Dropped Files | ZeroBOX
Name cc3bd53d7288359c_loader[1].dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\loader[1].dat
Size 5.3MB
Processes 2788 (iexplore.exe)
Type PE32+ executable (console) x86-64, for MS Windows
MD5 9275ae35733730eda1da5e7e29bdf8db
SHA1 a279a1f05e847941a9b4a84eb3b734d1921af063
SHA256 cc3bd53d7288359c8a25bb27b44d324b679b0a61466bf0fa79991d5639eb53ee
CRC32 19126FFA
ssdeep 98304:7KrF3sCrgxhqVvTCxW1WnH3hSE23Yp+T3O2ptNvmHRJZ07NQJDZpk:7KrF3Tr2IVGMql23X3jptNvmHLZ00Xk
Yara
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
VirusTotal Search for analysis
Name c2198cae4ee317f9_recoverystore.{bd1664b9-ba49-11ed-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BD1664B9-BA49-11ED-948E-94DE278C3274}.dat
Size 5.0KB
Processes 2708 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 13dcab116558dc955d1bd43c5735b5c8
SHA1 ee647453b4c77d468dd37d1d4e925a8ab1e7a183
SHA256 c2198cae4ee317f9862902034a4b380e8dbc50eddb6f0389a1fbd7d7f92a3576
CRC32 11A09E53
ssdeep 12:rlfF2UlPrEg5+IaCrI0CI7eF2Ul8TrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqb1:rqUl5/fUmTG5/k85jBM+NlWo6NlWoz
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 62295b05220a4c94_{bd1664ba-ba49-11ed-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BD1664BA-BA49-11ED-948E-94DE278C3274}.dat
Size 4.5KB
Processes 2708 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 99f652c196f6a13c3233d07b6d331654
SHA1 e50b6d4f9df7216e28b5db8b39c556b2e3d88b12
SHA256 62295b05220a4c946c981d51a33f9ffbc9dc2035270a4138c7f0a4b20cb39599
CRC32 169FEC22
ssdeep 12:rlxAFRljrEgm8GL7KF0fDrEgm8Gn7qsLNl26abax1NlsfRbax0cb:rYhG8MG8KLNlIoNl4ncb
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis