Dropped Files | ZeroBOX
Name d172d750493be64a_icon18_wrench_allbkg[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\icon18_wrench_allbkg[1].png
Size 475.0B
Processes 7400 (iexplore.exe)
Type PNG image data, 18 x 18, 8-bit colormap, non-interlaced
MD5 f617effe6d96c15acfea8b2e8aae551f
SHA1 6d676af11ad2e84b620cce4d5992b657cb2d8ab6
SHA256 d172d750493be64a7ed84dec1dd2a0d787ba42f78bc694b0858f152c52b6620b
CRC32 87FB2FCE
ssdeep 12:6v/7ElZUJDdwjI5Fa4ep0LPf+veUxQn6/Xh0ptMQsfZhkNTpQEsb7:ZK1dw0etKjfUxQn6/x0DWrETpQZb7
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name ea50ac7fddb61a5c_kfomcnqeu92fr1mu4mxm[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\KFOmCnqEu92Fr1Mu4mxM[1].woff
Size 19.9KB
Processes 7400 (iexplore.exe)
Type Web Open Font Format, TrueType, length 20332, version 1.1
MD5 dc3e086fc0c5addc09702e111d2adb42
SHA1 b1138b84ff19eac5f43c4202297529d389bd09b7
SHA256 ea50ac7fddb61a5ce248a7f8b3a31a98fe16285e076b16e6da6b4e10910724bb
CRC32 F6DA8D99
ssdeep 384:U0iwaxoOUPVkOJJSu6SsCKTIRDqG9oHKwZh98OSv+MsgkAOY:75mlUmOSu1guh+fZhLSxkAr
Yara None matched
VirusTotal Search for analysis
Name d2be13fcaa24bc90_rs=aa2yrtuztrlz4shm1gfccffxdziz-5oj0q[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\rs=AA2YrTuZTrLZ4SHM1gfcCFFxdZIZ-5oj0Q[1].js
Size 121.5KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 5e4942b285c4f59dfa068cd51c469507
SHA1 945e8615a9552a9f8bc1ea76664b23d2b374620d
SHA256 d2be13fcaa24bc90a6e7e61d232ddefa0c889ee62913d8ee380aa55df3758fd1
CRC32 FDF3BE69
ssdeep 1536:TWkD1459R9wfhe6jGb2Ts9zhKXAtDbxseevBHzOtQtrxvxqACJIV4ZwPcITtoyD:VseGhlxxmvBHIQ9N2JIVWgzTtx
Yara None matched
VirusTotal Search for analysis
Name 418807f281b4da10_recoverystore.{2d7dc9df-a6e3-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2D7DC9DF-A6E3-11EB-BDE1-94DE278C3274}.dat
Size 4.5KB
Processes 6988 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 ec6f0995cc806ce160deb360b09a6cec
SHA1 baf0b759c0c7baa4853e81f8fba486e0572f72da
SHA256 418807f281b4da1069c7009bf373aea2851cc5c320f146c86a43eb56debf0c2d
CRC32 DA48CF70
ssdeep 12:rlfF21rEg5+IaCrI0F7+F2hQrEg5+IaCrI0F7ugQNlTqbaxDOUxZNlTqbaxDOExa:rq15/1hQ5/3QNlWwnNlWgG
Yara
  • Microsoft_Office_Document_Zero - Microsoft Office Document Signature Zero
VirusTotal Search for analysis
Name 4f9da8b8b59401ea_blogin[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\blogin[1].htm
Size 283.0B
Processes 7400 (iexplore.exe)
Type gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
MD5 9ff8c582fff795800d975ed93af9aa03
SHA1 733d1e9a1b5e3183f1df77b33f65bb4737e3e8db
SHA256 4f9da8b8b59401ea85574bc54b317f4020705534eb8bf8631bbe1ea7ed651c7e
CRC32 09DBA553
ssdeep 6:Xt5EE44qS7r9XOreS6b42LesrO8RRz1UIBwIiW43NdIgAxR5t:X0R4qmr9+SSwrVa8RfUIBle4gAxRv
Yara None matched
VirusTotal Search for analysis
Name a1495da3cf3db37b_favicon[1].ico
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\favicon[1].ico
Size 3.6KB
Processes 7400 (iexplore.exe)
Type MS Windows icon resource - 2 icons, 32x32, 8 bits/pixel, 16x16, 8 bits/pixel
MD5 59a0c7b6e4848ccdabcea0636efda02b
SHA1 30ef5c54b8bbc3487ea2b4c45cd11ea2932e4340
SHA256 a1495da3cf3db37bf105a12658636ff628fee7b73975b9200049af7747e60b1f
CRC32 26FF9B96
ssdeep 6:NXulKltegZ//OekukCS4kdxpHIWvUkt/ctmnzteghFnUtC+i/T2MWFetk/m+:NaKXe2m5CREDssfnxeo/2XUKu+
Yara None matched
VirusTotal Search for analysis
Name 22ca5e3dcd26fa66_115981500-css_bundle_v2[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\115981500-css_bundle_v2[1].css
Size 36.1KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 c29aa18d795af74929173ceb3122e759
SHA1 5b39dbf5bbecfc61d844242c136d3f1ceea88d7f
SHA256 22ca5e3dcd26fa66a4af4b4a5d47a6a3a17f4cb9abdd03707901758b28f5c1d6
CRC32 C4A0C5E2
ssdeep 384:B0OhFvg3AwN6VysImDyPWquJMpx/SCYW0bS8+Rl9yapwuJ86YKSQCNL/J69nKg9N:B0Oh+/N6nIm6IvW0ErVJwxgngRdFr2
Yara None matched
VirusTotal Search for analysis
Name 2cb09c7b3e19bfc4_analytics[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\analytics[1].js
Size 48.0KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 6df1787c4be82d1bb24f8bffa10c7738
SHA1 3634e839429e462e49c5f42b75fbfb4ba318af6d
SHA256 2cb09c7b3e19bfc41743ca3624ef81c3258d56525647feac76aa757e0292627a
CRC32 ACF7AC32
ssdeep 768:/yR3fYFBLbfs5sP5XqY3TyPnHpl1WY3SoavFVv6PU+CgYUD0lgEw0stZM:/y9gZfl5h3UHpaY3SoRCw0sk
Yara None matched
VirusTotal Search for analysis
Name 8684a32d1a10d050_maia[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\maia[1].css
Size 42.5KB
Processes 7400 (iexplore.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 9e914fd11c5238c50eba741a873f0896
SHA1 950316ffef900ceecca4cf847c9a8c14231271da
SHA256 8684a32d1a10d050a26fc33192edf427a5f0c6874c590a68d77ae6e0d186bd8a
CRC32 021CA9F6
ssdeep 768:xwAbmEw+jAJFnSCZ9vWdmIfhjQucISYsU8/F+:bAJFnSC3W1QXISYsU8t+
Yara None matched
VirusTotal Search for analysis
Name f9ab6ea1f0ca7bbe_44[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\44[1].htm
Size 41.5KB
Processes 7400 (iexplore.exe)
Type HTML document, ASCII text, with very long lines
MD5 5b0175dd30bd407af2915d017f1f4e90
SHA1 9d731789c2b12c396ea5cf075410da42f555005c
SHA256 f9ab6ea1f0ca7bbe8e50c9df8b688da3f516b8d60c6a3532c61338514a15d122
CRC32 7DD21A01
ssdeep 768:Rb3eyHHvPWdfL1VVtl4wtlvywhIsXnSplt2SHD:Rb3LHH2dfLNEwtlyplT
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name cbad27c35fbc84e2_blogger-logotype-color-black-1x[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\blogger-logotype-color-black-1x[1].png
Size 1.1KB
Processes 7400 (iexplore.exe)
Type PNG image data, 112 x 27, 8-bit colormap, non-interlaced
MD5 a9d652846aeacdf8da5401f6e4d4a409
SHA1 6127321cafe0be999bc0c9d952715ede2b9dd83d
SHA256 cbad27c35fbc84e2da4280476adeb197566db2750b8b4a79eb7e872db8d8acb7
CRC32 66E5D8E4
ssdeep 24:pHw9USYaX/4NI/2E9sif2iEOMyraXw0RkG:gtYaX/RsOEOK5RkG
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a01a632e56731a85_kfolcnqeu92fr1mmwulfbbc-[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
Size 19.9KB
Processes 7400 (iexplore.exe)
Type Web Open Font Format, TrueType, length 20396, version 1.1
MD5 68d6dabfe54e245e7d5d5c16c3c4b1a9
SHA1 7fdab895eaebecedb3fb5473eab94a1b292cef19
SHA256 a01a632e56731a854f35701aa8c3a6a19a113290d9032ff9048f8064c45383bd
CRC32 657DC019
ssdeep 384:SfXdUIIA0zhyKR28ePpAwxZ5M3py8wtshtdf45DEVTGdYb7H2Q/VEgm:Svdj0zhbRmjIQ8wtsV4lEVGdY3/i/
Yara None matched
VirusTotal Search for analysis
Name 4742177c20372209_blogin[2].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\blogin[2].htm
Size 148.5KB
Processes 7400 (iexplore.exe)
Type HTML document, UTF-8 Unicode text, with very long lines
MD5 f3001e18e22fd4b4dd812d36edca849e
SHA1 018e700df0f018870629451602ec0a4439f9fe56
SHA256 4742177c203722098db2f92f1199cee64664c131211d6caf79f2edff86f619d4
CRC32 C337B7DF
ssdeep 1536:8bS/sDkN24yywq/Qq2wpx2w8/dKhjxytS5ei2hB9xwZAb/a1ZHhZZNWZtXwnW29q:CSUvaEaFIOyRgFC5rjWi
Yara None matched
VirusTotal Search for analysis
Name 17ea722efecdb3f2_css[2].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\css[2].css
Size 188.0B
Processes 7400 (iexplore.exe)
Type ASCII text
MD5 3bd925042c5aa408e6ffd3886a769ac3
SHA1 4b1cc4bdc645a642dbec4459203d6431237884e3
SHA256 17ea722efecdb3f25e85780ecfdc6fdf0c52b0947ba0ab48bfe5e055d73e85f9
CRC32 87BF9F8A
ssdeep 3:0SYWFFWlIYCiF15RI5XwDKLRIHDfFWYhfqzrZqcdJ2dTi8EuRlGwLYTL5JYARNin:0IFFm15+56Zzhizlpd0celB69JNin
Yara None matched
VirusTotal Search for analysis
Name da3eb4ab25e02a8d_1277698886-ieretrofit[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\1277698886-ieretrofit[1].js
Size 26.1KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 cb9af0197f496f52b471a76cfd8d601a
SHA1 067b3ee27f6b49431b5c72791d52f353c577853b
SHA256 da3eb4ab25e02a8dc118febc626df495acd468e84bc0b9767b56e8959b150f99
CRC32 7DBDE732
ssdeep 384:kRXBsAF8UMG+43L1dHMqXCxPHo189YaGuVMxoufjWFerWxWHrog4P+eF4MeUkz9+:kRX1kwqwVqkWxWHrwjF4VUQ9DlbQ
Yara None matched
VirusTotal Search for analysis
Name 934d8989883b7cf1_1564291244-widgets[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\1564291244-widgets[1].js
Size 143.9KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 785136fe4454f41862d0a9e70982dd6c
SHA1 76f4b04df165030565576648e156ab4600200196
SHA256 934d8989883b7cf1c2c336b02c88ab26f80edd2a2447686665665a5c0dacb86c
CRC32 1B911F50
ssdeep 1536:Mi2uQ2rcWe9MZ4oxI4VKq7N49dlbQ3KwwPBsYn7YJlUNpKG2rQNj3NvEk7GFciNX:OSVKqqU3KVbHIrkZGIVm
Yara None matched
VirusTotal Search for analysis
Name 6e8a28a0638c920e_mem5yags126mizpba-un_r8ouuhv[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\mem5YaGs126MiZpBA-UN_r8OUuhv[1].woff
Size 18.2KB
Processes 7400 (iexplore.exe)
Type Web Open Font Format, TrueType, length 18668, version 1.1
MD5 a7622f60c56ddd5301549a786b54e6e6
SHA1 d55574524345932db3968c675e1aea08c68a456f
SHA256 6e8a28a0638c920e5b76177e5f03ba94fcdedd3e3ecd347c333d82876b51c9c0
CRC32 36CC95AF
ssdeep 384:Wv4QHZChiRh3lwLOf8cWN78NXpcr6gBUA9CD/q4cOPZmPO:WvwhNOkvvxC7qnc
Yara None matched
VirusTotal Search for analysis
Name ecb30886406e3f77_gradients_light[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\gradients_light[1].png
Size 403.0B
Processes 7400 (iexplore.exe)
Type PNG image data, 20 x 1100, 8-bit/color RGBA, non-interlaced
MD5 4f7de2e6afefb125b1f14fa5cda610ee
SHA1 57a145f234b504a73f9d55cf39f2231a04719456
SHA256 ecb30886406e3f776ff7bc3834de849944471e626ff148bed2fa389d02866044
CRC32 DC34595E
ssdeep 12:6v/74Qlk8WIyzs740Oc5maj4m3YULe3dk:Hgk8uw740OcWAY13dk
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a786a9d1a429aa43_{2d7dc9e0-a6e3-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2D7DC9E0-A6E3-11EB-BDE1-94DE278C3274}.dat
Size 3.5KB
Processes 6988 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 47108872dfc10ff5fd13b398a819ec32
SHA1 2a1c81f87dea3fa2aaf94f48363bd8517cda1c1f
SHA256 a786a9d1a429aa43cecb4908a9f9404e2ed3122974292cd214fb9478098c6d99
CRC32 4118C777
ssdeep 12:rl0oXGFwxrEgmfx06FO2QrEgmfx0qTNlI8lbaxYFQRy0/:rlxG/QGBNlJJmgM
Yara
  • Microsoft_Office_Document_Zero - Microsoft Office Document Signature Zero
VirusTotal Search for analysis
Name 21cc4dc6c3c01b84_3101730221-analytics_autotrack[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\3101730221-analytics_autotrack[1].js
Size 24.7KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 094ce5dcaccf632457ae9fbf4f325399
SHA1 87e144f51c7bee2d624709c8f596037a92d06e66
SHA256 21cc4dc6c3c01b84c808004173f42e3ed1b4f09551a10d69b4cec7394a1590e6
CRC32 AFC34DF4
ssdeep 768:xkt9hXjJ9UP+8qeyDVrQi7xD21qTOxcVB9yNGY:xc9hXjJYyDVrQi7xD21qTfBg
Yara None matched
VirusTotal Search for analysis
Name fb50ac8ff6534e0a_cb=gapi[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\cb=gapi[1].js
Size 100.6KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 88d349cb2e4a5cda56d6aceb7814c003
SHA1 0207d4f13e45d1426962cc27801eb077c2bb12a9
SHA256 fb50ac8ff6534e0a729d06cadcf21132f67316823655960cbcb82d6299c84e8c
CRC32 AEE32865
ssdeep 1536:FFEkfyvq4mjPOU9MQu6a8prWgxCXexVEMqmNd/t9KyJ/v4ISKQAAirTqt4UpJ5w0:zfyvq4OCXuqkdl9dpBSKQAZrT6J5w0
Yara None matched
VirusTotal Search for analysis
Name 0fdcb4746995f0d5_body_gradient_tile_light[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\body_gradient_tile_light[1].png
Size 95.0B
Processes 7400 (iexplore.exe)
Type PNG image data, 10 x 10, 1-bit colormap, non-interlaced
MD5 3b2a20d5b0ba4ca0c5dd90865ad6b9c4
SHA1 a90928a16d11d21e112b45b60990a9d7d19cc1d5
SHA256 0fdcb4746995f0d5240e5ec11370cb950722a894f3cff4118aa68ccc92010edd
CRC32 B96E65DC
ssdeep 3:yionv//thPlH1kmlS1jmTQ9IyehXhbp:6v/lhPcS5TeIFdhbp
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 0fc52ef116f03fd9_281434096-static_pages[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\281434096-static_pages[1].css
Size 3.7KB
Processes 7400 (iexplore.exe)
Type ASCII text, with very long lines
MD5 b3e61df6e41a93485461f77324fcd93e
SHA1 46efb1044ff1cb854e02bcb49ada1d501ce0aff4
SHA256 0fc52ef116f03fd95f9857856f1e2cbdfa2cacc398e066db0d8d5481739bc2d7
CRC32 A124C187
ssdeep 96:Tpnj64Z4HufeAA4DhRXRBd031AkDhRXRBd039YAH/hv:xjnRfp
Yara None matched
VirusTotal Search for analysis
Name 416383056b9ae44d_css[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\css[1].css
Size 613.0B
Processes 7400 (iexplore.exe)
Type ASCII text
MD5 e061445ce9fa2bcd1ec9ed28fdbae3ab
SHA1 50aa0e173c9bffb3dc4b9625a413e3c29e02f56f
SHA256 416383056b9ae44d4f3247b8ee2a780620bc9d88eabfad6e487bd6df682efa2e
CRC32 92E65C9E
ssdeep 12:UJO6940FD7O6ZRoT6pYwE5r37uqF/iO6ZRoT6pixUEqF/iO6ZN76pixQvJY:G9XD7OYs/frR/iOYsNxUv/iOYN7Nxn
Yara None matched
VirusTotal Search for analysis
Name f74e7582ac7d7823_6ffupzse.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\6FFUPZSE.txt
Size 192.0B
Processes 7400 (iexplore.exe)
Type ASCII text
MD5 8fec7f853ef67f6a6d4b0a5efb083bea
SHA1 3db957a2520e8f9aad1dc40176196a2efeae9bf5
SHA256 f74e7582ac7d7823b1074d01c4e751a4a8a0bd8a217ac8391a2ffa4a8fa2fe90
CRC32 1BC361A6
ssdeep 3:qPCi2VvkCRv75vkTvWblNW2XvSfXEoP00jLAc8QzvkCRv75vMrkdXi6VS7SmWtXX:g2VvrvkTvWBE2XvSf0F0jt8svrvaUSVG
Yara None matched
VirusTotal Search for analysis