Dropped Files | ZeroBOX
Name ebda567a4cc36d51_{bdaa3686-ba49-11ed-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{BDAA3686-BA49-11ED-948E-94DE278C3274}.dat
Size 4.0KB
Processes 2616 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 d73c01416588575f027373aec3a9a6ba
SHA1 a299c80d7294dbe8e432bb55f1a85327c5e017c6
SHA256 ebda567a4cc36d51b2b25c8a46cf84f0ccf55d1d93b83871d887e52c4281b416
CRC32 10948509
ssdeep 12:rl0YmGFmQrEgmft7KFnrEgmft7qgONlPBbaxdj1ljohNlPBbaxdj1ljo:rvGAGrONlJ6QNlJ6
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name dc30e6500ebcf937_x-8.6-[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\x-8.6-[1].htm
Size 83.8KB
Processes 2696 (iexplore.exe)
Type ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
MD5 83510ad1397bd08f248bbee8464e124c
SHA1 dd3e41549f10f895c188bc33667a8f2f332f8c0b
SHA256 dc30e6500ebcf937a237d027acdd40c2dd68741b4f40a9523196ee82eb13e3c3
CRC32 6D5CE740
ssdeep 1536:eB7cH1LhKlBqIKVhuzdPQq0aJP9sWtjG7ew3nILWODPPmoIYuOVje+ZNne:eRMhKlcluzdPv0o+QK7eknIL1DHmrYur
Yara
  • IsELF - Executable and Linking Format executable file (Linux/Unix)
VirusTotal Search for analysis
Name 68d9e9aaf809a246_recoverystore.{bdaa3685-ba49-11ed-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{BDAA3685-BA49-11ED-948E-94DE278C3274}.dat
Size 4.5KB
Processes 2616 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 05e70473a46d890bc41406ad70eb9a8a
SHA1 c42fbefa98e7d2f64b079543306743dda6bb8552
SHA256 68d9e9aaf809a246f679abf4ab9f17fd0fbf926765b6666021403d8a7cd158ac
CRC32 D6AD1C00
ssdeep 12:rlfF2QrEg5+IaCrI0F7+F2mvrEg5+IaCrI0F7ugQNlTqbaxoANlTqbaxIg:rqQ5/1Y5/3QNlWwNlW
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis