Dropped Files | ZeroBOX
Name 76b408bc1d79438b_{0c266fba-d323-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0C266FBA-D323-11EB-BDE1-94DE278C3274}.dat
Size 4.5KB
Processes 540 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 c9621aeb4d87c66fea1040dea64105f4
SHA1 b8452d0be97e47675323012b4009bd2d158ea3da
SHA256 76b408bc1d79438b25f56dc8eabeaaf73333422ea480d8e6e343e6ef34b6a5d3
CRC32 9D9D97AB
ssdeep 12:rlxAF+vrEgm8GL7KFExrEgm8G77qsANl26abax1NlwfRbaxxtb+4:rfvG8UxG8mANlIoNlcQta
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 234363abe54009d5_recoverystore.{0c266fb9-d323-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0C266FB9-D323-11EB-BDE1-94DE278C3274}.dat
Size 5.0KB
Processes 540 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 55323307fbf2c7297149b59083a9fbfb
SHA1 f0c78d788c47544870a250b9cfd214cc71b21cd5
SHA256 234363abe54009d5a47e417ca749ab6129232daf679bb3b1afc5531f401f8aca
CRC32 8C87423F
ssdeep 24:rqLKS5/fkaTG5/k85jBM+NlWTJ9NlWXS:rsf5EOG5cojBSTJoXS
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 4277fde72512aedc_vbc[1].exe
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\vbc[1].exe
Size 809.5KB
Processes 1836 (iexplore.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 5beae2f6cea2c9f92ab4e2b34dfac0d4
SHA1 bcc2fd8547e15bc77f77fc227b563012e16ba4b1
SHA256 4277fde72512aedcd199bfe2d51f005870a4c947dc4faa5c9806992b1af37c2c
CRC32 8E61D4CE
ssdeep 12288:dsiWFHmscN7fKpOQk3cjl1r17txBV3bShEOSJZ/8s9nqAmbO/mAWYTlxEAmD:mZH+KUFcjlVFLB8hEOgZkCqrW3WYTb
Yara
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • Is_DotNET_EXE - (no description)
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis