Dropped Files | ZeroBOX
Name a1fa622b47a529e1_702031fb.emf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\702031FB.emf
Size 4.9KB
Processes 1108 (WINWORD.EXE)
Type Windows Enhanced Metafile (EMF) image data version 0x10000
MD5 bf2393dfe4576945d1f26d3595c5ef9f
SHA1 f9abbbcf4bad106e4f5c039082257357f4c28aef
SHA256 a1fa622b47a529e1064458aa0decd0c1ebc16efb621511c8cba545036ffeb00e
CRC32 71C49B27
ssdeep 24:Y6cOaHN87k0sqFjsdB3g6G7OdE5qOppcWfswKnZFwG6uvX51m0KZdHk1a/Uo:XQNikssdBg6qjpLkwOEG6kpnydHk1a/Z
Yara None matched
VirusTotal Search for analysis
Name 49b1e8ffc49a1613_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 1108 (WINWORD.EXE)
Type data
MD5 933324794f30cf44634f259ab044fc4d
SHA1 92d9a29a0654e6c0d2a081e9fdfe27bf12709355
SHA256 49b1e8ffc49a1613e3d600e0b9fac17a15da396952d59d13cd4d1e7b197dc134
CRC32 AA877618
ssdeep 3:yW2lWRdvL7YMlbK7lnn/l:y1lWnlxK7
Yara None matched
VirusTotal Search for analysis
Name 675371536bb556a9_~$19_7169909343268.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$19_7169909343268.doc
Size 162.0B
Processes 1108 (WINWORD.EXE)
Type data
MD5 673c86586d78f392ae0d3d06d744f69f
SHA1 b5b924a205d2591cd56c6cd064c8b637f42620f3
SHA256 675371536bb556a92f08ff841d6669c28718e02aec31ac58ac4a79886a641f1b
CRC32 90CE6C2E
ssdeep 3:yW2lWRdvL7YMlbK7lZtnNWGkt/l:y1lWnlxK73tnEGw
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{49f0111d-868e-4fa0-b0e0-7477ab9be03f}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{49F0111D-868E-4FA0-B0E0-7477AB9BE03F}.tmp
Size 1.0KB
Processes 1108 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis