Dropped Files | ZeroBOX
Name 0472e8dafd6c34e2_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2556 (WINWORD.EXE)
Type data
MD5 abd90e16daf2d0aa0ca45442b2cbf3e1
SHA1 ded3d7f182bae5091a2e036691538ecfd0caedf8
SHA256 0472e8dafd6c34e21419c37d200fa66584ffdbe2cbc7d678c87c2a7a366ce631
CRC32 61C359B7
ssdeep 3:yW2lWRdvL7YMlbK7le:y1lWnlxK7o
Yara None matched
VirusTotal Search for analysis
Name 913e71acba46ee36_~$vernment policy updated 2023.docx
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$vernment policy Updated 2023.docx
Size 162.0B
Processes 2556 (WINWORD.EXE)
Type data
MD5 5d02dab6ed8ee04abf443d96df165426
SHA1 ec38bc2b5bd46b6838ccea62dbadfb2b993fbba4
SHA256 913e71acba46ee36e12dab454e62515797ee27999842021620630283930a5bdf
CRC32 B425902D
ssdeep 3:yW2lWRdvL7YMlbK7lhZpnNWGktat:y1lWnlxK7RpnEGwe
Yara None matched
VirusTotal Search for analysis
Name 80373395c6e516a3_~wrs{523b6cd7-aee7-4797-b7a4-ea3b76526a45}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{523B6CD7-AEE7-4797-B7A4-EA3B76526A45}.tmp
Size 1.5KB
Processes 2556 (WINWORD.EXE)
Type data
MD5 ac369d44d0d6af758ed3f2c541b48865
SHA1 3a1975db0bdf1dc64663ff32110a3aa5eb9fcb89
SHA256 80373395c6e516a3a535d7c9c1591569e7b0ca39866297c2282ce688ff14ab50
CRC32 E7438AA5
ssdeep 3:5lsl4/I5lNVRDUD3hdYV0GlBLBAaM1nRF5Zfdkl5X/l7htjPxRbzNR0qWPNR0/S4:olgI5lN48GGzlAajJpkqWj0NqWUZffmN
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{bfb6cb33-d795-45a3-83f9-e6d7f4190124}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BFB6CB33-D795-45A3-83F9-E6D7F4190124}.tmp
Size 1.0KB
Processes 2556 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis