Dropped Files | ZeroBOX
Name 41e3f69ecc09290e_httperrorpagesscripts[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\httpErrorPagesScripts[1]
Size 5.4KB
Processes 2472 (iexplore.exe)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 dea81ac0a7951fb7c6cae182e5b19524
SHA1 8022d0b818a0aea1af61346d86e6c374737bc95a
SHA256 41e3f69ecc09290ebc49be16d2415036ddb2f7a4b868eef4091d0b5a301762fe
CRC32 5E7F4A18
ssdeep 96:JCc1g1V1riA1CiOcitXred1cILqcpOnZ1g1V1OWnvvqt:xmjriGCiOciwd1BPOPmjOWnvC
Yara None matched
VirusTotal Search for analysis
Name 1d8e5fd3c1fd384c_bullet[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\bullet[1]
Size 447.0B
Processes 2472 (iexplore.exe)
Type PNG image data, 15 x 15, 8-bit colormap, non-interlaced
MD5 26f971d87ca00e23bd2d064524aef838
SHA1 7440beff2f4f8fabc9315608a13bf26cabad27d9
SHA256 1d8e5fd3c1fd384c0a7507e7283c7fe8f65015e521b84569132a7eabedc9d41d
CRC32 614F6AFF
ssdeep 12:6v/71Cyt/JNTWxGdr+kZDWO7+4dKIv0b1GKuxu+R:/yBJNTqsSk9BTwE05su+R
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 89097f85954c992a_eywcet97lv2u[1].cab
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\EYWCET97LV2U[1].cab
Size 281.1KB
Processes 2472 (iexplore.exe)
Type Microsoft Cabinet archive data, 287893 bytes, 1 file
MD5 0785352502e5180153c079fa6cbe1ada
SHA1 94cabf17018ce27745e0effb5346c4b8afb71e69
SHA256 89097f85954c992ab27572d63daf119b87bb75cd3785ffcc2b5615988a9a398b
CRC32 391DA56E
ssdeep 6144:Ht289kjPMvG/Ob5606j6EJ7jnjF6LHaEaIskUTlje:N+jPMvr6+kjFqHaEdkl6
Yara
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 919c1ae29e106ace_{3bd0b3a6-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3BD0B3A6-434D-11EC-98E1-94DE278C3274}.dat
Size 4.0KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 a615c9d49e65b1e5af0f4e10f1e7d87d
SHA1 0c775599239485ed4d69e7c4e35123d8c67d21b9
SHA256 919c1ae29e106aced27f7e7d638aa8bd663251c4c4b2ecd25f0a005a9638262e
CRC32 6744E929
ssdeep 12:rlxAF2rEgm8GL76FHrEgm8GL7qjNlO+baxjNlO+baxG:rFG8nG81NlxWNlxH
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 1059dfed5e715546_{3bd0b3a7-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3BD0B3A7-434D-11EC-98E1-94DE278C3274}.dat
Size 4.5KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 1e3ca95aa1911df0831786affe068a0a
SHA1 9c89e9d137049885edefd107b1304184a1e0266f
SHA256 1059dfed5e715546c9aa45553c7f3e8888e7c65463eb3a6359caaa60809f87cd
CRC32 7DBA1C42
ssdeep 48:rO4Xpe+Tk3Gufpn+Tk3GuTrBNBbBotWz+:b8G8VGSbNGE
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 0d40196d1367fccb_recoverystore.{3bd0b3a1-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{3BD0B3A1-434D-11EC-98E1-94DE278C3274}.dat
Size 6.0KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 8d35e1d56c5360d2b90b008c23125d4a
SHA1 d6808b6f8d98f2c9c75eccc5fcd6b1d4bd841153
SHA256 0d40196d1367fccbddacea32951de4ebcf7f81ed8521184a4d82f6a29f0bb5fc
CRC32 76EB42A3
ssdeep 12:rlEFDrEgmZ+IaCrSNc8GbDMFYbrEgmZ+IaCrSNc8G9bPYDSyMeMiqqzLSyMeMiqj:rmG5/V8ONbG5/V8ZHMsMCNlWifNlWi0
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 18ae9d76727c45a5_errorpagestrings[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\errorPageStrings[1]
Size 2.0KB
Processes 2668 (iexplore.exe)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 867666e4f73a755e0c135ce4e90de230
SHA1 a7b1d23f1d2ef9de6b149925147d44076e17fcb3
SHA256 18ae9d76727c45a577073bfc8d8914fedccfcf43b5afeeaf26737448712334e3
CRC32 D8C63FA6
ssdeep 48:z9UUiqu6xl8W22751dwvRHERyRyntQRXP6KtU5SwVze/6e/+Ng7FU50U5ZF0:z9UUiqRxqH211CvRHERyRyntQRXP6C8o
Yara None matched
VirusTotal Search for analysis
Name e5806fa4b2e0ef0c_{3bd0b3a4-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3BD0B3A4-434D-11EC-98E1-94DE278C3274}.dat
Size 4.0KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 b40c5dfcb3bb3d26bd7237c2ee1f9887
SHA1 eae95ec8f8d221f2d4bad27294363d9b3ca23546
