Dropped Files | ZeroBOX
Name 26d66fabea48da55_ntoskrnl.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\ntoskrnl.exe
Size 31.5KB
Processes 3052 (njntos.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 b510120966ae2b95f96e34dffb58f277
SHA1 d41021338292ff9860150a2c11af8c1c60027cfc
SHA256 26d66fabea48da55d5fc15a9f7ba07c8e0f28cd3050a20fe5b80c5ab94288037
CRC32 9E1F7018
ssdeep 768:zbGRTP1/plIzxTCft4A/11ZvKXQmIDUu0tiF0j:qb1aS/4QVkfj
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • Win_Backdoor_njRAT_Zero - Win Backdoor njRAT
VirusTotal Search for analysis