Dropped Files | ZeroBOX
Name 858ffd1a8f2ae4ee_ark[1].dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\ark[1].dat
Size 1.1MB
Processes 1188 (iexplore.exe)
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 cc074e25e77d6a797edffea9cfc92662
SHA1 5e8700a4150edee7eddc6ab1b42930793f99b779
SHA256 858ffd1a8f2ae4eee47beb1dbf1b7ae25f4d1e6410179dd3d586ed879410b6f4
CRC32 BC395139
ssdeep 24576:+I17HgQXsUijszaUwpagBFFikcSXZfR/Y92XbxKFD8/aOJPb:+UEQsbQzaPagBFjZZ/dW87l
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
VirusTotal Search for analysis
Name ad61704bae7d5566_{bd37c5a6-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BD37C5A6-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 2144 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 31780244ebe60b75233f8b7e61fc6fe3
SHA1 8606665ae9af55185cdc7a5e7a3d01e0fa99e61b
SHA256 ad61704bae7d5566b0cdb34a2a7596d16b22859f3266dc6bc429253147deb3d1
CRC32 ED740693
ssdeep 12:rlxAF4ljrEgm8GL7KFsLDrEgm8Gr7qsLNl26abax1NlgfRbax5GbeAT:r1hG8CG8WLNlIoNlsYGbeA
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 2c5719bbe23fc192_recoverystore.{bd37c5a5-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BD37C5A5-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 2144 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 897dcd2414966c4d11f18bcc47590266
SHA1 d58cdec1e1d3cc7cf8b2fa04463733f27ca1f6cc
SHA256 2c5719bbe23fc192f29e39b484627a33ffc87e68ad65e42bf589bfb555b64e03
CRC32 98F49D4F
ssdeep 12:rlfF2uPrEg5+IaCrI0CI7eF2pTrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbaxmL:rqk5/fpTG5/k85jBM+NlWXNlWa
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis