45
SHA1 8f3daec46e9a99c3b33e3d0e56c03402ccc52b9d
SHA256 61a3daae72558662851b49175c402e9fe6fd1b279e7b9028e49506d9444855c5
CRC32 E4180C34
ssdeep 6144:zCsFFfyrvxoQuXkulRopY/5BI8T5sHAVHMM/k3y:tQxoNlR6K5v5vVsMZ
Yara None matched
VirusTotal Search for analysis
Name c91abf556e55c29d_chrome_200_percent.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\chrome_200_percent.pak
Size 173.2KB
Processes 2660 (node.js.exe)
Type data
MD5 4610337e3332b7e65b73a6ea738b47df
SHA1 8d824c9cf0a84ab902e8069a4de9bf6c1a9aaf3b
SHA256 c91abf556e55c29d1ea9f560bb17cc3489cb67a5d0c7a22b58485f5f2fbcf25c
CRC32 AF14A938
ssdeep 3072:4DQYaEQN6AJPKNzIwafR54x5GMR+F44ffbdZnYw9p4AbIVGYoDd+HxNK/rIM0:4DQYaNN68QEVgx5GMRejnbdZnVE6YopY
Yara None matched
VirusTotal Search for analysis
Name 01c830b0007b8ce6_bn.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\bn.pak
Size 883.7KB
Processes 2660 (node.js.exe)
Type data
MD5 5cdd07fa357c846771058c2db67eb13b
SHA1 deb87fc5c13da03be86f67526c44f144cc65f6f6
SHA256 01c830b0007b8ce6aca46e26d812947c3df818927b826f7d8c5ffd0008a32384
CRC32 EF3C0460
ssdeep 1536:wqf22AwWk+ADszaaH0PaMadiMNKVbVtQW01jilDouMGsW2uMBVr+9RU4yVS5PMxq:1zW/AMfafVoCp8YbkJBbdJ2DB5y0XlRB
Yara None matched
VirusTotal Search for analysis
Name 265d8b1bc479ad64_it.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\it.pak
Size 404.7KB
Processes 2660 (node.js.exe)
Type data
MD5 d58a43068bf847c7cd6284742c2f7823
SHA1 497389765143fac48af2bd7f9a309bfe65f59ed9
SHA256 265d8b1bc479ad64fa7a41424c446139205af8029a2469d558813edd10727f9c
CRC32 0FBBC154
ssdeep 6144:8cPuDjrpxctogSrqRrhsO11RT9TeexAGTL6+q2WKLV9fLwY+25OM388HrmwGWNBI:8cmDZREZJy8KL1LjAS5ZzoC
Yara None matched
VirusTotal Search for analysis
Name 6a526cd5268b80df_pt-PT.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\pt-PT.pak
Size 407.2KB
Processes 2660 (node.js.exe)
Type data
MD5 6a7232f316358d8376a1667426782796
SHA1 8b70fe0f3ab2d73428f19ecd376c5deba4a0bb6c
SHA256 6a526cd5268b80df24104a7f40f55e4f1068185febbbb5876ba2cb7f78410f84
CRC32 79C0F02B
ssdeep 6144:isWkrPyGJeOMqieJVJJxhlOlxLu3ov5xKqSR0B:X3PBxj8zv5xKqSRW
Yara None matched
VirusTotal Search for analysis
Name 41e0f3619cda3b00_lt.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\lt.pak
Size 446.5KB
Processes 2660 (node.js.exe)
Type data
MD5 980c27fd74cc3560b296fe8e7c77d51f
SHA1 f581efa1b15261f654588e53e709a2692d8bb8a3
SHA256 41e0f3619cda3b00abbbf07b9cd64ec7e4785ed4c8a784c928e582c3b6b8b7db
CRC32 B5290F48
ssdeep 6144:Ca5OlSk7unX4nkokvgneIVUoCb1DD7U5R3zv9dFaL8tx9e2lJ2I96S2:Ca5Olrpgme2UoC9c59zv9fx9eoP6S2
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 24ea4028da66a293_ta.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ta.pak
Size 1019.3KB
Processes 2660 (node.js.exe)
Type data
MD5 7006691481966109cce413f48a349ff2
SHA1 6bd243d753cf66074359abe28cfae75bcedd2d23
SHA256 24ea4028da66a293a43d27102012235198f42a1e271fe568c7fd78490a3ee647
CRC32 C1478BF2
ssdeep 6144:LXNxfy+orMVjLn1ExBlhfg5yzntRMcA2i:rffyrrMFL1cB3g5yzMcA2i
Yara None matched
VirusTotal Search for analysis
Name 7d72e3adb35e13ec_sv.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\sv.pak
Size 376.3KB
Processes 2660 (node.js.exe)
Type data
MD5 502e4a8b3301253abe27c4fd790fbe90
SHA1 17abcd7a84da5f01d12697e0dffc753ffb49991a
SHA256 7d72e3adb35e13ec90f2f4271ad2a9b817a2734da423d972517f3cff299165fd
CRC32 B60C654E
ssdeep 6144:M4pITVzssdlJ9EAjiws8cB7xjpZ/4LLXru9M9SOxDE/xUDvZv5pB5mEgb7:BpIXzJ9V2B1q5/5mz
Yara None matched
VirusTotal Search for analysis
Name 2630a9d5912c8ef0_fil.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\fil.pak
Size 427.8KB
Processes 2660 (node.js.exe)
Type data
MD5 3165351c55e3408eaa7b661fa9dc8924
SHA1 181bee2a96d2f43d740b865f7e39a1ba06e2ca2b
SHA256 2630a9d5912c8ef023154c6a6fb5c56faf610e1e960af66abef533af19b90caa
CRC32 09D66987
ssdeep 6144:2zHaVyEDQV5aZrU+5xeuhGjZ3ZmA58Pm+7JATvy8:2zNMdU4XA5Imb
Yara None matched
VirusTotal Search for analysis
Name f98b7442befc2853_ca.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ca.pak
Size 416.9KB
Processes 2660 (node.js.exe)
Type data
MD5 d259469e94f2adf54380195555154518
SHA1 d69060bbe8e765ca4dc1f7d7c04c3c53c44b8ab5
SHA256 f98b7442befc285398a5dd6a96740cba31d2f5aadadd4d5551a05712d693029b
CRC32 C12EA368
ssdeep 12288:+XnGrijIs3cSlFEYLCJBB43nbhjJSwmrwiwWzM1ldLbpuQ16BtryBBwIle3nei3X:iNV4ossMNu51hnW5CptA
Yara None matched
VirusTotal Search for analysis
Name ccbca246b9a93fa8_chrome_100_percent.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\chrome_100_percent.pak
Size 124.1KB
Processes 2660 (node.js.exe)
Type data
MD5 acd0fa0a90b43cd1c87a55a991b4fac3
SHA1 17b84e8d24da12501105b87452f86bfa5f9b1b3c
SHA256 ccbca246b9a93fa8d4f01a01345e7537511c590e4a8efd5777b1596d10923b4b
CRC32 B530FE53
ssdeep 3072:vlKzwqCT4wDNzIwL2o418Gb0+VRLf0ld0GY3cQ39Vm2I:vlKzwt4uEgK18Gb0OV8ld0GecQ3f2
Yara None matched
VirusTotal Search for analysis
Name 5b2ffb78fa963f2d_vk_swiftshader.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\vk_swiftshader.dll
Size 5.1MB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 524b0d85d992f86a7f26c162f3dbb91c
SHA1 bc9c862fd01f6134a0514dcb63f9fab7a61ce269
SHA256 5b2ffb78fa963f2dea5a7fcf7676fc3aba243c4372d7528c8f1fc8f726d0a3fa
CRC32 3FBDE90F
ssdeep 98304:RKJSTu+985EkjstvgsnpkkHF3y/AFIB7:RQq85EkjstvgsnpkkJETB
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2e1d413442def9ca_fr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\fr.pak
Size 444.3KB
Processes 2660 (node.js.exe)
Type data
MD5 0bf28aff31e8887e27c4cd96d3069816
SHA1 b5313cf6b5fbce7e97e32727a3fae58b0f2f5e97
SHA256 2e1d413442def9cae2d93612e3fd04f3afaf3dd61e4ed7f86400d320af5500c2
CRC32 844A02EB
ssdeep 12288:07bju28t6QuagV1ZztzYpZ4MYnYM/LDBW5Mx0q20wCbKZL3wfzkCh1f/5FEs6rYr:6JVzbf55Z
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 1729aa5c8a7e24a0_pl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\pl.pak
Size 429.6KB
Processes 2660 (node.js.exe)
Type data
MD5 18d49d5376237bb8a25413b55751a833
SHA1 0b47a7381de61742ac2184850822c5fa2afa559e
SHA256 1729aa5c8a7e24a0db98febcc91df8b7b5c16f9b6bb13a2b0795038f2a14b981
CRC32 D243A845
ssdeep 12288:f2jujSo9/D+Xgv3iWGb1vPiCUdhUo3Ymhz1QhjAB5cUE447e:Sc3N1Qhw5me
Yara None matched
VirusTotal Search for analysis
Name 33f4c20f7910bc3e_ro.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ro.pak
Size 420.1KB
Processes 2660 (node.js.exe)
Type data
MD5 99eaa3d101354088379771fd85159de1
SHA1 a32db810115d6dcf83a887e71d5b061b5eefe41f
SHA256 33f4c20f7910bc3e636bc3bec78f4807685153242dd4bc77648049772cf47423
CRC32 C62B6B3E
ssdeep 6144:pqgw32K4aoFt3GgnSYn0vLi5OU6ois2a/7ulqr:pqgVzFt3GgnSY0vLi5OXo3/5r
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 90e585f101cf0bb7_en-GB.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\en-GB.pak
Size 336.5KB
Processes 2660 (node.js.exe)
Type data
MD5 d59e613e8f17bdafd00e0e31e1520d1f
SHA1 529017d57c4efed1d768ab52e5a2bc929fdfb97c
SHA256 90e585f101cf0bb77091a9a9a28812694cee708421ce4908302bbd1bc24ac6fd
CRC32 4A64BC4D
