Dropped Files | ZeroBOX
Name e677929a819c9025_{bd3300f2-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BD3300F2-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 3056 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 7845eb9c578a752c6cbf0f5f66b05a11
SHA1 c3f1037526dfd7e8cf81b1cefbc227167edf888c
SHA256 e677929a819c9025bfeb6401c6ec1b9b47da217e606f48025e741047dc58b6ea
CRC32 6B3F8700
ssdeep 12:rlxAFRljrEgm8GL7KF00xrEgm8G77qsANl26abax1NlwfRbaxgRqhr1A:rYhG8pxG8mANlIoNlc58r
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 8706fcb0368cca6e_recoverystore.{bd3300f1-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BD3300F1-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 3056 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 209e3ddf375b3e84cdcea6ef68fe7802
SHA1 07c86fbcab5530524eab4b6f920fc8de003ef1f3
SHA256 8706fcb0368cca6e11609b35cf86dbeeb61276e0d969784a5e7374b11247b37f
CRC32 278D092D
ssdeep 12:rlfF2xrEg5+IaCrI0CI7eF2VITrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbax78:rqx5/fqTG5/k85jBM+NlWCuNlW6Uy
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 07b974442b53035b_bin[1].exe
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\bin[1].exe
Size 3.0MB
Processes 2224 (iexplore.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 af4268c094f2a9c6e6a85f8626b9a5c7
SHA1 7d6b6083ec9081f52517cc7952dfb0c1c416e395
SHA256 07b974442b53035b8d057a7b429c191fe71f149a698041b005ee85645a89c165
CRC32 0E7C0B09
ssdeep 49152:y2sQ8R/u6S/gPV4PW/vlLr8EdiITRf+EGg7dH1zaSo5hTk6k1qFG:yfQM/fSoPFNLQg1WT5Q
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
VirusTotal Search for analysis