Dropped Files | ZeroBOX
Name 4293c1d8574dc87c_mozi[1].zip
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\Mozi[1].zip
Size 132.6KB
Processes 2252 (iexplore.exe)
Type ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
MD5 59ce0baba11893f90527fc951ac69912
SHA1 5857a7dd621c4c3ebb0b5a3bec915d409f70d39f
SHA256 4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7
CRC32 057611CE
ssdeep 3072:phNlHuBafLeBtfCzpta8xlBIOdVo3/4sxLJ10xioP:p3lOYoaja8xzx/0wsxzSi2
Yara
  • SUSP_ELF_LNX_UPX_Compressed_File - Detects a suspicious ELF binary with UPX compression
  • Mozi_botnet_IoT_malware - Mozi botnet IoT malware
  • IsELF - Executable and Linking Format executable file (Linux/Unix)
VirusTotal Search for analysis
Name 4a91b2d61a07e388_{ba334bbe-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BA334BBE-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 944 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 2a6050d350074b30a09fb8ee61b74912
SHA1 b8d1f8740955497e3dd7073812b0d634804527af
SHA256 4a91b2d61a07e3889f1f944344d65498f851d783d31175b38d7d7158df708ebe
CRC32 E9A9D9B8
ssdeep 12:rlxAFJjrEgm8GL7KFU1mxrEgm8G77qsANl26abax1NlwfRbaxaKA:reG8umxG8mANlIoNlczv
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name e9d4ca91c7f3f277_recoverystore.{ba334bbd-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BA334BBD-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 944 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 6c532f737928be31c2be4b7149126cc3
SHA1 6c3433a6af7cbede94b08f9ba18f7f5d1c9e2f0f
SHA256 e9d4ca91c7f3f277fdb5816d60e42629ad9e86f9f39bf34ea390f34d7941b2bd
CRC32 6D8D71CF
ssdeep 12:rlfF2PrEg5+IaCrI0CI7eF2vTrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbax8nq:rqP5/fvTG5/k85jBM+NlWrnrNlWX5X
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis