Dropped Files | ZeroBOX
Name 15f122e0d6a05e9f_~wrs{11e45107-a783-49e6-945c-3c37c75ae2e9}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{11E45107-A783-49E6-945C-3C37C75AE2E9}.tmp
Size 15.0KB
Processes 2988 (WINWORD.EXE)
Type data
MD5 0ac1239944c8a5d5b969e80d6a6ff60c
SHA1 2bbcd1e1bb6ade6c9d7a6485039e8af1f83c8bd5
SHA256 15f122e0d6a05e9fbd6ac6a9f071116942908fce163b09c9ab83e46d1429d582
CRC32 010FC16B
ssdeep 384:rXRTilckLSfavzxqsn+RZou1Bf3e5RCEPHOFvpRf:DRTiC3mxqsnmZlBGKEPHO1f
Yara None matched
VirusTotal Search for analysis
Name 93ead71d5e0e8e61_~$############################.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$############################.doc
Size 162.0B
Processes 2988 (WINWORD.EXE)
Type data
MD5 2dac4e438d21245745021142e8277f54
SHA1 0147dc702f127d089018926ae2248cd41457c630
SHA256 93ead71d5e0e8e613627d51be4445f51b0705ca3f1557031698fb37cfd19cb06
CRC32 C6E47FB1
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVtOl4Xhn:y1lWnlxK7ghqqFK4xn
Yara None matched
VirusTotal Search for analysis
Name d516a371b6fc0a52_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2988 (WINWORD.EXE)
Type data
MD5 56a4532b2fc2cf6fd4ec62a29758d231
SHA1 60f68bd8ac5b3f7290daa236bebd5f9c0f1510fd
SHA256 d516a371b6fc0a5270a1323f271bc2a36bc34f9cf06c783a642020c0da8948c3
CRC32 E93E4529
ssdeep 3:yW2lWRdvL7YMlbK7g7lxIt50iSjlVtNmk/tyXhn:y1lWnlxK7ghqqFNT/tyxn
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{3c93c974-7c9a-4dba-851c-3abf24280a90}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3C93C974-7C9A-4DBA-851C-3ABF24280A90}.tmp
Size 1.0KB
Processes 2988 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis