Dropped Files | ZeroBOX
Name f2ccaa6bcffb8c63_gdi32.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\gdi32.dll
Size 308.5KB
Processes 1872 (jajajdva.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0120de6a2b5003af22160995d1abafd4
SHA1 18e60d75526bc9edce26479d1f46fdf8c2e2a353
SHA256 f2ccaa6bcffb8c63d0455c9511225b6c5e8c55c1d8076e42f115b553bdf2479d
CRC32 380E0EA6
ssdeep 6144:4Lm+6tejtljCKDI/spqIDU5OXKH6Iv4h6Ibsi4bCxWIs:ftaljgs/UQX4vKA
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis