Dropped Files | ZeroBOX
Name 2830334b4f235977_a833e2e8.emf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A833E2E8.emf
Size 4.9KB
Processes 2536 (WINWORD.EXE)
Type Windows Enhanced Metafile (EMF) image data version 0x10000
MD5 6d06a44daf645d0f5fef3bcf485db971
SHA1 3c4d1821a414e38cac8379f49ed198ebe3146c7c
SHA256 2830334b4f23597712000666b54780cf7d478374acd0e3511fe29b0f0cee4f13
CRC32 CC14FBA2
ssdeep 48:XQNpXk/MssdBg6qjpLkwOEG6kpnydHk1a/Z:g5fBBFq9gV+Eu
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{32de539f-375b-477f-bac5-93bbbcfeb533}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{32DE539F-375B-477F-BAC5-93BBBCFEB533}.tmp
Size 1.0KB
Processes 2536 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 8fa6387bd77ce648_~$06_2966063104581.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$06_2966063104581.doc
Size 162.0B
Processes 2536 (WINWORD.EXE)
Type data
MD5 9513f10b947ce130c35a9dd8740b493a
SHA1 4707e1183d58af9353ae4bd8b761510087200656
SHA256 8fa6387bd77ce648b680ba19dcc55171c656c768118f3c208d04bd37e9509bb5
CRC32 AF625775
ssdeep 3:yW2lWRd/dwoW6L7KtvK7+scItaqYGn:y1lWioWmeVK7+WAGn
Yara None matched
VirusTotal Search for analysis
Name 1e215292d522fe50_5fb2f5c9.emf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5FB2F5C9.emf
Size 4.9KB
Processes 2536 (WINWORD.EXE)
Type Windows Enhanced Metafile (EMF) image data version 0x10000
MD5 b91310e07bc1a0c3bd5f942d96d067e8
SHA1 0ad79a17066e24111607f20f8ac85e686da8ddb6
SHA256 1e215292d522fe5014517cb47ce66de3b55dee7d72c41d7431a16e95190ea642
CRC32 CA6CBB3E
ssdeep 48:XQNpXpWGssdBg6qjpLkwOEG6kpnydHk1a/Z:g5wGBBFq9gV+Eu
Yara None matched
VirusTotal Search for analysis
Name cedb9384b9b83c16_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2536 (WINWORD.EXE)
Type data
MD5 98b84a26fdc9866d5f2999ec9145898c
SHA1 3febbe10d6f727b41c1fb3d8e371b7e76aecac2b
SHA256 cedb9384b9b83c16aa662b680ee29652f955549102f04b6ea3278c2534dbe180
CRC32 FCC49762
ssdeep 3:yW2lWRd/dwoW6L7KtvK7+scItafPtn:y1lWioWmeVK7+Waln
Yara None matched
VirusTotal Search for analysis