Dropped Files | ZeroBOX
Name d8a384390033973b_~$normal.dotm
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
Size 162.0B
Processes 2556 (WINWORD.EXE)
Type data
MD5 66aa6ce5946fb93fa8ed38bf3b50f3ea
SHA1 1a803d5ae7e501f117ad0da5b7bb190eb81e3365
SHA256 d8a384390033973b3e0fc63fc57963802f6459f2c2e88cdf6dcb323d6c73100c
CRC32 0044B0A4
ssdeep 3:yW2lWRdvL7YMlbK7l/nl:y1lWnlxK7
Yara None matched
VirusTotal Search for analysis
Name 0b22f6e039c55375_~$.gh.gh.ghghghgh.doc
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\~$.gh.gh.ghghghgh.doc
Size 162.0B
Processes 2556 (WINWORD.EXE)
Type data
MD5 82c1a7c460b4deb40e0e6a8bf674146b
SHA1 65318dd43d5f50e179f7b483210fccd6e76fd077
SHA256 0b22f6e039c553755b7f2a83c38105e64b18201debd95906cb3bdc24ac14e021
CRC32 3C88FD62
ssdeep 3:yW2lWRdvL7YMlbK7lhZ1nITnl:y1lWnlxK7R1nITn
Yara None matched
VirusTotal Search for analysis
Name acdf84ac7d546dba_~wrs{e8a7ede8-8c29-4445-85b4-f656c24827bd}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{E8A7EDE8-8C29-4445-85B4-F656C24827BD}.tmp
Size 6.5KB
Processes 2556 (WINWORD.EXE)
Type data
MD5 7f43cc8bd570b4b4e528a9dcc00afcba
SHA1 9d19be35e5597b5bfb8b8f1b2f7f8101c8be36de
SHA256 acdf84ac7d546dba7f0ccf62eeeb0a1bdb51c1c04020076a53f54efca6a2ab28
CRC32 48A6820A
ssdeep 192:Kc0D3Rt4jWyuooV6JGi8shru5/HWdg5WAy0MBTB85m:gRt4yyuoosJD8Iah2G5Wj0sB85m
Yara None matched
VirusTotal Search for analysis
Name 4826c0d860af884d_~wrs{bfb6cb33-d795-45a3-83f9-e6d7f4190124}.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{BFB6CB33-D795-45A3-83F9-E6D7F4190124}.tmp
Size 1.0KB
Processes 2556 (WINWORD.EXE)
Type data
MD5 5d4d94ee7e06bbb0af9584119797b23a
SHA1 dbb111419c704f116efa8e72471dd83e86e49677
SHA256 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
CRC32 23C03491
ssdeep 3:ol3lYdn:4Wn
Yara None matched
VirusTotal Search for analysis