Dropped Files | ZeroBOX
Name 77e89102732a7359_{bd3eecb4-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BD3EECB4-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 1884 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 94b59f04cd76ae6f015d4b680e9141fe
SHA1 45d9e52a4a3b95576318bfbe81f2f43bb338b51a
SHA256 77e89102732a735960b411d0937263315dd32f3da4e129f03e88e97cd5a844e7
CRC32 4CFFE0DC
ssdeep 12:rlxAF4ljrEgm8GL7KFsLDrEgm8Gn7qsLNl26abax1NlsfRbaxoxkI6udcFlZl:r1hG8CG8KLNlIoNl4iedchl
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 1f973d307ac67667_.win32[1].exe
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\.win32[1].exe
Size 192.5KB
Processes 2264 (iexplore.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8c3c941efdc044a57a89a4163918acb2
SHA1 1682b1832b65cb2a6ee775a5e4f2c024058acdb7
SHA256 1f973d307ac6766796e6abcaf1c71b8e506859ebf82d9d176fafc564383b2e20
CRC32 D78A9B8F
ssdeep 3072:25mJMInhU7WuCr4VT+3HmDqg4Aa2oAnq5mnzL/:3PhCWuCryT+Wm8a5QP
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis
Name 6b02c7914a695e7f_recoverystore.{bd3eecb3-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BD3EECB3-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 1884 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 ad664686a0dcd8f30a5701635e7df0dd
SHA1 e6f37bee01574c3645d14032f018d080469def76
SHA256 6b02c7914a695e7f81b21113dcd6458a336d299d6df9fde2b8960f55b458d077
CRC32 3E552491
ssdeep 12:rlfF2CrEg5+IaCrI0CI7eF2YliTrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbaxa:rqC5/fYliTG5/k85jBM+NlWzNlWq
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis