Dropped Files | ZeroBOX
Name f825dd89181e7435_d93f411851d7c929.customDestinations-ms~RF28082c3.TMP
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF28082c3.TMP
Size 7.8KB
Processes 9068 (None) 6652 (None)
Type data
MD5 61d3b003e73f968491bb9de05318fcbd
SHA1 abb40732bf72a072c5b176449fdb8f1c56383e03
SHA256 f825dd89181e743525684aff8d99cc6d78046e461147c33b6f7a182b98c58ea9
CRC32 76116DE9
ssdeep 96:wtuCiGCPDXBqvsqvJCwoNtuCiGCPDXBqvsEHyqvJCworc7HwxGlUVul:wt7XoNt7bHnorXxY
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name f323d6ec7f23d38b_Ahnlab.hwp
Submit file
Filepath C:\Users\test22\AppData\Roaming\Ahnlab\Ahnlab.hwp
Size 26.4KB
Processes 9068 (None)
Type Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
MD5 44747ab1d0295b16d08b078e892c595a
SHA1 8e45603c838a2e2b0cf590769230a0a78747c188
SHA256 f323d6ec7f23d38bf004e761bd03bb86eabe21d2f750cbe2bd4a639942246d45
CRC32 5576CAFC
ssdeep 96:fkA1SjRUSRcxhgR/dZ1HCltYSgmNoIpvRiMLdvOrd3iHSmUKxp6FBc/LLkARt/UE:fc7VshXrXaITUIPJDeu+MOMSZ2
Yara
  • NPKI_Zero - File included NPKI
  • Antivirus - Contains references to security software
VirusTotal Search for analysis