ssdeep 6144:80kjE55JcUnMP9egFXwqfaYnT9Xa5alSeBNdg:80kQJZnM1XwWT05YScg
Yara None matched
VirusTotal Search for analysis
Name bcb3a3d2fca3c33f_libGLESv2.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\libGLESv2.dll
Size 7.3MB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 cba2436016f7a2838588a52d5b6f30f1
SHA1 81ddf44b3e122dfbee1a2cd8d4544364f1a621a4
SHA256 bcb3a3d2fca3c33fa3d1d5dc976aa913cdc8001df8e64c2cd3d2c545245141bf
CRC32 53EF625E
ssdeep 98304:U8qvGdDtslh+LD3ZDWfnSvBSDU5bPm3k89Ld3gsOMt/:JD3ZXJ7bPWLWsD/
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 2a3d3abc9f80bad5_ja.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ja.pak
Size 493.4KB
Processes 2660 (node.js.exe)
Type data
MD5 d10d536bcd183030ba07ff5c61bf5e3a
SHA1 44dd78dba9f098ac61222eb9647d111ad1608960
SHA256 2a3d3abc9f80bad52bd6da5769901e7b9e9f052b6a58a7cc95ce16c86a3aa85a
CRC32 D950D998
ssdeep 3072:rO2YZ2QUgbjicTver049pUVOT6z4Z72hA/Na4oQPkwaIAOenOIUNH7bbeCcX5RWX:rOpZ2eH/IzSVKo4Z728owPS58HRxVX
Yara None matched
VirusTotal Search for analysis
Name ca7b880391fcd319_pt-BR.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\pt-BR.pak
Size 405.7KB
Processes 2660 (node.js.exe)
Type data
MD5 0d9dea9e24645c2a3f58e4511c564a36
SHA1 dcd2620a1935c667737eea46ca7bb2bdcb31f3a6
SHA256 ca7b880391fcd319e976fcc9b5780ea71de655492c4a52448c51ab2170eeef3b
CRC32 550C9699
ssdeep 6144:Bm1HqF4Znh9GzBtNBXBLd1OUDcpryHF55NJND0bsRzlb2:UHrnhMzX5PJB4sRxC
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsyFB38.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsyFB38.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name 9bbfa7a9f2116281_te.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\te.pak
Size 942.4KB
Processes 2660 (node.js.exe)
Type data
MD5 f809bf5184935c74c8e7086d34ea306c
SHA1 709ab3decff033cf2fa433ecc5892a7ac2e3752e
SHA256 9bbfa7a9f2116281bf0af1e8ffb279d1aa97ac3ed9ebc80c3ade19e922d7e2d4
CRC32 BB5823BB
ssdeep 12288:wM9fKUyABW3p1F9SviTlw2cfgvNFOJgr/p54JVQJMwKpaJC28+58XoX0Doq9OyUk:wM9fKU6225jM9h
Yara None matched
VirusTotal Search for analysis
Name 6d61e5189438f372_am.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\am.pak
Size 599.3KB
Processes 2660 (node.js.exe)
Type data
MD5 2009647c3e7aed2c4c6577ee4c546e19
SHA1 e2bbacf95ec3695daae34835a8095f19a782cbcf
SHA256 6d61e5189438f3728f082ad6f694060d7ee8e571df71240dfd5b77045a62954e
CRC32 F56D87D9
ssdeep 12288:b3pIuPzq8xSTwO8sgjZz5E9VJAVtnuviQix30jH8+I:b3plq8xLO8zjZz5E9VJAVtSiQO
Yara None matched
VirusTotal Search for analysis
Name d1f17508f3a01068_es-419.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\es-419.pak
Size 411.3KB
Processes 2660 (node.js.exe)
Type data
MD5 7f6696cc1e71f84d9ec24e9dc7bd6345
SHA1 36c1c44404ee48fc742b79173f2c7699e1e0301f
SHA256 d1f17508f3a0106848c48a240d49a943130b14bd0feb5ed7ae89605c7b7017d1
CRC32 912DB7F6
ssdeep 3072:34e5fql0vt1s9zjzVMY/6+yN9d8piKkGp2Ioiw/QbuOXV5blUB0GLF96RRIHKxgY:34e5Sktm92Yfhpjq+5wLF96oSdc4
Yara None matched
VirusTotal Search for analysis
Name f33afa6b8df235b0_sl.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\sl.pak
Size 417.8KB
Processes 2660 (node.js.exe)
Type data
MD5 d4bd9f20fd29519d6b017067e659442c
SHA1 782283b65102de4a0a61b901dea4e52ab6998f22
SHA256 f33afa6b8df235b09b84377fc3c90403c159c87edd8cd8004b7f6edd65c85ce6
CRC32 886B5958
ssdeep 12288:iyCeC3SMQRB21BPDwY5oEcAVOlJgi/fzxzqg:iTJ6kDwY5oEc0i/fzxt
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 95f7b8664306da8d_v8_context_snapshot.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\v8_context_snapshot.bin
Size 574.4KB
Processes 2660 (node.js.exe)
Type data
MD5 4cd37ea771ea4fe2f3ad46217cc02206
SHA1 31680e26869b007e62550e96dbf846b3980d5b2b
SHA256 95f7b8664306da8d0073a795e86590ed6fdaede5f489132e56c8779f53cf1ed5
CRC32 F17587A0
ssdeep 6144:bFzofuYUahtcOm3A0Tg8zY8y4XrxXSIIBYgHi:JMfu/fTY8zrM9C7
Yara
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 1cc44c5fbe1c0525_cs.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\cs.pak
Size 426.0KB
Processes 2660 (node.js.exe)
Type data
MD5 04a680847c4a66ad9f0a88fb9fb1fc7b
SHA1 2afcdf4234a9644fb128b70182f5a3df1ee05be1
SHA256 1cc44c5fbe1c0525df37c5b6267a677f79c9671f86eda75b6fc13abf5d5356eb
CRC32 9F8C302A
ssdeep 6144:U4ftEfqE2jv7ShUjBA59wjd558YAGKND9Gto8QV:U41HE2jjShqywjd558YAbNDcI
Yara None matched
VirusTotal Search for analysis
Name 4cca7e6c05b2d988_vulkan-1.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\vulkan-1.dll
Size 906.5KB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 6d4adf9a48dbce2e480ef10b1338ca3c
SHA1 ceb77d5768c6eda84ec8e0b43821b8027764de81
SHA256 4cca7e6c05b2d988926e4b4d0c8ff91d6356f18de8bf40b440251180e5cad6a7
CRC32 5B700C8B
ssdeep 24576:IEW7F7IyaHx/fempu2e6Z5WODYsHh6g3P0zAk7o:e7IyaBfempa6Z5WODYsHh6g3P0zAk7
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name c2656201ac86438d_LICENSES.chromium.html
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\LICENSES.chromium.html
Size 7.9MB
Processes 2660 (node.js.exe)
Type HTML document, UTF-8 Unicode text, with very long lines
MD5 312446edf757f7e92aad311f625cef2a
SHA1 91102d30d5abcfa7b6ec732e3682fb9c77279ba3
SHA256 c2656201ac86438d062673771e33e44d6d5e97670c3160e0de1cb0bd5fbbae9b
CRC32 1D59FBA8
ssdeep 24576:dbTy6TU675kfWScRQfJw91SmfJB6i6e6R626X8HHdE/pG6:tygpj
Yara None matched
VirusTotal Search for analysis
Name 61cbce9a31858ddf_de.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\de.pak
Size 414.3KB
Processes 2660 (node.js.exe)
Type data
MD5 8e6654b89ed4c1dc02e1e2d06764805a
SHA1 ff660bc85bb4a0fa3b2637050d2b2d1aecc37ad8
SHA256 61cbce9a31858ddf70cc9b0c05fb09ce7032bfb8368a77533521722465c57475
CRC32 4710D8B5
ssdeep 6144:TFigju3qg4wajEzUKnYm31SOmhqYl51gHNiOIkCJD:TFiecqg1aqHSOu599kCJD
Yara None matched
VirusTotal Search for analysis
Name f245ab242aafeef3_ur.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ur.pak
Size 602.6KB
Processes 2660 (node.js.exe)
Type data
MD5 ff0a23974aef88afc86ecc806dbf1d60
SHA1 e7bae97cbb8692a0d106644dfaa9b7d7ea6fcef0
SHA256 f245ab242aafeef37db736c780476534fad0706aa66dcb8b6b8cd181b4778385
CRC32 A18705DA
ssdeep 12288:LbeI8PzGSEiyqkAXsA5rzTExbWW7mQYrjuUco/9NjjFpvIx:LbDwz5qWK
Yara None matched
VirusTotal Search for analysis
Name 3d95c5819f57a0ad_id.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\id.pak
Size 365.2KB
Processes 2660 (node.js.exe)
Type data
MD5 7b39423028da71b4e776429bb4f27122
SHA1 cb052ab5f734d7a74a160594b25f8a71669c38f2
SHA256 3d95c5819f57a0ad06a118a07e0b5d821032edcf622df9b10a09da9aa974885f
CRC32 3F075435
ssdeep 6144:Fl9jv1p49ahfjDVnjHFsRmP28Wvr5PdhpvtEDSVsEaOq:FlLpblVnjHFCm+8Sr5Pdhzq
Yara None matched
VirusTotal Search for analysis
Name 983b15dcc31d0e9a_ru.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ru.pak
Size 687.2KB
Processes 2660 (node.js.exe)
Type data
MD5 ab9902025dcf7d5408bf6377b046272b
SHA1 c9496e5af3e2a43377290a4883c0555e27b1f10f
SHA256 983b15dcc31d0e9a3da78cd6021e5add2a3c2247322aded9454a5d148d127aae
CRC32 5EC5BED5
ssdeep 12288:ckXRY5eXN2hHO3j/jHXzvMBsiA2kkce8P/XyFGGJGswfaZ/LeUFCcYWIkHWajf+F:ck5LZ5w6pF
Yara None matched
VirusTotal Search for analysis
Name 319d1e20150d4e3f_fa.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\fa.pak
Size 607.6KB
Processes 2660 (node.js.exe)
Type data
MD5 9d273af70eafd1b5d41f157dbfb94fdc
SHA1 da98bde34b59976d4514ff518bd977a713ea4f2e
SHA256 319d1e20150d4e3f496309ba82fce850e91378ee4b0c7119a003a510b14f878b
CRC32 47961CEF
ssdeep 12288:Kxw5iX9nuyaXTfwHxwNUWGOGfStQEvy1zeItDmNtua/1wMTAKzIxRAQiHedNu36/:Kxw5YuyaXTfwRwNUWGOGfStQEvy1zeIR
Yara None matched
VirusTotal Search for analysis
Name 38526a94dca0a2b1_app-64.7z
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsoFB49.tmp\app-64.7z
Size 71.2MB
Processes 2660 (node.js.exe)
Type 7-zip archive data, version 0.4
MD5 e25943144006dad6794c46b9515f75f6
SHA1 1d55443121a44c82d1b17aeedf79438f6e7f58c9
SHA256 38526a94dca0a2b1286bcebeca9668cac20b866b88080be85ac37c399d0c638a
CRC32 B87BB345
ssdeep 1572864:njdd8sMGv6fdWfu7QcQx4wFnrUY2asfgEdjrFQcIubVxqGZ6i:j8sHSFiquBFwL9gujRQcFTL6i
Yara None matched
VirusTotal Search for analysis
Name 4d207c5c202c19c4_en-US.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\en-US.pak
Size 339.0KB
Processes 2660 (node.js.exe)
Type data
MD5 5e3813e616a101e4a169b05f40879a62
SHA1 615e4d94f69625dda81dfaec7f14e9ee320a2884
SHA256 4d207c5c202c19c4daca3fddb2ae4f747f943a8faf86a947eef580e2f2aee687
CRC32 A47253E8
ssdeep 6144:xiLqIY2MuZYLMMP9ecGmM8faYdY4K55TiSbn8vMwS:xiLqIp34MM+mM0Y55eSKMwS
Yara None matched
VirusTotal Search for analysis
Name 9e16499cd96a155d_zh-TW.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\zh-TW.pak
Size 341.8KB
Processes 2660 (node.js.exe)
Type data
MD5 524711882cbfb5b95a63ef48f884cff0
SHA1 1078037687cfc5d038eeb8b63d295239e0edc47a
SHA256 9e16499cd96a155d410c8df4c812c52ff2a750f8c4db87fd891c1e58c1428c78
CRC32 184564BC
ssdeep 6144:BiwxICJkrCU2JLuRyMD+4qz5MHzCtMkZ/9ybT1:BiyS0pMD+4qz5MHzd6/o
Yara None matched
VirusTotal Search for analysis
Name d0c38eb889ee27d8_da.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\da.pak
Size 386.8KB
Processes 2660 (node.js.exe)
Type data
MD5 1a53d374b9c37f795a462aac7a3f118f
SHA1 154be9cf05042eced098a20ff52fa174798e1fea
SHA256 d0c38eb889ee27d81183a0535762d8ef314f0fdeb90ccca9176a0ce9ab09b820
CRC32 B07C5899
ssdeep 6144:Q3rSn4RJ28687mlwlGXaJwZkqEb1Phv6VP5yarXGzOJixhd4/TWwS:eND/xqkqEO5nrFTq
Yara None matched
VirusTotal Search for analysis
Name a10c3d236246e001_resources.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\resources.pak
Size 5.0MB
Processes 2660 (node.js.exe)
Type data
MD5 7d5065ecba284ed704040fca1c821922
SHA1 095fcc890154a52ad1998b4b1e318f99b3e5d6b8
SHA256 a10c3d236246e001cb9d434a65fc3e8aa7acddddd9608008db5c5c73dee0ba1f
CRC32 73A7DE99
ssdeep 98304:HLYxfQVcnNWz49PDq2AwpmqdhBh1Dd42cjrwrbHw4o0DPelwG3RC:H0pQGcMButuBhpd4jkrU4oeelrRC
Yara None matched
VirusTotal Search for analysis
Name 9b1fbf0c11c520ae_elevate.exe
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\resources\elevate.exe
Size 105.0KB
Processes 2660 (node.js.exe)
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 792b92c8ad13c46f27c7ced0810694df
SHA1 d8d449b92de20a57df722df46435ba4553ecc802
SHA256 9b1fbf0c11c520ae714af8aa9af12cfd48503eedecd7398d8992ee94d1b4dc37
CRC32 C908A44F
ssdeep 3072:1bLnrwQoRDtdMMgSXiFJWcIgUVCfRjV/GrWl:1PrwRhte1XsE1l
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name 32d83ff113fef532_vk_swiftshader_icd.json
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\vk_swiftshader_icd.json
Size 106.0B
Processes 2660 (node.js.exe)
Type ASCII text, with no line terminators
MD5 8642dd3a87e2de6e991fae08458e302b
SHA1 9c06735c31cec00600fd763a92f8112d085bd12a
SHA256 32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
CRC32 596B3D49
ssdeep 3:YD96WyV18tzsmyXLVi1rTVWSCwW2TJHzeZ18rY:Y8WyV18tAZLVmCwXFiZ18rY
Yara None matched
VirusTotal Search for analysis
Name 9dfbe0dad5c7021c_icudtl.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\icudtl.dat
Size 10.1MB
Processes 2660 (node.js.exe)
Type data
MD5 d89ce8c00659d8e5d408c696ee087ce3
SHA1 49fc8109960be3bb32c06c3d1256cb66dded19a8
SHA256 9dfbe0dad5c7021cfe8df7f52458c422cbc5be9e16ff33ec90665bb1e3f182de
CRC32 6132F83C
ssdeep 98304:OKPBQYOo+ddlymOk25flQCUliXUxiG9Ha93Whla6ZGdnp/8k:OKPBhORjOhCliXUxiG9Ha93Whla6ZGrn
Yara None matched
VirusTotal Search for analysis
Name c1802b29b13663a8_snapshot_blob.bin
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\snapshot_blob.bin
Size 266.9KB
Processes 2660 (node.js.exe)
Type data
MD5 8915dd2a6d6b4ebf9a16c77fe063d8de
SHA1 a03132adcb99a82ba269d56ab6577ccfd1bb08e5
SHA256 c1802b29b13663a8890031411270866834246931f71f41397682dd88fa16d485
CRC32 35BDBD0A
ssdeep 1536:MpeVehd7eASb6iAGm4hmWRSJTnBSki+TfUNp2Zg+TEJ0xEI2tWaw8MCZ72T04GO9:YdyNm4mWRSJTBSXsU1vJzbYB
Yara None matched
VirusTotal Search for analysis
Name 798ea5d88a57d1d7_gu.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\gu.pak
Size 858.5KB
Processes 2660 (node.js.exe)
Type data
MD5 7b5f52f72d3a93f76337d5cf3168ebd1
SHA1 00d444b5a7f73f566e98abadf867e6bb27433091
SHA256 798ea5d88a57d1d78fa518bf35c5098cbeb1453d2cb02ef98cd26cf85d927707
CRC32 3A1EBB8A
ssdeep 3072:Xz2UMY57hmdUoITsKMaWZKerbtsMhmksd4M+0+z20QmuOAl5VpvoxWnhygfZw/gQ:D2UMY57h9w4MSbsp5cLhdKE8
Yara None matched
VirusTotal Search for analysis
Name 5154e165bd6c2cc0_LICENSE.electron.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\LICENSE.electron.txt
Size 1.1KB
Processes 2660 (node.js.exe)
Type ASCII text
MD5 4d42118d35941e0f664dddbd83f633c5
SHA1 2b21ec5f20fe961d15f2b58efb1368e66d202e5c
SHA256 5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
CRC32 3958EFAA
ssdeep 24:36DiJHxRHuyPP3GtIHw1Gg9QH+sUW8Ok4F+d1o36qjFD:36DiJzfPvGt7ICQH+sfIte36AFD
Yara None matched
VirusTotal Search for analysis
Name 857fe3ab766b60a8_ar.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\ar.pak
Size 656.0KB
Processes 2660 (node.js.exe)
Type data
MD5 47a6d10b4112509852d4794229c0a03b
SHA1 2fb49a0b07fbdf8d4ce51a7b5a7f711f47a34951
SHA256 857fe3ab766b60a8d82b7b6043137e3a7d9f5cfb8ddd942316452838c67d0495
CRC32 CD7345BB
ssdeep 12288:gjptqBycpX8vYULIrmhkH+P5NNb++YTzgpPMgSENeX:BB2um5S++
Yara None matched
VirusTotal Search for analysis
Name c0043d9fa0b841da_hu.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\hu.pak
Size 446.1KB
Processes 2660 (node.js.exe)
Type data
MD5 f5e1ca8a14c75c6f62d4bff34e27ddb5
SHA1 7aba6bff18bdc4c477da603184d74f054805c78f
SHA256 c0043d9fa0b841da00ec1672d60015804d882d4765a62b6483f2294c3c5b83e0
CRC32 1F6F4AB0
ssdeep 6144:SGAK2lkJ2gSSSfLOAYkky1MV5QgsZfGRAxY62R9PSam7EEOEeLvx5gR4RStG2r2/:pAKWkJ2gSsAkV5QgsiR4747vx5VL/
Yara None matched
VirusTotal Search for analysis
Name 1606b94aef970478_et.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\et.pak
Size 371.8KB
Processes 2660 (node.js.exe)
Type data
MD5 a94e1775f91ea8622f82ae5ab5ba6765
SHA1 ff17accdd83ac7fcc630e9141e9114da7de16fdb
SHA256 1606b94aef97047863481928624214b7e0ec2f1e34ec48a117965b928e009163
CRC32 3E879427
ssdeep 6144:2Mg++J/xRN0JLnrC4HFJbT/RauiQ/G5LjR43f7LQkPQW:2MmJnq7DG5LjQ
Yara None matched
VirusTotal Search for analysis
Name a34704f71891b89c_app.asar
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\resources\app.asar
Size 52.0MB
Processes 2660 (node.js.exe)
Type data
MD5 1999194779916f58f30a1b8500d53768
SHA1 a458c3356a701a077eb27611482b1a7ae37180bd
SHA256 a34704f71891b89c77f26403a3749617bc7e96e6966ae45a7e5d1e3674f82eaa
CRC32 28AA0951
ssdeep 393216:QLjOc0yFzUHtaIWQ0S0xClzANtP6ChuVy:Q/WyU8S0xClzANtP6ChuVy
Yara
  • Malicious_Library_Zero - Malicious_Library
  • ftp_command - ftp command
  • Antivirus - Contains references to security software
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Javascript_Blob - use blob(Binary Large Objec) javascript
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name e900f6d0dd9d5a05_nb.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\nb.pak
Size 374.0KB
Processes 2660 (node.js.exe)
Type data
MD5 af0fd9179417ba1d7fcca3cc5bee1532
SHA1 f746077bbf6a73c6de272d5855d4f1ca5c3af086
SHA256 e900f6d0dd9d5a05b5297618f1fe1600c189313da931a9cb390ee42383eb070f
CRC32 F48A9BDE
ssdeep 6144:rmRAsByIhGvbSqOp7f21zg2mKP7s4Uzwn5el4nYHOp1D:rmRGxvbSqOp7f21vs4kM5el4Jp1D
Yara None matched
VirusTotal Search for analysis
Name 846943f77a425f38_hr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\hr.pak
Size 413.6KB
Processes 2660 (node.js.exe)
Type data
MD5 8f9498d18d90477ad24ea01a97370b08
SHA1 3868791b549fc7369ab90cd27684f129ebd628be
SHA256 846943f77a425f3885689dcf12d62951c5b7646e68eadc533b8b5c2a1373f02e
CRC32 36BDEFDE
ssdeep 3072:yL0fCmEZW/FhjNmvgVRTKBOS+/6ocIG0uPXuyAF6WI6DkYAiKbeM/ogQbn7xjemW:QYCmNLjN3pV5v5tE77ORS
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name f11041c48831c93a_th.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\th.pak
Size 792.4KB
Processes 2660 (node.js.exe)
Type data
MD5 2c41616dfe7fcdb4913cfafe5d097f95
SHA1 cf7d9e8ad3aa47d683e47f116528c0e4a9a159b0
SHA256 f11041c48831c93aa11bbf885d330739a33a42db211daccf80192668e2186ed3
CRC32 042DB970
ssdeep 12288:1Jf31Mkgs3s5UWgHLRflsjj8cKGXdlogG0EeuLADh7Kle9dKj753ohP09XAyFHyJ:1Qzt5/5l
Yara None matched
VirusTotal Search for analysis
Name 3eb38ae99653a7db_System.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsoFB49.tmp\System.dll
Size 12.0KB
Processes 2660 (node.js.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0d7ad4f45dc6f5aa87f606d0331c6901
SHA1 48df0911f0484cbe2a8cdd5362140b63c41ee457
SHA256 3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
CRC32 D50C2CEF
ssdeep 192:1enY0LWelt70elWjvfstJcVtwtYbjnIOg5AaDnbC7ypXhtIj:18PJlt70esj0Mt9vn6ay6
Yara
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 54324671a161f6d6_uk.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\uk.pak
Size 688.5KB
Processes 2660 (node.js.exe)
Type data
MD5 ee70e9f3557b9c8c67bfb8dfcb51384d
SHA1 fc4dfc35cde1a00f97eefe5e0a2b9b9c0149751e
SHA256 54324671a161f6d67c790bfd29349db2e2d21f5012dc97e891f8f5268bdf7e22
CRC32 D4516355
ssdeep 12288:wrccq9nty/KiDswU1nbx05kB3IjUUmEg5KuoLNiXElqnOyh:HGX35EEK
Yara None matched
VirusTotal Search for analysis
Name e79c1e7a47250d88_el.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\el.pak
Size 751.0KB
Processes 2660 (node.js.exe)
Type data
MD5 9528d21e8a3f5bad7ca273999012ebe8
SHA1 58cd673ce472f3f2f961cf8b69b0c8b8c01d457c
SHA256 e79c1e7a47250d88581e8e3baf78dcaf31fe660b74a1e015be0f4bafdfd63e12
CRC32 0451A19A
