Dropped Files | ZeroBOX
Name b4019912b09e1a5c_~$tracted_at_0x21e69.rtf
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$tracted_at_0x21e69.rtf
Size 162.0B
Processes 2988 (WINWORD.EXE)
Type data
MD5 48aa56a9f94eac5257cb6441207e8ded
SHA1 17bb784e3f8491d33948398f7dd933c27852b910
SHA256 b4019912b09e1a5c87741a88e7f295458a707683f2c6e6ad1a034c45c01f3469
CRC32 7F2FBFA6
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt4lwXhllFrll:y1lWnlxK7ghqNxdj
Yara None matched
VirusTotal Search for analysis
Name 84bc90364b34fcef_~wrs{faba6632-a3a3-4b99-b1ce-48c6dc37f900}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FABA6632-A3A3-4B99-B1CE-48C6DC37F900}.tmp
Size 1.5KB
Processes 2988 (WINWORD.EXE)
Type data
MD5 3dea867828b84fe6601a4d53591c7ad6
SHA1 0bc71deffc3fe8dc6d18636c9bc3ebaf29af3b26
SHA256 84bc90364b34fcef4abadf2a54499e541f25d82a7941febebe44c5861ac6df7c
CRC32 BFE7D603
ssdeep 3:H3AJlF//9lUJmT3BcPlpkt0u/n/l1lZt/laxktkbjlull5aw2/lpSaivlgl5aw9v:H3Er7adKt91/ttkb8/ow298Rmowd
Yara None matched
VirusTotal Search for analysis
Name fc3a22553b0b9c52_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2988 (WINWORD.EXE)
Type data
MD5 4a1f4ab6408b7fdf10667af524456e21
SHA1 d967089a53ebfd34144d41b4163c08adf2401df7
SHA256 fc3a22553b0b9c52f3c622d5934a5b1793b2be06c92aa7cbb1b6c988ab4739fb
CRC32 13DE48BD
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt7mk/tyXhllFrll:y1lWnlxK7ghq7T/tyxdj
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{f5d4adeb-78a1-444c-abc6-d8cc3865188a}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F5D4ADEB-78A1-444C-ABC6-D8CC3865188A}.tmp
Size 1.0KB
Processes 2988 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis