Dropped Files | ZeroBOX
Name 253bd6cb2b29db77_~$lawzx.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$lawzx.doc
Size 162.0B
Processes 1952 (WINWORD.EXE)
Type data
MD5 92fcbcf1d216e29e814d5215b65f1f26
SHA1 77cfabfdfc767d5fdc37d5f8aa3303736c470dfa
SHA256 253bd6cb2b29db77aa37606ba705547dacdb0ed9b8acff78171937f58c1853e1
CRC32 979A12FF
ssdeep 3:yW2lWRdpf/W6L7Kv1ZJK7HRtpuItg3lqMJ:y1lWlWmgdK7vgJ
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{be4cdfc1-8279-41d0-b946-07cb50716005}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BE4CDFC1-8279-41D0-B946-07CB50716005}.tmp
Size 1.0KB
Processes 1952 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 95f87deb06465213_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 1952 (WINWORD.EXE)
Type data
MD5 571d0fbc66b18d219c61f44d13b93ffc
SHA1 f5e4a1934790afee21e582b5ec0041a72e015969
SHA256 95f87deb06465213a248e17efbb896749aeac40b5714fae01f5e316285bfcb35
CRC32 6CA25C40
ssdeep 3:yW2lWRdpf/W6L7Kv1ZJK7HRtpuItg3lq9sl/n:y1lWlWmgdK7vgPl/n
Yara None matched
VirusTotal Search for analysis
Name 6d7c1e599ae958b1_~wrs{c4e2f51f-da36-49fc-b9d5-108ccc5c54a4}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C4E2F51F-DA36-49FC-B9D5-108CCC5C54A4}.tmp
Size 40.8KB
Processes 1952 (WINWORD.EXE)
Type data
MD5 c52012cbde375099da44b0aed7fa6677
SHA1 88564ec2fee0354b32b30b831ac21e803a028a27
SHA256 6d7c1e599ae958b1af4af69a876f17ac95764decce02e77b7a1004fd0c59cf38
CRC32 634DA72C
ssdeep 768:Ms0SCWiMuz1rqAyLt+eqViz9yCFcEhZVsf3l5H9SvnvE+esH:EDvwxKrK2f1Wvnvdey
Yara None matched
VirusTotal Search for analysis