ssdeep 12288:H/58dBquNw2202pgtZSWjZ4LIbsJvaP5A3HKQiEQBR07391qf2utKMaBlS9WffFR:H8BquNw2202pgtsWjyLrJvaRA3HtiEQG
Yara None matched
VirusTotal Search for analysis
Name f528e698b1642838_af.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\af.pak
Size 368.9KB
Processes 2660 (node.js.exe)
Type data
MD5 7e51349edc7e6aed122bfa00970fab80
SHA1 eb6df68501ecce2090e1af5837b5f15ac3a775eb
SHA256 f528e698b164283872f76df2233a47d7d41e1aba980ce39f6b078e577fd14c97
CRC32 166C7ACB
ssdeep 6144:ebGJWQdLX/Wi6fR9a5DhZ2FQPnUGSBhjA636Zi2Jyn9Ybt5KXpgmLwSVxJsVxSjf:6GJW2bOi6fRmZ2OPnUThjA636Zi2Jynd
Yara None matched
VirusTotal Search for analysis
Name 88df231cf2e506db_mr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\mr.pak
Size 843.7KB
Processes 2660 (node.js.exe)
Type data
MD5 c0ef1866167d926fb351e9f9bf13f067
SHA1 6092d04ef3ce62be44c29da5d0d3a04985e2bc04
SHA256 88df231cf2e506db3453f90a797194662a5f85e23bbac2ed3169d91a145d2091
CRC32 108AD937
ssdeep 3072:OVDue+/Ti/eFcDX6WRAWXXspvidz0F5MU9G3GRe3RQR3K5/knxi4nou4bmHwIZus:eueAi2FZW2bo26lp70Kte5zGpGiBs
Yara None matched
VirusTotal Search for analysis
Name ad65351a240205e8_bg.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\bg.pak
Size 685.3KB
Processes 2660 (node.js.exe)
Type data
MD5 a19269683a6347e07c55325b9ecc03a4
SHA1 d42989daf1c11fcfff0978a4fb18f55ec71630ec
SHA256 ad65351a240205e881ef5c4cf30ad1bc6b6e04414343583597086b62d48d8a24
CRC32 1D587866
ssdeep 12288:7Od6KqVw2iILlY+dAs1aQUfjoaVV4FH2mFxvx35uKN3CuKb7szmV2Jfu64K+z5jG:KsKqJi6lY+dAs1aQU7yZx35uK4XQzQI9
Yara None matched
VirusTotal Search for analysis
Name 890f50a57b862f48_kn.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\kn.pak
Size 988.5KB
Processes 2660 (node.js.exe)
Type data
MD5 c548a5f1fb5753408e44f3f011588594
SHA1 e064ab403972036dad1b35abe9794e95dbe4cc00
SHA256 890f50a57b862f482d367713201e1e559ac778fc3a36322d1dfbbef2535dd9cb
CRC32 D0318C0D
ssdeep 12288:VxaK34cS7yFcH4dr/4g7M5iVUZ+xw+UFV:jf7/K5uUb
Yara None matched
VirusTotal Search for analysis
Name a976fad1cc4eb297_he.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\he.pak
Size 531.4KB
Processes 2660 (node.js.exe)
Type data
MD5 6d787dc113adfb6a539674af7d6195db
SHA1 f966461049d54c61cdd1e48ef1ea0d3330177768
SHA256 a976fad1cc4eb29709018c5ffcc310793a7ceb2e69c806454717ccae9cbc4d21
CRC32 A5279BC3
ssdeep 12288:DczykRrlOUmTU2/S9iyBZ60DAf1X2VeQCap4M52QoLpMzu5flmd9DnwWHQgZ:+F55VoQ
Yara None matched
VirusTotal Search for analysis
Name 65cc75329d17ec26_ffmpeg.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\ffmpeg.dll
Size 2.7MB
Processes 2660 (node.js.exe)
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
MD5 e096c168b79a56ded0df1aa142d9f1da
SHA1 318f20dab294a315bd935160e9417fb5b28300f5
SHA256 65cc75329d17ec264e7a2db571ea55f918394241445ea64569a56c75d0cfdc60
CRC32 E25DF0C4
ssdeep 49152:YGJO72cNsdMZWfAn1fdmZMOqcQrGhjUHgNxGUwSCmmfYDJGz5SN3lzl3hSKqH:Jj8n1QqGCmmfIUz59t
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
VirusTotal Search for analysis
Name d81f28f69da0036f_tr.pak
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\2iwKvKU0Xyuhbxs3ZAVxAhinEZ8\locales\tr.pak
Size 401.8KB
Processes 2660 (node.js.exe)
Type data
MD5 3a858619502c68d5f7de599060f96db9
SHA1 80a66d9b5f1e04cda19493ffc4a2f070200e0b62
SHA256 d81f28f69da0036f9d77242b2a58b4a76f0d5c54b3e26ee96872ac54d7abb841
CRC32 D62193D9
ssdeep 6144:y1MAG26Pl1kY1bkQq/7I5NsA7WGgeh5X/0+gi1ZavXEAQwiBvVGI:9j2Yle66s5775X/R
Yara
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis