Dropped Files | ZeroBOX
Name 07640085a08fa9ce_recoverystore.{bdc6d2bd-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BDC6D2BD-BA49-11ED-AC50-94DE278C3274}.dat
Size 5.0KB
Processes 2032 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 572a020dd18552665e200eaf5e98d8dc
SHA1 79c987f80078e2e5fdf1993aa198bccdbd01f75d
SHA256 07640085a08fa9ce907cde3976e25d0b26fa66565298ec624a595752cb13f206
CRC32 0691216D
ssdeep 12:rlfF2brEg5+IaCrI0CI7eF2UXTrEgmZ+IaCrI0CIc8GmRVOeMiqI771NlTqbaxKH:rqb5/fETG5/k85jBM+NlWPNlWO
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name a04ac6d98ad98931_caj67s6g.i
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\CAJ67S6G.i
Size 78.4KB
Processes 1376 (iexplore.exe)
Type ELF 32-bit LSB executable, ARM, EABI5 version 1 (GNU/Linux), statically linked, stripped
MD5 9b6c3518a91d23ed77504b5416bfb5b3
SHA1 0a2d170abbf5031566377b01431e3b82d342630a
SHA256 a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3
CRC32 44977344
ssdeep 1536:87vbq1lGAXSEYQjbChaAU2yU23M51DjZgSQAvcYkFtZTjzBht5:8D+CAXFYQChaAUk5ljnQssL
Yara
  • Hajime_botnet_IoT_malware - Hajime botnet IoT malware
  • IsELF - Executable and Linking Format executable file (Linux/Unix)
VirusTotal Search for analysis
Name 3f1a46f9c916a259_{bdc6d2be-ba49-11ed-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BDC6D2BE-BA49-11ED-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 2032 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 4439930ce34ee130f739520928bd8bef
SHA1 ec3b3d60f802b2a87858a5c0751f30712abafd0a
SHA256 3f1a46f9c916a259182564e360e5e2a5ad29122f4a18a1866447c2db03b6da39
CRC32 FAD94FA4
ssdeep 12:rlxAFMRjrEgm8GL7KF7xrEgm8GH7qsANl26abax1NlMfRbaxkdP+lQyY:r3G8LxG8qANlIoNlYXdP+lQh
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis