Dropped Files | ZeroBOX
Name a264f95e77a3d02f_~wrs{e8a7ede8-8c29-4445-85b4-f656c24827bd}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E8A7EDE8-8C29-4445-85B4-F656C24827BD}.tmp
Size 21.5KB
Processes 2568 (WINWORD.EXE)
Type data
MD5 4922b4ad9b3ae8c719253d3f07e6bcba
SHA1 4d959ad8407b008011242566d91d12c7dd439c1c
SHA256 a264f95e77a3d02fa6cb9e40b5fca1245df1bcec318ab8b4138d0a321bd59aa5
CRC32 32E6E30B
ssdeep 384:rgxuPmZ2HYZa5Q5VmIQXwvW5Kq2g09a8iesgxgr:rgI2Q5Q6IQXwvW5Kq2g0YResgI
Yara None matched
VirusTotal Search for analysis
Name a36c6683d0754d68_~$merozx.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$merozx.doc
Size 162.0B
Processes 2568 (WINWORD.EXE)
Type data
MD5 50c9d90ab451fd6a2789981bc38ef123
SHA1 b3958947768f25d9fd1945b77dab4e05165ef24c
SHA256 a36c6683d0754d68dc181113e0eba69e1b885881b819208b7d3891a5253ab2f5
CRC32 4F0402BC
ssdeep 3:yW2lWRdvL7YMlbK7lhZWGml/:y1lWnlxK7Ru
Yara None matched
VirusTotal Search for analysis
Name d8a384390033973b_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2568 (WINWORD.EXE)
Type data
MD5 66aa6ce5946fb93fa8ed38bf3b50f3ea
SHA1 1a803d5ae7e501f117ad0da5b7bb190eb81e3365
SHA256 d8a384390033973b3e0fc63fc57963802f6459f2c2e88cdf6dcb323d6c73100c
CRC32 0044B0A4
ssdeep 3:yW2lWRdvL7YMlbK7l/nl:y1lWnlxK7
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{bfb6cb33-d795-45a3-83f9-e6d7f4190124}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BFB6CB33-D795-45A3-83F9-E6D7F4190124}.tmp
Size 1.0KB
Processes 2568 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis