Dropped Files | ZeroBOX
Name c043e5aef5fcf05f_recoverystore.{bd297789-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BD297789-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 204 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 44a3688f7e7523e550abbea6fb6414c9
SHA1 46b88424f32de6e88e6cac268f8cbef9af2cf0e5
SHA256 c043e5aef5fcf05ff6b3eb8105c4fee04df7aaa5c7b04a31a72db5e2120f1e5c
CRC32 7571F672
ssdeep 12:rlfF23rEg5+IaCrI0CI7eF2fcTrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbaxa/:rq35/ffcTG5/k85jBM+NlWHNlWy
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 2db7fd3c9c3c4b67_msvcp140[1].dll
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\msvcp140[1].dll
Size 438.8KB
Processes 1188 (iexplore.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 1fb93933fd087215a3c7b0800e6bb703
SHA1 a78232c352ed06cedd7ca5cd5cb60e61ef8d86fb
SHA256 2db7fd3c9c3c4b67f2d50a5a50e8c69154dc859780dd487c28a4e6ed1af90d01
CRC32 946682DF
ssdeep 12288:UEPa9C9VbL+3Omy5CvyOvzeOKaqhUgiW6QR7t5s03Ooc8dHkC2esGgW8g:UEPa90Vbky5CvyUeOKg03Ooc8dHkC2ed
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
VirusTotal Search for analysis
Name 429a7fbf6e798749_{bd29778a-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BD29778A-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 204 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 beabdc8f8e47d1dd9271024a561ae589
SHA1 ad1458f7a4d203fcd614afb34d63ae591e4437cc
SHA256 429a7fbf6e7987498da1bf08d3fad4cc9dbe06fad70ad2cca33df9c42254c91f
CRC32 38B4EDEE
ssdeep 12:rlxAFljrEgm8GL7KFlrEgm8GM7qsbNl26abax1Nl8fRbaxqZ1L6b+MWl:ruG8VG8rbNlIoNloI
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis