Dropped Files | ZeroBOX
Name fac869e635a6ba3f_~wrs{b74914f2-1804-4a31-a29b-7f9c12e21dc9}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B74914F2-1804-4A31-A29B-7F9C12E21DC9}.tmp
Size 1.5KB
Processes 884 (WINWORD.EXE)
Type data
MD5 c00bd4a6bec71cc811f52943a8d3b131
SHA1 fa89a094b91b2efe7bcd605ceb1fceb29a4d44d5
SHA256 fac869e635a6ba3f259cc4409bf7edb33821fa5f29b562ba4ef355bfe64ac53e
CRC32 DDB57AC4
ssdeep 6:IiiiiiiiiiI4/9+Qc8++lPkalT4Mu8lPloBl/oK:W49+QG+3/g
Yara None matched
VirusTotal Search for analysis
Name fd77deab758b405a_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 884 (WINWORD.EXE)
Type data
MD5 462e90ef90dfe17ec4dac63f5292ba2f
SHA1 10f5582c8c52dfd8d0d62d02b3f2bbc7e8910ea9
SHA256 fd77deab758b405af23fb63cb258b067ea21c8bb3921d6eea75bef962de6e0dd
CRC32 7E353E2E
ssdeep 3:yW2lWRd7/tiloW6L7S/vjTK7gwhgHItwldx9qG/l:y1lWFiloWmoXK7gcg4Y42l
Yara None matched
VirusTotal Search for analysis
Name 7f042ef872f13d7c_~wrs{c4e2f51f-da36-49fc-b9d5-108ccc5c54a4}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C4E2F51F-DA36-49FC-B9D5-108CCC5C54A4}.tmp
Size 10.0KB
Processes 884 (WINWORD.EXE)
Type data
MD5 ba043c3cb8d7327369f0a909c3d0f6f1
SHA1 dae06565ec324d63f3a6282d4fd79ddc39ab7540
SHA256 7f042ef872f13d7c3a66c0aed6b4d0f95b7254904223414cbef01e272adad15b
CRC32 0E91567A
ssdeep 192:vT7ftwYb/UrDoUZgYQVQHgeaCDCzidTziYuRMl6I1LO6aPDgRHwj3shiP+F07CWK:vfbyXHPaCDwipzIe11LUPmHq8079hGL
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{be4ca11a-8279-41d0-b946-07cb50716005}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BE4CA11A-8279-41D0-B946-07CB50716005}.tmp
Size 1.0KB
Processes 884 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis
Name 5aef211a28477953_~$crosoftdesignednewthechnologytoupgradeentireprocessinsingleclicktounderstandhowimportantitsisverynicefeaturesforthem.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$crosoftdesignednewthechnologytoupgradeentireprocessinsingleclicktounderstandhowimportantitsisverynicefeaturesforthem.doC
Size 162.0B
Processes 884 (WINWORD.EXE)
Type data
MD5 e0cd9c5382fcf2cd713abe4987f2e3f2
SHA1 ff639b83b75f3ef33543ac13006326733de02e0d
SHA256 5aef211a28477953a01bbd44764968e577b31736f638bfadd20528bea8dbe610
CRC32 661E27C6
ssdeep 3:yW2lWRd7/tiloW6L7S/vjTK7gwhgHItwldx9i5Gn:y1lWFiloWmoXK7gcg4Yw5Gn
Yara None matched
VirusTotal Search for analysis