Dropped Files | ZeroBOX
Name 93ddafef8f5245cd_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 1556 (WINWORD.EXE)
Type data
MD5 435b3563e7ca8f120afe299e499d2a65
SHA1 9ece5a95744728315ba50d435b224a8a1bf2f23a
SHA256 93ddafef8f5245cd728c7f5aaa32fbb29911c14c63abfab95521f7ed52750b83
CRC32 193E6707
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVtw:y1lWnlxK7ghqqFw
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{fc3a2e16-f845-4503-a0ae-d02d72da29ef}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FC3A2E16-F845-4503-A0AE-D02D72DA29EF}.tmp
Size 1.0KB
Processes 1556 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 06b913dd62dbc9b1_5bbf8d38.emf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5BBF8D38.emf
Size 4.9KB
Processes 1556 (WINWORD.EXE)
Type Windows Enhanced Metafile (EMF) image data version 0x10000
MD5 21328d6eaa23cd4e786d6c18ed931962
SHA1 18fc2e4aa4d7dd1122c5ba11f4f073cf27720678
SHA256 06b913dd62dbc9b1ae00ba33dd5bcd87e5efd5e2b56ebf7e2ea9fed37a91d5f6
CRC32 2C3ADA06
ssdeep 48:unhNY46sdBgD89t1Tb4HKKZX3Y6kpnydHk0azLUX:MY4jBvt1X6Y+EDS
Yara None matched
VirusTotal Search for analysis
Name f3c7b201229ac305_~$06_5212302001979.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$06_5212302001979.doc
Size 162.0B
Processes 1556 (WINWORD.EXE)
Type data
MD5 2da277991ad6e8f7f9363d8e9d3c9cfd
SHA1 ae7ba11bd22cf030631b9b137c1a9ff73fa395fb
SHA256 f3c7b201229ac3054837eeb9e73220fb2490844d14727abdc11cafa9043abc0a
CRC32 0391F9D8
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVtXul/S:y1lWnlxK7ghqqFXutS
Yara None matched
VirusTotal Search for analysis