Name | b3d510ef04275ca8_holderwb.txt |
---|---|
Filepath | C:\Users\test22\AppData\Local\Temp\holderwb.txt |
Size | 2.0B |
Processes | 2972 (vbc.exe) 972 (Kofi.exe) |
Type | Little-endian UTF-16 Unicode text, with no line terminators |
MD5 | f3b25701fe362ec84616a93a45ce9998 |
SHA1 | d62636d8caec13f04e28442a0a6fa1afeb024bbb |
SHA256 | b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209 |
CRC32 | 88F83096 |
ssdeep | 3:Qn:Qn |
Yara | None matched |
VirusTotal | Search for analysis |
Name | a51eb251f696457a_holdermail.txt |
---|---|
Filepath | C:\Users\test22\AppData\Local\Temp\holdermail.txt |
Size | 435.0B |
Processes | 2808 (vbc.exe) 972 (Kofi.exe) |
Type | ASCII text, with CRLF line terminators |
MD5 | 453a6b7949477c770a13cfa7e6bcbb6f |
SHA1 | 387ae697aff4261e610c8a47182c430b4f5e4d5a |
SHA256 | a51eb251f696457a0ea5efa1291069f2857a5209a1434b42b1c31959fb015564 |
CRC32 | 4BB1D58F |
ssdeep | 6:QAXvqKwHNx7hzIRMCADAwzRZvSAmY/SPIFvBnDWncnDWAwb:Qqwz5UMCADzRAGaetyngyAwb |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 1556196786229413_pidloc.txt |
---|---|
Filepath | C:\Users\test22\AppData\Roaming\pidloc.txt |
Size | 43.0B |
Processes | 972 (Kofi.exe) |
Type | ASCII text, with no line terminators |
MD5 | 6aaa7410f82a56fd05b200b98b385375 |
SHA1 | e93a8b0e177dce56716be2bceb47390901249b3d |
SHA256 | 155619678622941330a52dd70a7777af172d1bd6978616ecf89e2d4d6e081638 |
CRC32 | 1FFD164F |
ssdeep | 3:oNmWxpcL4E2J5xAItMJ:oNmQpcLJ23fc |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 3658d7fa3c43456f_pid.txt |
---|---|
Filepath | C:\Users\test22\AppData\Roaming\pid.txt |
Size | 3.0B |
Processes | 972 (Kofi.exe) |
Type | ASCII text, with no line terminators |
MD5 | c22abfa379f38b5b0411bc11fa9bf92f |
SHA1 | 5a14ec71168ce0b15c0e9cece3865e308e28e32b |
SHA256 | 3658d7fa3c43456f3c9c87db0490e872039516e6375336254560167cc3db2ea2 |
CRC32 | 8C2BF6B9 |
ssdeep | 3:jX:r |
Yara | None matched |
VirusTotal | Search for analysis |