Dropped Files | ZeroBOX
Name 9104375d05036cc1_{5bb6d614-320f-11ec-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{5BB6D614-320F-11EC-BDE1-94DE278C3274}.dat
Size 4.5KB
Processes 2076 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 92958d8c99a89be2937320185e905fdb
SHA1 01a268d8d33c9deb35b43c81322aa8271c92f42e
SHA256 9104375d05036cc1e1d53ec92bb37b9b53fddda9b25ef18df344dd326d0b0c38
CRC32 C23D7EDF
ssdeep 12:rlxAFJ7rEgm8GL7KF+9CxrEgm8GP7qsANl26abax1NlkfRbaxQUO:rSG8gCxG8CANlIoNlAY
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name a61c0005479e5fc7_recoverystore.{5bb6d613-320f-11ec-bde1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{5BB6D613-320F-11EC-BDE1-94DE278C3274}.dat
Size 5.0KB
Processes 2076 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 a20f703da397c6ac11961c4256e3d624
SHA1 d00778d0da5b7032c34a153ac194b4ba73287e96
SHA256 a61c0005479e5fc77d1ab4776191d0d3e87740b88748ed8e44ae4187466b4a98
CRC32 37B99430
ssdeep 12:rlfF2brEg5+IaCrI0CI7eF2mETrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbaxYH:rqb5/fZTG5/k85jBM+NlWTNlW
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 2e8b750d6a8b14cf_porcal4[1].exe
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\Porcal4[1].exe
Size 7.0MB
Processes 2888 (iexplore.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 27828516c38739491a3d20e733850aa5
SHA1 823a9262cfea211e5ca6bb211c185661e3a5f33e
SHA256 2e8b750d6a8b14cff802d89ba55447014d63ffd4c5c711f36e900d6a9aff66df
CRC32 A1C09214
ssdeep 196608:QL6ocnTV67JnbhUtuvbPORiE9Z1v8KMf4UUIHSMi:a6JnTE7Jn1UGW7v8HQsi
Yara
  • Antivirus - Contains references to security software
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis