Dropped Files | ZeroBOX
Name 529ee598370fa59c_recoverystore.{3af13721-f8b1-11eb-91f6-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{3AF13721-F8B1-11EB-91F6-94DE278C3274}.dat
Size 4.5KB
Processes 1932 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 450371fca506f475e5ec57933c2f6d33
SHA1 2636214b8777a37f9f01a66b966021eac4b93fe3
SHA256 529ee598370fa59c3ba646ee0fcec6a0530358088543cb547a86a64a050ad925
CRC32 04ADB3B7
ssdeep 12:rlfF2UUorEg5+IaCrI0F7+F2ZrEg5+IaCrI0F7ugQNlTqbax1jNlTqbax1:rqg5/1Z5/3QNlW+jNlW+
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name b0abe318200dcde4_error[2]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\error[2]
Size 1.7KB
Processes 888 (mshta.exe)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 b9bec45642ff7a2588dc6cb4131ea833
SHA1 4d150a53276c9b72457ae35320187a3c45f2f021
SHA256 b0abe318200dcde42e2125df1f0239ae1efa648c742dbf9a5b0d3397b903c21d
CRC32 3FC3F274
ssdeep 48:NIAbzyYh8rRLkRVNaktqavP61GJZoF+SMy:xWqxztqaHO
Yara None matched
VirusTotal Search for analysis
Name 7990e703ae060c24_error[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\error[1]
Size 3.2KB
Processes 888 (mshta.exe)
Type HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 16aa7c3bebf9c1b84c9ee07666e3207f
SHA1 bf0afa2f8066eb7ee98216d70a160a6b58ec4aa1
SHA256 7990e703ae060c241eba6257d963af2ecf9c6f3fbdb57264c1d48dda8171e754
CRC32 B319CFA5
ssdeep 96:vKFlZ/kxjqD9zqp36wxVJddFAdd5Ydddopdyddv+dd865FhlleXckVDuca:C0pv+GkduSDl6LRa
Yara None matched
VirusTotal Search for analysis
Name eaf427a3b2b5d1e8_brnuymzfvtubareudks.sct
Submit file
Filepath C:\ProgramData\bRNuYmzFVtUBAreUdKS.sct
Size 2.4KB
Processes 460 (iexplore.exe)
Type HTML document, ASCII text, with very long lines, with CRLF line terminators
MD5 048518f0cbc8f7b0b806cb78a705a3f6
SHA1 27ee815af7f094bfa0e79675e1fdf6eda7c7dd57
SHA256 eaf427a3b2b5d1e830ee8551cadcd7d1ca954d9d6246a5866346d2a9c8d5ca61
CRC32 4E5D1011
ssdeep 48:tzaJiSV8qVeEkYhM9ZEt0IyCGrSisDXugVGAdLJ0i0hC7:PW8KkYS9I05CWS3D+g9J
Yara None matched
VirusTotal Search for analysis
Name 92c51e03d5d2b1cb_{3af13722-f8b1-11eb-91f6-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3AF13722-F8B1-11EB-91F6-94DE278C3274}.dat
Size 3.5KB
Processes 1932 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 fc6cc4410a18fa85aa2b1538237c6a9a
SHA1 8a2ea5e01becb2cf6897599159f5e108af919080
SHA256 92c51e03d5d2b1cbaa02172a18f630a96ba1c39eb51cf8aff5ec278758f77ebe
CRC32 7C0F09D4
ssdeep 12:rl0oXGFvxrEgmfox76FmsrEgmfe7qTNl889baxvsKtHaK+wCUF2O44:r6xGAuGZNl88Wrlh+/UFh
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 5f95eff2bcaaea82_warning[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\warning[1]
Size 1.0KB
Processes 888 (mshta.exe)
Type GIF image data, version 89a, 36 x 38
MD5 124a9e7b6976f7570134b7034ee28d2b
SHA1 e889bfc2a2e57491016b05db966fc6297a174f55
SHA256 5f95eff2bcaaea82d0ae34a007de3595c0d830ac4810ea4854e6526e261108e9
CRC32 EED13E6B
ssdeep 12:z4ENetWsdvCMtkEFk+t2cd3ikIbOViGZVsMLfE4DMWUcC/GFvyVEZd6vcmadxVtS:nA/ag/QSi6/LKZzqKVQgJOexQkYfG6E
Yara None matched
VirusTotal Search for analysis