Dropped Files | ZeroBOX
Name d35f4971613c8705_aaberg
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\Aaberg
Size 244.0KB
Processes 2560 (Scandoc1114.exe)
Type data
MD5 270f73d838c3247af779f37fead97f3e
SHA1 7e1c931c0508553f6a458775e9991c398cc632ce
SHA256 d35f4971613c870511958727b1a5623915892d7bad977dc25b4bcbc0a97dcf11
CRC32 9F8AA2C6
ssdeep 6144:Ik4VbcLDYhjLmaRIi7cDjuzcdAuQeTzFiB9gs:IkybcvYhjLmayi7crDQZgs
Yara None matched
VirusTotal Search for analysis
Name 1fa24852d507e24e_autEFDF.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\autEFDF.tmp
Size 9.7KB
Processes 2560 (Scandoc1114.exe)
Type data
MD5 e40f8609c5ab653062b1e2b071e2792c
SHA1 706aa88f631c62490affb27338431bb3d8de1ac7
SHA256 1fa24852d507e24e9964f48704d31be7911f44eb5c3827798b13eb7a93fbabd2
CRC32 A862ADFD
ssdeep 192:uFnxJiTefgLsYzUS46SgtVppx6RqDVxkKFg/3ndM6UO/spNn:u1xJj0sYzUS1SgnppURgXkKwC/O4Nn
Yara None matched
VirusTotal Search for analysis
Name 86ac906e1a2c2544_piceworth
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\piceworth
Size 29.0KB
Processes 2560 (Scandoc1114.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 2a0c7be628a2002dd9171ba7fec11713
SHA1 e0122801d49cb3967b612c723242543462ec3eba
SHA256 86ac906e1a2c25442df1d954da1fcc546ceb7584f508f7b867c17b9afa59e46d
CRC32 4C9651E5
ssdeep 768:aiTZ+2QoioGRk6ZklputwjpjBkCiw2RuJ3nXKUrvzjsNbQE+I+h6584vfF3if6ga:aiTZ+2QoioGRk6ZklputwjpjBkCiw2Rj
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 94de442add503b78_autEFCE.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\autEFCE.tmp
Size 162.4KB
Processes 2560 (Scandoc1114.exe)
Type data
MD5 57772947abd1c201daf63c877a5af2b4
SHA1 c942817a1e4c58fb26f2ff068cfc97e97110b1bf
SHA256 94de442add503b789eae81d4e006549c96e896a597518002dbc625071ed66a6f
CRC32 E9E35785
ssdeep 3072:4S2gnHbEffnWsLI89QDxg/j9u/pFMzOFjRXLsNi/v5R/hqEVEDrVTjO5L:3r7EffnWsc8ODOjarbxLyi/rsGENiL
Yara None matched
VirusTotal Search for analysis