Dropped Files | ZeroBOX
Name d172d750493be64a_icon18_wrench_allbkg[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\icon18_wrench_allbkg[1].png
Size 475.0B
Processes 1332 (iexplore.exe)
Type PNG image data, 18 x 18, 8-bit colormap, non-interlaced
MD5 f617effe6d96c15acfea8b2e8aae551f
SHA1 6d676af11ad2e84b620cce4d5992b657cb2d8ab6
SHA256 d172d750493be64a7ed84dec1dd2a0d787ba42f78bc694b0858f152c52b6620b
CRC32 87FB2FCE
ssdeep 12:6v/7ElZUJDdwjI5Fa4ep0LPf+veUxQn6/Xh0ptMQsfZhkNTpQEsb7:ZK1dw0etKjfUxQn6/x0DWrETpQZb7
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e187164d5afa5394_css[2].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\css[2].css
Size 188.0B
Processes 1332 (iexplore.exe)
Type ASCII text
MD5 8b5e62c03dea1d170435e3b9905e1eb4
SHA1 685952eeed70a2d994e3cb10577b6225e7f7c726
SHA256 e187164d5afa5394e2367788dff613b00389cd9e21a083af70e286ec74030ffe
CRC32 6A6C3532
ssdeep 3:0SYWFFWlIYCiF15RI5XwDKLRIHDfFWYhfqzrZqcdJ1NAIquRlGwLYTL5JYARNin:0IFFm15+56ZzhizlpddtHlB69JNin
Yara None matched
VirusTotal Search for analysis
Name ea50ac7fddb61a5c_kfomcnqeu92fr1mu4mxm[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\KFOmCnqEu92Fr1Mu4mxM[1].woff
Size 19.9KB
Processes 1332 (iexplore.exe)
Type Web Open Font Format, TrueType, length 20332, version 1.1
MD5 dc3e086fc0c5addc09702e111d2adb42
SHA1 b1138b84ff19eac5f43c4202297529d389bd09b7
SHA256 ea50ac7fddb61a5ce248a7f8b3a31a98fe16285e076b16e6da6b4e10910724bb
CRC32 F6DA8D99
ssdeep 384:U0iwaxoOUPVkOJJSu6SsCKTIRDqG9oHKwZh98OSv+MsgkAOY:75mlUmOSu1guh+fZhLSxkAr
Yara None matched
VirusTotal Search for analysis
Name 08ceec9e56972e84_4165186901-widgets[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\4165186901-widgets[1].js
Size 147.0KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 ad1d34f7f094f646261b28ae4d8a8ad6
SHA1 1fe6e907f87aa0ca13f6f170859bc065f62eafd4
SHA256 08ceec9e56972e8493cf3c6bd21886a68d6325f6c12babc85ad9dff845b1df92
CRC32 1EA96FED
ssdeep 1536:9/eRZMuKGyVWG9MIkEDCgMhx1ThPZwdprLYq3SmkZstUszed6BTC9UHblCYg3JxJ:7oyMh5S5imTtQdxy7Q9rEeYFeOm
Yara None matched
VirusTotal Search for analysis
Name b32e8baf10154d55_{4c8301c4-db9b-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4C8301C4-DB9B-11EB-BDE1-94DE278C3274}.dat
Size 3.5KB
Processes 1772 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 12168d91463dedabe39657ba2a8a72ee
SHA1 0700f6d3afd97f15f43c35e9a0f8ad20aabda60e
SHA256 b32e8baf10154d55477daedd2ef508ae8dbbb08eef718297e4b3802b04c94d3c
CRC32 F99C1A7D
ssdeep 12:rl0oXGF0+xrEgmfx06FxrEgmfx0qTNlI8lbaxYzQRyf/:rIxGFGBNlJJMg3
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 8684a32d1a10d050_maia[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\maia[1].css
Size 42.5KB
Processes 1332 (iexplore.exe)
Type UTF-8 Unicode text, with very long lines, with no line terminators
MD5 9e914fd11c5238c50eba741a873f0896
SHA1 950316ffef900ceecca4cf847c9a8c14231271da
SHA256 8684a32d1a10d050a26fc33192edf427a5f0c6874c590a68d77ae6e0d186bd8a
