Dropped Files | ZeroBOX
Name 054bbf77cd133e8d_recoverystore.{add19965-3c48-11ef-91c7-080027c2f7b0}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{ADD19965-3C48-11EF-91C7-080027C2F7B0}.dat
Size 4.5KB
Processes 2052 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 d613c2b7cdef787f189ad3233760ba61
SHA1 326dcdd4567885f25b1953fe952a4198eb09ae5e
SHA256 054bbf77cd133e8dba902be67dd8535230e4db84a6ef7fe27a33be1e2598edbe
CRC32 8D9165B8
ssdeep 12:rlfF2ZrEg5+IaCrI0F7+F29XWrEg5+IaCrI0F7ugQNlTqbaxXP0TZdNlTqbaxXPh:rqZ5/1JW5/3QNlWe6NlWe
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 0ed583114cb91c67_accounts_google_com[1].htm
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\accounts_google_com[1].htm
Size 271.0B
Processes 2160 (iexplore.exe)
Type gzip compressed data
MD5 11b5f7972136ba99e811424ce2a47a0c
SHA1 1c91c73991e222370442c52b7f406322ecf2d578
SHA256 0ed583114cb91c67e2553a1e5be6540f5e318e9f489f18f58e60d752f5be53d6
CRC32 F14ADCFE
ssdeep 6:XtLpZF0oTUIBi8X4Gf8wX4U4ZGQsPHmQjQi02tsibb8klBdCYQwEn:X1zF0OHCGfMhZGHPGZX2tsibb1un
Yara None matched
VirusTotal Search for analysis
Name 5e71088a1ddda5aa_{add19966-3c48-11ef-91c7-080027c2f7b0}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{ADD19966-3C48-11EF-91C7-080027C2F7B0}.dat
Size 9.5KB
Processes 2052 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 22b6884a50d1e50330dc58bcf0eeb8a0
SHA1 fb68034a386a12b67dc3cfd876d6bc9a7aec0178
SHA256 5e71088a1ddda5aa9122148395aad5ddf5ffa2d3fb1c55a40c9266c85646d3cd
CRC32 F71A4230
ssdeep 192:H3HAfet3dfMU3H2Af13HAfb3HAfN3HAfR+kZLfY3HAfV:QG/kWCMKB
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 6de598428c334097_IE9CompatViewList[1].xml
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\IE9CompatViewList[1].xml
Size 141.7KB
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 c236e316e1b9ac60ce15dac7bcb8b2de
SHA1 1e240ed5f7cbc3dc8cd2397c7151a0d7e5f173c2
SHA256 6de598428c334097a21eb2dd5963c190fc5f80a6289bce205ded0466393745a4
CRC32 8B345ADA
ssdeep 3072:toSMrEDL1FwhdFFaz6l8vHG+TbFPAzepobjyG7I1K1IB2+Tir8v1IG9aIedyPcFC:mSMrEDL1FwhdFFaz6l8vHG+TbFPAzepR
Yara None matched
VirusTotal Search for analysis
Name e3c638bae3322473_8wim0xf7.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\8WIM0XF7.txt
Size 130.0B
Processes 2160 (iexplore.exe)
Type ASCII text
MD5 7c845a1c0731d8fce8cc4b07b59ee5b5
SHA1 c8f0611e947dbdff248267201105a273a37a17ea
SHA256 e3c638bae332247307f2ea6a10c95655eddaf6ac947c0c093112895246461ca5
CRC32 35D12F46
ssdeep 3:LDM8vUJtEFPzbXWSbIHSfCWizJ3uJcSMM9TcUNX7vWYQSReNG/:Lg+nPHXWjSfDa+SVKTlNXCYHRP/
Yara None matched
VirusTotal Search for analysis
Name 5b10aeb64c00086f_PE04IXTR.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\PE04IXTR.txt
Size 130.0B
Processes 2160 (iexplore.exe)
Type ASCII text
MD5 16f39a73742dc7a0db762651d20ed853
SHA1 7fa00866c2f5e8a12949cd56ae2c59dce38f8ad7
SHA256 5b10aeb64c00086f91ecabf270676934a7090103e3ab779412f6de7ef09813ad
CRC32 9A971EA9
ssdeep 3:LDM8vUvFoepwKuHrTOtveWJ3uJcSMMmteUNX7vWfWJEe0/:Lg+o2epYutvF+SVJLNXC+WP/
Yara None matched
VirusTotal Search for analysis