Dropped Files | ZeroBOX
Name 576dbbfdd466c269_{e6d59d72-51cd-11ee-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E6D59D72-51CD-11EE-AC50-94DE278C3274}.dat
Size 4.0KB
Processes 2144 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 d46dbde596525b74ca4c6330ce4abcc9
SHA1 aa7b3402c760ec0115a51a44eef4c1d6561283b0
SHA256 576dbbfdd466c2699dc3f42f59c17ba8ef296c9a5eef6b8dbf9eaa86820fb430
CRC32 32695B66
ssdeep 12:rl0YmGFuWrEgmfcB7KFWcrEgmfZ7qgONlQ8dbax9tX/Q1746NlL9baxGjMsKtHa+:rrGGcG/ONlZ59NlpDAlh+
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 0ed5b0823e71e0e3_590aee7bdd69b59b.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\590aee7bdd69b59b.customdestinations-ms
Size 7.8KB
Processes 2112 (powershell.exe)
Type data
MD5 f4a8a3e56bca0190031a365f104571cf
SHA1 7a4eac7016b8feca961f757cfe05bfeb4b76c10f
SHA256 0ed5b0823e71e0e3262a8a73ff269499135b20c9c5aa71e34b57a9f43218ed41
CRC32 E95A2C69
ssdeep 96:QtuC6GCPDXBqvsqvJCwoFtuC6GCPDXBqvsEHyqvJCworQStDHXyWlUVul:QtbXoFtbbHnorFTyo
Yara
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
VirusTotal Search for analysis
Name 31ff6ae696e61466_recoverystore.{e6d59d71-51cd-11ee-ac50-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E6D59D71-51CD-11EE-AC50-94DE278C3274}.dat
Size 4.5KB
Processes 2144 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 5f331ad7a906f8cf70c906fab149f61b
SHA1 a9266c6086e14072710273b2857cab5e9842d465
SHA256 31ff6ae696e6146606b268f4f045076dc54639bff62c90fcfad59a78faa053e6
CRC32 5197F4A2
ssdeep 12:rlfF2QxrEg5+IaCrI0F7+F2urEg5+IaCrI0F7ugQNlTqbaxVVV8NlTqbaxVV15:rqe5/1u5/3QNlW6VV8NlW6V15
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis