Dropped Files | ZeroBOX
Name 4afe78ea38d83d6f_~wrs{53591c86-608b-43eb-88e5-ab7fb32104d9}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{53591C86-608B-43EB-88E5-AB7FB32104D9}.tmp
Size 1.5KB
Processes 2596 (WINWORD.EXE)
Type data
MD5 350a5324dca756feae0bd9e808944061
SHA1 54c348a1e91769766281ac620c6bb6f4985ecfb1
SHA256 4afe78ea38d83d6fc99b088d68a8d67ff83ce6bba94daaca1e98bf98b5829b24
CRC32 6579B5FA
ssdeep 6:IiiiiiiiiiE/bYflo3dc8++ZYSySkssqA1+tKHEU9n:S/XtG+aSpk1j1+tKHEU9
Yara None matched
VirusTotal Search for analysis
Name 6ab29183111ccec0_d550c343.wmf
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D550C343.wmf
Size 98.0B
Processes 2596 (WINWORD.EXE)
Type Targa image data - Map - RLE 7 x 65536 x 0 "\005"
MD5 36a768d4b7d523b07b9eab23a3eb5962
SHA1 9f4d04e95430b4985923ad1d848034749c446898
SHA256 6ab29183111ccec00711075daaa18673279d998916456e16507073526e1e8be7
CRC32 9EC88728
ssdeep 3:VmUtKlg/log/lz4+5Fv/Ollxg/lwPgBC/h/l/n:Mc+gtogt0+54/mtwPgk5t/n
Yara None matched
VirusTotal Search for analysis
Name 2e15a577cabbb299_~$tracted_at_0x0.rtf
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$tracted_at_0x0.rtf
Size 162.0B
Processes 2596 (WINWORD.EXE)
Type data
MD5 25bce7a2cf4309e2ea268b166299bad5
SHA1 be9c10ecf2f578823ef2b837cd4d50c21d24f09e
SHA256 2e15a577cabbb2999dddd1ff6560ad313ac272093a39a9fd4ccbf774ff1e3af7
CRC32 47DEC0A0
ssdeep 3:yW2lWRdvL7YMlbK7lhZhnaltl:y1lWnlxK7Rhna
Yara None matched
VirusTotal Search for analysis
Name 818ac9d3621dd802_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2596 (WINWORD.EXE)
Type data
MD5 ee32490f318ff4e444547a5f83870e80
SHA1 09f2ae32c5f293e2ad8ab9eef34b353b0f27362c
SHA256 818ac9d3621dd80293562e5769e503579c6e9fe996e67c6145f7984c532d2f9b
CRC32 1A78502A
ssdeep 3:yW2lWRdvL7YMlbK7lznXl:y1lWnlxK7
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{bfb6cb33-d795-45a3-83f9-e6d7f4190124}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BFB6CB33-D795-45A3-83F9-E6D7F4190124}.tmp
Size 1.0KB
Processes 2596 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 9cd21abbd7183795_~wrs{e8a7ede8-5313-47fe-85b4-f656c24827bd}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E8A7EDE8-5313-47FE-85B4-F656C24827BD}.tmp
Size 27.7KB
Processes 2596 (WINWORD.EXE)
Type data
MD5 1bc592372adc6e408b7b5894319eb85e
SHA1 17443d1b459c2bc87874bb59633eb9b709115069
SHA256 9cd21abbd718379592088f5f46167b4a41d555b2f178eea81b5af163a4e2b240
CRC32 B80AD9DA
ssdeep 384:BLB0PezsGMVSOplyQMA0tA5EYZxzDRCkO:MWfWuAHZxvRCkO
Yara None matched
VirusTotal Search for analysis