Dropped Files | ZeroBOX
Name 6bb0bb56497a55a6_~$f###############################fff.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$F###############################fff.doc
Size 162.0B
Processes 2548 (WINWORD.EXE)
Type data
MD5 92ffa8482ea5cfb508adb4c85404c3a9
SHA1 2b51e6c4fba3478827386e0de83a560a2f00d94a
SHA256 6bb0bb56497a55a61bed90bd748a17589dbad5903a12450d06d9e4c476d55447
CRC32 3E316DE0
ssdeep 3:yW2lWRdvL7YMlbK7lhZm3wZvtl:y1lWnlxK7RmgR
Yara None matched
VirusTotal Search for analysis
Name 76890cc67b5a4962_~wrs{6cf27a32-2df8-4904-a0d8-8568c704ecc4}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6CF27A32-2DF8-4904-A0D8-8568C704ECC4}.tmp
Size 13.5KB
Processes 2548 (WINWORD.EXE)
Type data
MD5 652336738c916cc15f831b0680fcac38
SHA1 223c5181b0a7e74b85ba9b2a5b1ece203d440a4d
SHA256 76890cc67b5a49628c263050bdd2012713f45090dd9e61cbfc4d3834853a1705
CRC32 6F58D756
ssdeep 384:3gQQXrmrGX9DHxFXH2TwZ2RH6+1pzt/LWgP:QQQXrjX9DHxF32sG6ozt/aY
Yara None matched
VirusTotal Search for analysis
Name 818ac9d3621dd802_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2548 (WINWORD.EXE)
Type data
MD5 ee32490f318ff4e444547a5f83870e80
SHA1 09f2ae32c5f293e2ad8ab9eef34b353b0f27362c
SHA256 818ac9d3621dd80293562e5769e503579c6e9fe996e67c6145f7984c532d2f9b
CRC32 1A78502A
ssdeep 3:yW2lWRdvL7YMlbK7lznXl:y1lWnlxK7
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{bfb6cb33-d795-45a3-83f9-e6d7f4190124}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BFB6CB33-D795-45A3-83F9-E6D7F4190124}.tmp
Size 1.0KB
Processes 2548 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis