Dropped Files | ZeroBOX
Name b72df5ff378c6d32_fsd-{3f0f5fbb-da70-41a3-b148-d56542b49789}.fsd
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{3F0F5FBB-DA70-41A3-B148-D56542B49789}.FSD
Size 128.0KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 232dc60c76a447aa8e16c8db2987ee05
SHA1 688a36f62610fdbf253b9b4b61fa0fce76ad584b
SHA256 b72df5ff378c6d32bc8dbfe0a43b287be246ef69fb3b7c8d055968bed163a06e
CRC32 9B00422B
ssdeep 48:I3xDkHrBmSsDGi6kvXD1zCOq3HWfVP3aMxK96Op96OZ:KxcmS7kvQOR3NLq
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{7a1e450e-8154-422f-a5e5-4372182e73d2}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7A1E450E-8154-422F-A5E5-4372182E73D2}.tmp
Size 1.0KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 505aca296ce61ba4_~$s afg post 9-11.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$s Afg post 9-11.doc
Size 162.0B
Processes 2428 (WINWORD.EXE)
Type data
MD5 e449ac6d110e74bff9e1f7067460430d
SHA1 f9fc1ffdc7f585aecc48b8cfe393269974c54d5c
SHA256 505aca296ce61ba46f5a66b2d2979318fc315b3e60f72be0db5bdc17e0a4ccf7
CRC32 3581E1FC
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVt7mltA//+qK:y1lWnlxK7ghqqF7mltA//+x
Yara None matched
VirusTotal Search for analysis
Name 5e8ac2bd54c242cb_fsd-cnry.fsd
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
Size 128.0KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 c60c08bfd38d5ef97f6f0e8db50b71c4
SHA1 d11a18601fb91d170babf67fa73eb27b07f2cbef
SHA256 5e8ac2bd54c242cbb096a35efc1f878a91055d74a7dd4902794b139b1e5f33a3
CRC32 38C278BC
ssdeep 48:I38kkwBPTOgHTWLI20vK9lPlIvu5f6FUCErru6h4EmY4EmIH:KNPagzW0i9lH5f6FUCE3Nh4En4EjH
Yara None matched
VirusTotal Search for analysis
Name 5909c9aa6243bab2_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2428 (WINWORD.EXE)
Type data
MD5 cd27393b0b94091115907158a5dae124
SHA1 a181b5eeb744f91e780a611ebe9752d9435cd25c
SHA256 5909c9aa6243bab27d7e6213d2e58aaadd4f7db8baa5b65037d6e07c57d37708
CRC32 12C56EA3
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVtnVt/A//+qK:y1lWnlxK7ghqqFVt/A//+x
Yara None matched
VirusTotal Search for analysis
Name edc0e68c5b776416_~wrs{3b0fb1c4-bc08-4032-b961-7798385cb5c0}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3B0FB1C4-BC08-4032-B961-7798385CB5C0}.tmp
Size 1.8KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 a8e26944986307e88a683b56f4eef695
SHA1 83eec405895c3b5c26c5cf218e00bb852041df34
SHA256 edc0e68c5b7764166f2e8200036901d31069a73cc0f1094ca8abb428755809ef
CRC32 80AF63D0
ssdeep 24:oKtMWwAQEzmO8/+h80V/PW4lFgTXnUjj5yf+t9Qf092taauZ3LGFiMtl:zlOf3c/+4liXWj5Jb92tQVGUMtl
Yara None matched
VirusTotal Search for analysis
Name f8ea4410eae621fc_fsd-{d0e256ce-bd69-468d-a2c8-79f0a0b8fdea}.fsd
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{D0E256CE-BD69-468D-A2C8-79F0A0B8FDEA}.FSD
Size 128.0KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 bbfda58db372521d118fb818527382b7
SHA1 25679bd98e15d59eb45e3080b234f8ace2d8662e
SHA256 f8ea4410eae621fcf36cb88c0725cc4782d1aa6a8683d1304ee8909d4bb68a1a
CRC32 7FCE2966
ssdeep 96:KMxyGcuKFtoGpwjXrGJ2HA78jmgGDVte9ZC1oZC19C3InRCPIn:NcwGpoGd4jCDIZOoZO9QInRWIn
Yara None matched
VirusTotal Search for analysis
Name d6ad675b2d7b76aa_fsf-ctbl.fsf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF
Size 114.0B
Processes 2428 (WINWORD.EXE)
Type data
MD5 1e3179e2369a9f2956c34db5ac2e2fb3
SHA1 721a16298d5bab7bf2e95ea0c4c7d1f8cb4fad93
SHA256 d6ad675b2d7b76aa98fb6d696ddcafc96e8312ef2905939bead982e83e9ea54d
CRC32 A896C8BD
ssdeep 3:yVlgsRlz5XlonfNJFzI+3qu7UPH5lzg+mf276:yPblz5X2C+auoPI+mf22
Yara None matched
VirusTotal Search for analysis
Name be5cf10e56cedff5_fsd-cnry.fsd
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD
Size 128.0KB
Processes 2428 (WINWORD.EXE)
Type data
MD5 33d988d960e80b056c0b24cf49300c26
SHA1 02f59583e07e614133499a58cfb080c431a16b7d
SHA256 be5cf10e56cedff5ae4862c772c90f3c875e05fb3246e530cb73cd41e3f9ad88
CRC32 8FE3801A
ssdeep 48:I3FNkwBOFyyiN75aenePV1uQQdUDYrkCJT3h/VbvLQ3h/VbvLGH:KBLN5nePiQaUkkC53h/JLQ3h/JLGH
Yara None matched
VirusTotal Search for analysis
Name c904ae38c5a45539_fsf-{0e1eee64-e8c6-4e2a-9759-63cf07fd8988}.fsf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
Size 114.0B
Processes 2428 (WINWORD.EXE)
Type data
MD5 abe1d4fe6e157737ea795cfdfa0ecc2b
SHA1 79c0d6011fec5f1c7a7e6dccbe6567b46e181c16
SHA256 c904ae38c5a455392bde137a4c56b895968aadc76662c37412b711edaa0be1c3
CRC32 7616E523
ssdeep 3:yVlgsRlzclQZlMaWYRTKHZ+R1Hc0Z276:yPblzJZ3R18u22
Yara None matched
VirusTotal Search for analysis