CRC32 021CA9F6
ssdeep 768:xwAbmEw+jAJFnSCZ9vWdmIfhjQucISYsU8/F+:bAJFnSC3W1QXISYsU8t+
Yara None matched
VirusTotal Search for analysis
Name 78a712fd0cc8b59b_recoverystore.{4c8301c3-db9b-11eb-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4C8301C3-DB9B-11EB-BDE1-94DE278C3274}.dat
Size 4.5KB
Processes 1772 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 0c032c84ea5ebf04b7c186872ec34260
SHA1 43e03ea81aeb8505b5762f7d1b47dccae4ee4075
SHA256 78a712fd0cc8b59b0a5654c588ca898410769f5179a1dc3bee0c71bc2e2da0fc
CRC32 70D45C79
ssdeep 12:rlfF2XrEg5+IaCrI0F7+F2IUrEg5+IaCrI0F7ugQNlTqbax5VasZNlTqbax5VacA:rqX5/1b5/3QNlWgHNlWg
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 73d6a5ea11fb7bf6_analytics[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\analytics[1].js
Size 48.2KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 042b7183d8645f5cf9d0d6acd5ff8358
SHA1 447a98467ea31e253ecb63ee8564c8b5e1e77d58
SHA256 73d6a5ea11fb7bf6e6a6ccd44b1635d52c79b0a00623d0387c9dddd4b7c68e89
CRC32 18BD6311
ssdeep 768:/yR3fYFBCwsNDsP5XqY0TyPnHpl1TY3SoavyVv6PU+CgYUD0lgEw0stZK:/y9g1r5h0UHp/Y3SowCw0sy
Yara None matched
VirusTotal Search for analysis
Name c98b647124c63dea_mem5yags126mizpba-un_r8ouuhv[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\mem5YaGs126MiZpBA-UN_r8OUuhv[1].woff
Size 18.3KB
Processes 1332 (iexplore.exe)
Type Web Open Font Format, TrueType, length 18744, version 1.1
MD5 2a6051095e2330fb1a45b836e3ba038e
SHA1 1da733c279aa12c3d8857aed80cd910c2b209eae
SHA256 c98b647124c63dea93b52bcf6a97a76a6944b9894dc0377b70f8c3b47d91382a
CRC32 CACCA3BD
ssdeep 384:zawWpQHZNpxHreHjc5bHhYc9ON58zWZnmiN4RHcSd2UrrMKCWX:zawPscLqqO/8zG/4RHvdh33X
Yara None matched
VirusTotal Search for analysis
Name cbad27c35fbc84e2_blogger-logotype-color-black-1x[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\blogger-logotype-color-black-1x[1].png
Size 1.1KB
Processes 1332 (iexplore.exe)
Type PNG image data, 112 x 27, 8-bit colormap, non-interlaced
MD5 a9d652846aeacdf8da5401f6e4d4a409
SHA1 6127321cafe0be999bc0c9d952715ede2b9dd83d
SHA256 cbad27c35fbc84e2da4280476adeb197566db2750b8b4a79eb7e872db8d8acb7
CRC32 66E5D8E4
ssdeep 24:pHw9USYaX/4NI/2E9sif2iEOMyraXw0RkG:gtYaX/RsOEOK5RkG
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 74ec003b6f1f0514_blogin[2].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\blogin[2].htm
Size 149.5KB
Processes 1332 (iexplore.exe)
Type HTML document, UTF-8 Unicode text, with very long lines
MD5 5021926f4ed1af508026e8398045cd65
SHA1 0a975d82319bee560275343ed64a0bc1ea8a69dd
SHA256 74ec003b6f1f051472fa186bff06b8deee1c46b525dd60a67bf1a200b83c76b2
CRC32 293AECC8
ssdeep 1536:BbSpjB/wN7FMONdQKzFFDkWVN57USnW+9MAOQtkB3AxtjApRnu01cawHtJUSWC8:hSJVqFMONuYtVqB3AxtEpIMSWn
Yara None matched
VirusTotal Search for analysis
Name a01a632e56731a85_kfolcnqeu92fr1mmwulfbbc-[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
Size 19.9KB
Processes 1332 (iexplore.exe)
Type Web Open Font Format, TrueType, length 20396, version 1.1
MD5 68d6dabfe54e245e7d5d5c16c3c4b1a9
SHA1 7fdab895eaebecedb3fb5473eab94a1b292cef19
SHA256 a01a632e56731a854f35701aa8c3a6a19a113290d9032ff9048f8064c45383bd
CRC32 657DC019
ssdeep 384:SfXdUIIA0zhyKR28ePpAwxZ5M3py8wtshtdf45DEVTGdYb7H2Q/VEgm:Svdj0zhbRmjIQ8wtsV4lEVGdY3/i/
Yara None matched
VirusTotal Search for analysis
Name 362b69c42b10b4a9_3775400722-ieretrofit[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\3775400722-ieretrofit[1].js
Size 26.0KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 5c43073b78d07cc3c3f7ce0d4e3227b3
SHA1 32e8ec5246fb97983642796d3eb1c1b6eefb836c
SHA256 362b69c42b10b4a9d1a79837f44f6ce3e5419d78684b94dc5ca2fe471873d3aa
CRC32 47AF6B30
ssdeep 384:12aOYTYDWsss8m/LFB9qxCXhHotj3+l6VM8XufjWFNPvyHe601DeP+eF4MegkQ4f:12M1lRkqZvyHetojF4Vgj4Dlag7
Yara None matched
VirusTotal Search for analysis
Name a1495da3cf3db37b_favicon[2].ico
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\favicon[2].ico
Size 3.6KB
Processes 1332 (iexplore.exe)
Type MS Windows icon resource - 2 icons, 32x32, 8 bits/pixel, 16x16, 8 bits/pixel
MD5 59a0c7b6e4848ccdabcea0636efda02b
SHA1 30ef5c54b8bbc3487ea2b4c45cd11ea2932e4340
SHA256 a1495da3cf3db37bf105a12658636ff628fee7b73975b9200049af7747e60b1f
CRC32 26FF9B96
ssdeep 6:NXulKltegZ//OekukCS4kdxpHIWvUkt/ctmnzteghFnUtC+i/T2MWFetk/m+:NaKXe2m5CREDssfnxeo/2XUKu+
Yara None matched
VirusTotal Search for analysis
Name 224d95cce0810861_3822632116-css_bundle_v2[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\3822632116-css_bundle_v2[1].css
Size 36.1KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 d390c06d2ab36f422aa956a5422f641c
SHA1 3451d2fa56bf7d5f66fd09c79376dd36fab85e46
SHA256 224d95cce08108610c46ef4134793dbdd619e43e90e9d9cf42716a08f45222f9
CRC32 65924129
ssdeep 384:B0OhFvg3AwN6VysImDyPWquJMpx/SCYW0bS8+Rl9yaZwuJ86YKSQCNL/J69nKg9N:B0Oh+/N6nIm6IvW0ErVJwxgngRdFr2
Yara None matched
VirusTotal Search for analysis
Name 78550c80f522c559_ees5odrt.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\EES5ODRT.txt
Size 192.0B
Processes 1332 (iexplore.exe)
Type ASCII text
MD5 bf83774abdf8efb116dc61879831e461
SHA1 b0c710c47e78ce7d45fe0402311bbead1388c9bb
SHA256 78550c80f522c55988e4800a2c0c9fb4de90e01a2bfd5364b126c19b55ed0682
CRC32 73D5A28C
ssdeep 3:qPC5Tg0XUflv75vYBJTTe5yV2cN/M0jL0rbXCUflv75v6fQT9jNwaVOVdcN/n:8uUDvQNMG2Z0jY/XCUDv6ai3w
Yara None matched
VirusTotal Search for analysis
Name ecb30886406e3f77_gradients_light[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\gradients_light[1].png
Size 403.0B
Processes 1332 (iexplore.exe)
Type PNG image data, 20 x 1100, 8-bit/color RGBA, non-interlaced
MD5 4f7de2e6afefb125b1f14fa5cda610ee
SHA1 57a145f234b504a73f9d55cf39f2231a04719456
SHA256 ecb30886406e3f776ff7bc3834de849944471e626ff148bed2fa389d02866044
CRC32 DC34595E
ssdeep 12:6v/74Qlk8WIyzs740Oc5maj4m3YULe3dk:Hgk8uw740OcWAY13dk
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 21cc4dc6c3c01b84_3101730221-analytics_autotrack[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\3101730221-analytics_autotrack[1].js
Size 24.7KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 094ce5dcaccf632457ae9fbf4f325399
SHA1 87e144f51c7bee2d624709c8f596037a92d06e66
SHA256 21cc4dc6c3c01b84c808004173f42e3ed1b4f09551a10d69b4cec7394a1590e6
CRC32 AFC34DF4
ssdeep 768:xkt9hXjJ9UP+8qeyDVrQi7xD21qTOxcVB9yNGY:xc9hXjJYyDVrQi7xD21qTfBg
Yara None matched
VirusTotal Search for analysis
Name 931a110c5e8b4a07_10[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\10[1].htm
Size 88.9KB
Processes 1332 (iexplore.exe)
Type HTML document, ASCII text, with very long lines
MD5 c3a52061a5fe3b17ffab6fec221a17fc
SHA1 4d0fcc1d7e01069cd4fef66f80bdbb3dca43c786
SHA256 931a110c5e8b4a07a3bb20f9e899fbafb65c015c246cbcae9205d180381f6312
CRC32 F58451B8
ssdeep 768:RY3eyHHvPWd0jSnLKj3M1qhjs22+SsXnZGNM2SFg:RY3LHH2d0jSOLM1qFh2YGNz
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis
Name c780ab9e75cfb9cc_blogin[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\blogin[1].htm
Size 410.0B
Processes 1332 (iexplore.exe)
Type gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
MD5 50f1eafe820eaac821544af1216b0d39
SHA1 8f18f009c640e738949e683da0b255a12c9b9aca
SHA256 c780ab9e75cfb9cc950bbaee79f36025185353afbce90c8305a0bf5e6e14a675
CRC32 7B968EA0
ssdeep 12:XFRcGjgkCOWsHvqfBwcgGJqIi0WrzBwcgGJqIi0WrW:XFRHuOTqZwGli0SwGli0h
Yara None matched
VirusTotal Search for analysis
Name 0fdcb4746995f0d5_body_gradient_tile_light[1].png
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\body_gradient_tile_light[1].png
Size 95.0B
Processes 1332 (iexplore.exe)
Type PNG image data, 10 x 10, 1-bit colormap, non-interlaced
MD5 3b2a20d5b0ba4ca0c5dd90865ad6b9c4
SHA1 a90928a16d11d21e112b45b60990a9d7d19cc1d5
SHA256 0fdcb4746995f0d5240e5ec11370cb950722a894f3cff4118aa68ccc92010edd
CRC32 B96E65DC
ssdeep 3:yionv//thPlH1kmlS1jmTQ9IyehXhbp:6v/lhPcS5TeIFdhbp
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 0fc52ef116f03fd9_281434096-static_pages[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\281434096-static_pages[1].css
Size 3.7KB
Processes 1332 (iexplore.exe)
Type ASCII text, with very long lines
MD5 b3e61df6e41a93485461f77324fcd93e
SHA1 46efb1044ff1cb854e02bcb49ada1d501ce0aff4
SHA256 0fc52ef116f03fd95f9857856f1e2cbdfa2cacc398e066db0d8d5481739bc2d7
CRC32 A124C187
ssdeep 96:Tpnj64Z4HufeAA4DhRXRBd031AkDhRXRBd039YAH/hv:xjnRfp
Yara None matched
VirusTotal Search for analysis
Name 416383056b9ae44d_css[1].css
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\css[1].css
Size 613.0B
Processes 1332 (iexplore.exe)
Type ASCII text
MD5 e061445ce9fa2bcd1ec9ed28fdbae3ab
SHA1 50aa0e173c9bffb3dc4b9625a413e3c29e02f56f
SHA256 416383056b9ae44d4f3247b8ee2a780620bc9d88eabfad6e487bd6df682efa2e
CRC32 92E65C9E
ssdeep 12:UJO6940FD7O6ZRoT6pYwE5r37uqF/iO6ZRoT6pixUEqF/iO6ZN76pixQvJY:G9XD7OYs/frR/iOYsNxUv/iOYN7Nxn
Yara None matched
VirusTotal Search for analysis