Dropped Files | ZeroBOX
Name cf5df26713138318_pid.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\pid.txt
Size 4.0B
Processes 2864 (Dpo.exe)
Type ASCII text, with no line terminators
MD5 ef0d17b3bdb4ee2aa741ba28c7255c53
SHA1 e3479c19053568ce27fcc573669d61191419b296
SHA256 cf5df267131383187bdb3d2c59a8718e37ac3103ae6612e9ee5fd113a75116e9
CRC32 F9B63EDE
ssdeep 3:BR:n
Yara None matched
VirusTotal Search for analysis
Name b3d510ef04275ca8_holderwb.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\holderwb.txt
Size 2.0B
Processes 108 (vbc.exe) 2864 (Dpo.exe)
Type Little-endian UTF-16 Unicode text, with no line terminators
MD5 f3b25701fe362ec84616a93a45ce9998
SHA1 d62636d8caec13f04e28442a0a6fa1afeb024bbb
SHA256 b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209
CRC32 88F83096
ssdeep 3:Qn:Qn
Yara None matched
VirusTotal Search for analysis
Name a51eb251f696457a_holdermail.txt
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\holdermail.txt
Size 435.0B
Processes 2808 (vbc.exe) 2864 (Dpo.exe)
Type ASCII text, with CRLF line terminators
MD5 453a6b7949477c770a13cfa7e6bcbb6f
SHA1 387ae697aff4261e610c8a47182c430b4f5e4d5a
SHA256 a51eb251f696457a0ea5efa1291069f2857a5209a1434b42b1c31959fb015564
CRC32 4BB1D58F
ssdeep 6:QAXvqKwHNx7hzIRMCADAwzRZvSAmY/SPIFvBnDWncnDWAwb:Qqwz5UMCADzRAGaetyngyAwb
Yara None matched
VirusTotal Search for analysis
Name 58ce6e7ebc632294_pidloc.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\pidloc.txt
Size 42.0B
Processes 2864 (Dpo.exe)
Type ASCII text, with no line terminators
MD5 fbafbf2c351bb105b791f3b51e992ef9
SHA1 212ca641bd31586a3755b4c9daaf39198996f619
SHA256 58ce6e7ebc632294874435ed52d10af755f045488975da2b561d4ff9d47229e1
CRC32 C741F126
ssdeep 3:oNmWxpcL4E2J5xAI3A:oNmQpcLJ23fw
Yara None matched
VirusTotal Search for analysis