SHA256 e5806fa4b2e0ef0c12f69bd488fe50df0c16f3b0d8b3403209e28a4ea88ef578
CRC32 5E1B3730
ssdeep 12:rlxAFErEgm8GL76FThrEgm8GL7qjNlO+baxKVNlO+baxH:r7G8zhG81Nlx7VNlxG
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 8d018639281b33da_errorpagetemplate[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\ErrorPageTemplate[1]
Size 2.1KB
Processes 2668 (iexplore.exe)
Type UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 f4fe1cb77e758e1ba56b8a8ec20417c5
SHA1 f4eda06901edb98633a686b11d02f4925f827bf0
SHA256 8d018639281b33da8eb3ce0b21d11e1d414e59024c3689f92be8904eb5779b5f
CRC32 E6FF242A
ssdeep 24:5+j5xU5k5N0ndgvoyeP0yyiyQCDr3nowMVworDtX3orKxWxDnCMA0da+hieyuSQK:5Q5K5k5pvFehWrrarrZIrHd3FIQfOS6
Yara None matched
VirusTotal Search for analysis
Name aa50a4a6a101c48a_unknownprotocol[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\unknownprotocol[1]
Size 6.7KB
Processes 2668 (iexplore.exe)
Type HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
MD5 378016e69253a0565eb7266fd032879e
SHA1 f6f59912a1c3e0f528fa48501be24c2868468269
SHA256 aa50a4a6a101c48addb7555f0c4ccc3eae62ffd49d2a47fb4b10c3efdfecabea
CRC32 6C2BC778
ssdeep 96:uODYifFSOpjE1rKHWFuIgtfX36a7hj7waw:uOdcOpA1r0IWaqN7wZ
Yara None matched
VirusTotal Search for analysis
Name 1471693be91e53c2_background_gradient[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\background_gradient[1]
Size 453.0B
Processes 2472 (iexplore.exe)
Type JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
MD5 20f0110ed5e4e0d5384a496e4880139b
SHA1 51f5fc61d8bf19100df0f8aadaa57fcd9c086255
SHA256 1471693be91e53c2640fe7baeecbc624530b088444222d93f2815dfce1865d5b
CRC32 C2D0CE77
ssdeep 6:3llVuiPjlXJYhg5suRd8PImMo23C/kHrJ8yA/NIeYoWg78C/vTFvbKLAh3:V/XPYhiPRd8j7+9LoIrobtHTdbKi
Yara
  • JPEG_Format_Zero - JPEG Format
VirusTotal Search for analysis
Name ac5e30375ea1a6da_{3bd0b3a2-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3BD0B3A2-434D-11EC-98E1-94DE278C3274}.dat
Size 4.5KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 5158e2f5cac7a6b94b7abff01c763137
SHA1 6919505c610b254d061623baae2277de832b3418
SHA256 ac5e30375ea1a6da038253b6cb08af5d9aeace77c916e403ecc93dc9a2de2e55
CRC32 B6A3733D
ssdeep 12:rl0ZGFkorEgmfAB76FPrEgmfN7qgONl08hbaxl/Q1V3iLNl/9baxwKtHaK+w63i:rHGjGLONl0Aj8NlF2lh+
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 51129c6c98a82ea4_info_48[1]
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\info_48[1]
Size 4.0KB
Processes 2472 (iexplore.exe)
Type PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
MD5 5565250fcc163aa3a79f0b746416ce69
SHA1 b97cc66471fcdee07d0ee36c7fb03f342c231f8f
SHA256 51129c6c98a82ea491f89857c31146ecec14c4af184517450a7a20c699c84859
CRC32 C6BA4B0B
ssdeep 96:WNTJL8szf79M8FUjE39KJoUUuJPnvmKacs6Uq7qDMj1XPL:WNrzFoQSJPnvzs6rL
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 2ed9457e44c4d3d0_{3bd0b3a5-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3BD0B3A5-434D-11EC-98E1-94DE278C3274}.dat
Size 6.5KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 d4be93a6f0e2f35bfaf0d1be4092390c
SHA1 e2ef1745303461118250a8c051d629e0a96bb369
SHA256 2ed9457e44c4d3d0ebd32fe68ae55156b25dbb33dcc5b2dcf0b297e87f88158e
CRC32 C2A3F8BC
ssdeep 48:rKGsH9pH+Tk3GuTrBNBbBotWz+3uTQyvDv7VvgyvLdTJBNBbBotWz+TTH:Kb1GSbNGE0kLr1JbNGE4
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 4d3262747ab025dc_{441f6536-434d-11ec-98e1-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{441F6536-434D-11EC-98E1-94DE278C3274}.dat
Size 3.5KB
Processes 2364 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 47346591afc9d1950fa74d82b23a4c40
SHA1 7906642037be206afa4afcc55497d83206edbcba
SHA256 4d3262747ab025dc108a9b6f9e0c9a5fa16ccc9cc79f027ac5d85bfed56fdc77
CRC32 16F2CC3E
ssdeep 6:rlaIlzRs+CFQXCB9Xh9Xh9X9Z+CFfW93nFrEgm8mXJ9Xh9XRCl0yfllCglp:rlR2FQCb77/F+rrEgm8Gz7qPNlCgb
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis