Name | a9220271c0eb79e5_d93f411851d7c929.customDestinations-ms~RFa70dce.TMP |
---|---|
Filepath | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RFa70dce.TMP |
Size | 7.8KB |
Type | data |
MD5 | b0c9ff441742f3847ea27da9dee7f2cd |
SHA1 | c42a1eb32ba953a0ce5d8635caabf71b5b281495 |
SHA256 | a9220271c0eb79e5750e0d0e62058ecac560e09cdf9e82ef61aeeabada5d48a4 |
CRC32 | 0BBCAB1A |
ssdeep | 96:RutuCOGCPDXBqvsqvJCwo+utuCOGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:UtvXoxtvbHnorrxQ |
Yara |
|
VirusTotal | Search for analysis |
Name | 1d6b2c4ff1ca2966_d93f411851d7c929.customdestinations-ms |
---|---|
Filepath | c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms |
Size | 7.8KB |
Processes | 54036 (powershell.exe) |
Type | data |
MD5 | 2d2297a40e2b64d7a59407aacae0e2af |
SHA1 | 0e496f2e92d26107be821377bb39ed61f1b24801 |
SHA256 | 1d6b2c4ff1ca29667eab044d6248f82576a3e8c231a28254ef1145baaee4c99b |
CRC32 | D8821F06 |
ssdeep | 96:L4tuCeGCPDXBqvsqvJCwok4tuCeGCPDXBqvsEHyqvJCworSP7Hwxf2lUVul:8tvXoptvbHnorrxQ |
Yara |
|
VirusTotal | Search for analysis |
Name | e93e709da2bf6000_logs.uce |
---|---|
Filepath | C:\logs.uce |
Size | 345.0B |
Processes | 53812 (AppLaunch.exe) |
Type | ASCII text, with CRLF line terminators |
MD5 | 0a686f03494576f1204e65653bce54bf |
SHA1 | 22faa860ec67a432ed3b6829939b5f6353139bc4 |
SHA256 | e93e709da2bf600012df6fa6bee9775c42c337501c485757f3a7bca17c135d7d |
CRC32 | F1352D10 |
ssdeep | 6:DiYgE/ovRhBFqGTUhKliYgE/ovRhBFqGTUhKSI7wKd/cwEJPDdVsYQnKfaHTPOxR:uwgphTlMxwgphTlMA7cwo7LS9jqgq2Ah |
Yara | None matched |
VirusTotal | Search for analysis |