Summary | ZeroBOX

saved_resource.html

Generic Malware
Category Machine Started Completed
FILE s1_win7_x6403_us April 20, 2025, 11:24 p.m. April 20, 2025, 11:27 p.m.
Size 253.0B
Type HTML document, ASCII text
MD5 225a7db3e8f67ad247d27c5f966868ce
SHA256 80d07f167372410b1580d254c222c91a906da829b2f2006537818a93700457b2
CRC32 DF130DB5
ssdeep 6:X1KxUoge0Q9xVk6QcjWR0NNEXW0YpT6+p3np/EB965:lPo7xVk6QclflfR5
Yara None matched

  • chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" C:\Users\test22\AppData\Local\Temp\saved_resource.html

    1712
    • chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3df6e00,0x7fef3df6e10,0x7fef3df6e20

      2096

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
file C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.111\Locales
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0xb80004
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30

exception.instruction_r: ff 15 16 1f 09 00 ff 25 00 00 00 00 aa a4 fc 76
exception.instruction: call qword ptr [rip + 0x91f16]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0xb80004
registers.r14: 238547448
registers.r15: 86947184
registers.rcx: 1224
registers.rsi: 17302540
registers.r10: 0
registers.rbx: 238546704
registers.rsp: 238546424
registers.r11: 238550320
registers.r8: 2004779404
registers.r9: 0
registers.rdx: 1280
registers.r12: 238547064
registers.rbp: 238546560
registers.rdi: 86928496
registers.rax: 12058624
registers.r13: 85116992
1 0 0
Application Crash Process chrome.exe with pid 1712 crashed
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0xb80004
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30
0x30

exception.instruction_r: ff 15 16 1f 09 00 ff 25 00 00 00 00 aa a4 fc 76
exception.instruction: call qword ptr [rip + 0x91f16]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0xb80004
registers.r14: 238547448
registers.r15: 86947184
registers.rcx: 1224
registers.rsi: 17302540
registers.r10: 0
registers.rbx: 238546704
registers.rsp: 238546424
registers.r11: 238550320
registers.r8: 2004779404
registers.r9: 0
registers.rdx: 1280
registers.r12: 238547064
registers.rbp: 238546560
registers.rdi: 86928496
registers.rax: 12058624
registers.r13: 85116992
1 0 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-spare.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
file C:\Users\test22\AppData\Local\Google\Chrome\User Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\First Run
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\5fe5265c-e070-406d-83d2-6aee4549e3b0.dmp
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6805453D-6B0.pma
Time & API Arguments Status Return Repeated

NtTerminateProcess

status_code: 0xc0000005
process_identifier: 1712
process_handle: 0x00000000000000bc
0 0

NtTerminateProcess

status_code: 0xc0000005
process_identifier: 1712
process_handle: 0x00000000000000bc
1 0 0
parent_process chrome.exe martian_process "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3df6e00,0x7fef3df6e10,0x7fef3df6e20
parent_process chrome.exe martian_process "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1028,13366542690504362985,7925483923734417929,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1032 /prefetch:2
Process injection Process 2096 resumed a thread in remote process 1712
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0

NtResumeThread

thread_handle: 0x000000000000011c
suspend_count: 2
process_identifier: 1712
1 0 0