0j7rxag85db5cphfncwf.zip -
Launching a JavaScript file directly from a ZIP.
The script writes a secondary, larger script into the Windows Registry or a hidden folder to maintain persistence across reboots. 0j7RXAG85Db5cpHfNCWF.zip
Check for scheduled tasks or registry keys pointing to wscript.exe or cscript.exe . Launching a JavaScript file directly from a ZIP
Creation of unusually large entries in HKEY_CURRENT_USER\Software\ . 0j7RXAG85Db5cpHfNCWF.zip
While filenames like 0j7RXAG85Db5cpHfNCWF.zip change constantly, the following behaviors are consistent:
If the file has not been opened, delete it and clear the browser cache.
ZIP Archive containing a heavily obfuscated .js (JavaScript) file. Primary Malware Family: GootLoader.