Dropped Files | ZeroBOX
Name ebba0ebe2633f6e7_opjwghmwv
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\opjwghmwv
Size 5.0KB
Processes 2320 (vbc.exe)
Type data
MD5 d5907f1e5beb277d3263b29cb6b4a414
SHA1 94c8b0f4d30b07aa0095bfd5bd01304ce514f6da
SHA256 ebba0ebe2633f6e70930e73d910cc077390c01bfa622f85d68b794bc4719781f
CRC32 FC398AD1
ssdeep 96:eD3s36NxPD6PPhzrHkBeow6kmu8orqAXi2tTWpCduVDnlBKkOucbzRuXETE2uefu:Qss1D6P5fHk8hmuhrBSROkX2E2uefMTX
Yara None matched
VirusTotal Search for analysis
Name 6b86b273ff34fce1_6D6F4D.lck
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.lck
Size 1.0B
Processes 2496 (lisir.exe)
Type very short file (no magic)
MD5 c4ca4238a0b923820dcc509a6f75849b
SHA1 356a192b7913b04c54574d18c28d46e6395428ab
SHA256 6b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
CRC32 83DCEFB7
ssdeep 3:U:U
Yara None matched
VirusTotal Search for analysis
Name 511e6cff68dce0e4_f8onhe0zlq36er
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\f8onhe0zlq36er
Size 104.0KB
Processes 2320 (vbc.exe)
Type data
MD5 681f095722b21d5b0c5ad0fed14a5090
SHA1 1ed3a72d45b5ebb58d3a6f53d64458dd12762e61
SHA256 511e6cff68dce0e4cb15e478bf510c9a347df39b3e7100182b9a33524e488f28
CRC32 2D91FE7F
ssdeep 1536:KDAiyFk09dRXSTgn2TfyXnChYBZKmqVa/jSsZhvDn/WC4fMKXmHpfVlfy+gPXfy8:8tyRHi/SCh9fNsjWC40KWH9fybPXaro
Yara None matched
VirusTotal Search for analysis
Name 302727eca397d97f_6d6f4d.hdb
Submit file
Filepath C:\Users\test22\AppData\Roaming\41D896\6D6F4D.hdb
Size 4.0B
Processes 2496 (lisir.exe)
Type ISO-8859 text, with no line terminators
MD5 e32a6ca2d8b137049a26644c2a05ab85
SHA1 8be8b5a49dd36013f049002d7c9bb19511f81d0e
SHA256 302727eca397d97fa99f0cb359cac1ee6b952ce876131bc1c9cc0de5fa792a45
CRC32 2F7C4CB9
ssdeep 3:gn:gn
Yara None matched
VirusTotal Search for analysis
Name 135b69d3c201ad86_6d6f4d.exe
Submit file
Filepath c:\users\test22\appdata\roaming\41d896\6d6f4d.exe
Size 4.0KB
Processes 2320 (vbc.exe) 2496 (lisir.exe)
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 cc35a94fc2833c0fb64c802aed458bec
SHA1 ca070b329c9bef01ee5df8800f78f81db67de83f
SHA256 135b69d3c201ad8634d1ac39177dea87226dd58621829e42ac3023c29b0b5f7b
CRC32 B71E4B8F
ssdeep 48:qJxVzYx9or6Js2ByC4tIJs2BD2ihd8+/ZSkXThEsw7xI1IyIGl:KxY7orA1OtS1Nxd8WHtEswE
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsv8973.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsv8973.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis