Dropped Files | ZeroBOX
Name 5e48c36d9e060a97_~$voice attachment.docm
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$voice attachment.docm
Size 162.0B
Processes 2488 (WINWORD.EXE)
Type data
MD5 ee0845f0d17fc8b7ffa2416937a2baa0
SHA1 9e86291ad24f7c8580e27278a00bc88e032ae2c9
SHA256 5e48c36d9e060a974f7a6b7b816164088152dbf467c4219390c67f946df3773a
CRC32 2750DCAB
ssdeep 3:yW2lWRdUX1W6L7P1lvK7qP3KFIt5f3RPrl:y1lW4lWmLK7qiW/Tl
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{826a05f1-96ee-4cdb-9f0e-4f05e900525c}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{826A05F1-96EE-4CDB-9F0E-4F05E900525C}.tmp
Size 1.0KB
Processes 2488 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name e891f3388e341e33_~wrs{d50ebca8-ef7f-4cce-9bba-bfd8bc60269d}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D50EBCA8-EF7F-4CCE-9BBA-BFD8BC60269D}.tmp
Size 1.5KB
Processes 2488 (WINWORD.EXE)
Type data
MD5 922124d55392c4a3387b3d2b12cdbea9
SHA1 2e915cf8f354d65cf538c30d4eedb4ff61bcca00
SHA256 e891f3388e341e33330c597533a860f1b41b287ecbb438a2ad98afb05ca71a78
CRC32 5D018606
ssdeep 3:llYdltn/lLUUk:A329
Yara None matched
VirusTotal Search for analysis
Name 8a804a6141458944_fijxgr1chfv6js.vbs
Submit file
Filepath C:\Users\test22\AppData\Local\fijxgr1chfv6js.vbs
Size 20.0B
Processes 2488 (WINWORD.EXE) 292 (wscript.exe)
Type ASCII text, with no line terminators
MD5 4d7693d0977ac2d09d861d5402ed4ba4
SHA1 38fca0513c1237c0bade50ca278093aa714d8a70
SHA256 8a804a614145894431f8dc0bca2f7257fb06e94cb02bc065f1e1d4bcf9e09082
CRC32 CEA4B5BB
ssdeep 3:JHwx:JHw
Yara None matched
VirusTotal Search for analysis
Name db8539b0161f792e_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2488 (WINWORD.EXE)
Type data
MD5 5ad3b1e373533f795111d4026680cbad
SHA1 a46d4c7418d4334154b91f943c7e7236bccc89fc
SHA256 db8539b0161f792e34a0dd060ce7db9d34746fe152dbb03ecdebdaa9621dc816
CRC32 CAC0707F
ssdeep 3:yW2lWRdUX1W6L7P1lvK7qP3KFIt5f3FBhXn:y1lW4lWmLK7qiWrH
Yara None matched
VirusTotal Search for analysis