Dropped Files | ZeroBOX
Name 4826c0d860af884d_~wrs{be4cdeb6-8279-41d0-b946-07cb50716005}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BE4CDEB6-8279-41D0-B946-07CB50716005}.tmp
Size 1.0KB
Processes 880 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 28b7564b29d14151_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 880 (WINWORD.EXE)
Type data
MD5 22ced4be1be3f1686a0d09b3236341fd
SHA1 4bf9a9f508b9ff97597d28ae74f998f665cc837d
SHA256 28b7564b29d14151576a4176b753cc7b8d8c2af7ad5fbea98ab89908402c559e
CRC32 3CAF800F
ssdeep 3:yW2lWRdfl3/W6L7G9vZJK7SI9puIt6fAG:y1lW7lvWmC9vK7SI9rnG
Yara None matched
VirusTotal Search for analysis
Name 1c0dfb26f9d5d660_~wrs{c4e2f51f-da36-49fc-b9d5-108ccc5c54a4}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C4E2F51F-DA36-49FC-B9D5-108CCC5C54A4}.tmp
Size 16.0B
Processes 880 (WINWORD.EXE)
Type data
MD5 c59d751a76e5542d4dbddf54acd93278
SHA1 73f3b06ed2a41a70d699c9e5d960c1cc09da5c43
SHA256 1c0dfb26f9d5d660fc5516bf996d10a16e125f0ee44ab2586f9bb53d8f402546
CRC32 96C5DF39
ssdeep 3:XlkUn:XHn
Yara None matched
VirusTotal Search for analysis
Name d59ceaa2b1f90370_~$tracted_at_0x1eec6.rtf
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$tracted_at_0x1eec6.rtf
Size 162.0B
Processes 880 (WINWORD.EXE)
Type data
MD5 359187cfdb557b4dc000ba6f83368664
SHA1 9f58cde66c487113fbed0f8a628072b2c029f01d
SHA256 d59ceaa2b1f9037046f41a46c9b91e7be2e4dd9baf9eb5ec74b61fe1b5a07ae5
CRC32 BC3D1006
ssdeep 3:yW2lWRdfl3/W6L7G9vZJK7SI9puIt6fWKil:y1lW7lvWmC9vK7SI9rpfl
Yara None matched
VirusTotal Search for analysis