Dropped Files | ZeroBOX
Name 1925c6f4081e9d1c_~$1.rtf
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$1.rtf
Size 162.0B
Processes 2552 (WINWORD.EXE)
Type data
MD5 b81339d55acba80419fa70672fc5c4a1
SHA1 969db8073f80702505050e21992c2af88e0bd096
SHA256 1925c6f4081e9d1c76be99d3c35b269ffc5f9eb79efd5fe1b509e1e6100d94a9
CRC32 FC3684B7
ssdeep 3:yW2lWRdgwoW6L7RJlXK7BCtcItPrY9XG:y1lWJoWm1JVK74JPc9W
Yara None matched
VirusTotal Search for analysis
Name 3f4db508e0b8b147_~wrs{32fc0552-38e9-4aba-bec2-a0a377a9e2aa}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{32FC0552-38E9-4ABA-BEC2-A0A377A9E2AA}.tmp
Size 1.5KB
Processes 2552 (WINWORD.EXE)
Type data
MD5 885162f35522daea816c022d6d3683b4
SHA1 37ce7c7248ea553829432ddf0cc8ee64f7be258e
SHA256 3f4db508e0b8b147747df25d5dadba0de4dc82460a70be6559fe8be59a514b1d
CRC32 7E68CF9D
ssdeep 6:IiiiiiiiiiI4/9+Qc8++lPkalT4Mu8lPloBl/r:W49+QG+3/a
Yara None matched
VirusTotal Search for analysis
Name 50161b54fe8ea5b4_~wrs{b283718f-d789-43b6-af08-a0ab2e6f5ae3}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B283718F-D789-43B6-AF08-A0AB2E6F5AE3}.tmp
Size 6.3KB
Processes 2552 (WINWORD.EXE)
Type data
MD5 4a0d9131227ea389a736f6350dd3e1f0
SHA1 ce28f38ede586aabbc137007dfe9b20ddb719c4a
SHA256 50161b54fe8ea5b4ad0d9fe927f2d41d0cb31257cf4032253696fef332cf5d4a
CRC32 21E83EDD
ssdeep 96:F+hwDrnJT/xgz1AnSnlltuqO2jVfVjWbEaKFKDZqwm7maeOA:F+hwDrJT/WFuD2j7jUKFkZ7ymaPA
Yara None matched
VirusTotal Search for analysis
Name 406836ff9ff4e730_e8de59b0.wmf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E8DE59B0.wmf
Size 314.0B
Processes 2552 (WINWORD.EXE)
Type Targa image data - Map - RLE 28 x 65536 x 0 +2 "\005"
MD5 228531bfea0dc5f27a11c0c0a98d03d1
SHA1 144a036d44614fd33d9340d7e5400c84cde6d374
SHA256 406836ff9ff4e7303f6cbc8ff2c79c1b1767978732f826cf37c50ee8b5e307df
CRC32 3DA9C2A9
ssdeep 6:M49Ot2oto90ogtwRozWE4S/GbVJGpQuQSTzvkIsVlE49OXC1ynuKbg/p8V6klct:M49DeFObDGfHTzvNMeGOXCYnhbg06s0
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{105623a8-e014-4de1-bd24-aae27834c80b}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{105623A8-E014-4DE1-BD24-AAE27834C80B}.tmp
Size 1.0KB
Processes 2552 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 73d7ba7665dc9e04_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2552 (WINWORD.EXE)
Type data
MD5 0cb57804ea4c69f75578e6b1b2ccc75f
SHA1 ee60cc9af57f5e4ae59a08cb04f25e40e5969216
SHA256 73d7ba7665dc9e0494efa4bd4eb8f327d6ce32396d303d45a84580cff727aa17
CRC32 BEBA072B
ssdeep 3:yW2lWRdgwoW6L7RJlXK7BCtcItPrYvW/:y1lWJoWm1JVK74JPcu/
Yara None matched
VirusTotal Search for analysis