Dropped Files | ZeroBOX
Name 126ca1f465178e1a_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 1000 (WINWORD.EXE)
Type data
MD5 2eb0ee4ee71d2d8a16a490714850b086
SHA1 8b8708f50b5f8726592536cfbe9a4444afd7aaf7
SHA256 126ca1f465178e1aa7480a41cab83018bda3e18782ad213a3649b7ae961d5bea
CRC32 D482900F
ssdeep 3:yW2lWRd+t1SloW6L7htt/l7TK7lMEHItD1cLmtt:y1lWatoloWmP1lvK7L4DWLmtt
Yara None matched
VirusTotal Search for analysis
Name 8f45870d13badc2d_~wrs{b6a424cd-5825-4470-9fad-b9a3d194b318}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B6A424CD-5825-4470-9FAD-B9A3D194B318}.tmp
Size 14.5KB
Processes 1000 (WINWORD.EXE)
Type data
MD5 e8e1197bca1b7c3d6646f8fab08435df
SHA1 b3b287b5c8c6472d8e1690ccd99246bb8ecf63a3
SHA256 8f45870d13badc2d81a6ba2291ff4b3466e1ba68d27ff14dfa813865717b366a
CRC32 23A8AD1A
ssdeep 384:gJyHBhZFr6tBwqXCrpCPxE57x7Ka18/5NTK4MO7:+yhh7r6tBw1CPxC7Bh4MO7
Yara None matched
VirusTotal Search for analysis
Name c9b79de59532a164_~$mliecachesbrowser.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$MLIECachesBrowser.dOC
Size 162.0B
Processes 1000 (WINWORD.EXE)
Type data
MD5 d4edbec18e63bc1747e8be81366eba01
SHA1 991cd35c9f3e0e20177d7fa674d782161e5154cb
SHA256 c9b79de59532a164fef560633346d138a2dcdca23225d4a3d5d88ba4ecfcd176
CRC32 58B2CF69
ssdeep 3:yW2lWRd+t1SloW6L7htt/l7TK7lMEHItD1cLmbl:y1lWatoloWmP1lvK7L4DWLmbl
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{be4cde95-8279-41d0-b946-07cb50716005}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BE4CDE95-8279-41D0-B946-07CB50716005}.tmp
Size 1.0KB
Processes 1000 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis