Dropped Files | ZeroBOX
Name 3bfe46bb1ca35b20_kfolcnqeu92fr1mmeu9fbbc-[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\KFOlCnqEu92Fr1MmEU9fBBc-[1].woff
Size 19.5KB
Processes 2960 (iexplore.exe)
Type Web Open Font Format, TrueType, length 20012, version 1.1
MD5 de8b7431b74642e830af4d4f4b513ec9
SHA1 f549f1fe8a0b86ef3fbdcb8d508440aff84c385c
SHA256 3bfe46bb1ca35b205306c5ec664e99e4a816f48a417b6b42e77a1f43f0bc4e7a
CRC32 018E0965
ssdeep 384:Yc6bX9TagDCXKqs4+W5XVgaflKHjsGdZtlh3K/qzWz/scZpuB:YcCVaeCaF4ea9KHYQZtlh3Kgy4B
Yara None matched
VirusTotal Search for analysis
Name a2a1ddf97714e83e_{c80866d0-5065-11ef-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C80866D0-5065-11EF-948E-94DE278C3274}.dat
Size 4.5KB
Processes 2056 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 07035785e50623b6f724f901c64487bb
SHA1 1506cc6bbc28b50064d9256648ba09513dfa8409
SHA256 a2a1ddf97714e83e2dde12d7003fc9e1968d0d278f07bf37c1f77eb7bad297a5
CRC32 15DD3BD8
ssdeep 12:rlxAF2irrEgm8GL7KF2JxrEgm8Gr7qsANl26abax1NlgfRbax:r+rG8UxG8WANlIoNls
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 4070911a1bb9cc52_4uabrenhsxjlgdugo1oillu94ytzcwa[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\4UabrENHsxJlGDuGo1OIlLU94YtzCwA[1].woff
Size 25.8KB
Processes 2960 (iexplore.exe)
Type Web Open Font Format, TrueType, length 26464, version 1.1
MD5 08f80de0acf68d82aabab974a47d9e5f
SHA1 e6f1c0f5395a9c297aa162468961c1faf0ec1ed9
SHA256 4070911a1bb9cc52c4e4cd5e85ca186dcde89308a0517a8faa4715c2e0a9d45e
CRC32 FB696167
ssdeep 768:OIYb4Auz6mM1gBEL1WuL1BU91c6HJ8Y4mAS:OI84AueNmwHpBU91qY4m7
Yara None matched
VirusTotal Search for analysis
Name 069195370b9ca45f_recoverystore.{c80866cf-5065-11ef-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C80866CF-5065-11EF-948E-94DE278C3274}.dat
Size 4.5KB
Processes 2056 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 6cacff9ffe263cf9d123b913ea02c60b
SHA1 04bed27e6d99e1e7d6752a60f4dd9229559a1603
SHA256 069195370b9ca45fe054ea8c54f283b1f35216a591db35bc0d8fddf494d9c4ad
CRC32 69A10C62
ssdeep 12:rlfF2wSrEg5+IaCrI0F7+F2prEg5+IaCrI0F7ugQNlTqbaxtRLA08vONlTqbaxtK:rqv5/1p5/3QNlWoR80QONlWoR80gB
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name e3b0c44298fc1c14_cerF5E9.tmp
Empty file or file not found
Filepath C:\Windows\cerF5E9.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name fd361b57998c76f8_analytics[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\analytics[1].js
Size 44.9KB
Type ASCII text, with very long lines
MD5 871c39943ac31c498d591a714a31212c
SHA1 1d9ff3e3db5eb5293de06df5726f6058f07d98de
SHA256 fd361b57998c76f86335afa28b8a62527d88a8200fb5c428d6f0fff73383e955
CRC32 ACF6773C
ssdeep 768:zawmjvtB/E52UgKyPnUUTdAWA0YiaC6Vyn5ebYUDTJtwHx6g0stZS:za1K5QbUUT1A0YiowH8g0s6
Yara None matched
VirusTotal Search for analysis
Name 086a722e8fe1413c_index.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012020080720200808\index.dat
Size 32.0KB
Type Internet Explorer cache file version Ver 5.2
MD5 6386e4c5f5c9ba6e4d313406d194bd37
SHA1 a69128590163f9d4d04c6399730789218f6ba302
SHA256 086a722e8fe1413c5a773dc1cb5957609120c5ea53c1e82884dd342271698cd7
CRC32 63306B06
ssdeep 48:qsETU+lGKs4MlXMKs4jXhGPFdSo1TcRo3+14gyR:qsOUaGKstcKsSX2Fdj1F+h
Yara None matched
VirusTotal Search for analysis
Name eea94ebcf42f5feb_{c77bbc12-5065-11ef-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C77BBC12-5065-11EF-948E-94DE278C3274}.dat
Size 5.5KB
Processes 2764 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 f9f51e6150b541fbfb3bf8e297b6266d
SHA1 44e3cf09a9ac9e455680027eddb0f28b8615bd2e
SHA256 eea94ebcf42f5feba6f67c9b0889b6bbc5fda571a50df64285424c5ea44464cb
CRC32 D3D1E47A
ssdeep 48:rSWGdDf8JhUWcQqbD/I7kqbD/I7aqbD/IzOqbD/I7hqbD/I7wACHYOqbD/I7JQqS:e4bqH/uH/8H/k9H/lH/NHY9H/AH//S
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 5ce48d9e9d748ad4_4uagrenhsxjlgdugo1oill3owpg[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\4UaGrENHsxJlGDuGo1OIlL3Owpg[1].woff
Size 25.6KB
Processes 2960 (iexplore.exe)
Type Web Open Font Format, TrueType, length 26228, version 1.1
MD5 6dd4ad69d53830bdf5232a13482bd50d
SHA1 6fff1079d7e5d02a2259cb5d7833e790239e01cf
SHA256 5ce48d9e9d748ad4686094d3cc33f5ae1e272a5b618f5c6d146c4d12ef02e4a6
CRC32 CE368C7C
ssdeep 768:DBOEuz6T0146JY/J6unqhOYK0GJenzOoyo6:DBHuea4j/vnqo304enzUo6
Yara None matched
VirusTotal Search for analysis
Name 5d50f2c85b1c5954_tfewukjahgdfskyhiujfgsaiyufgsadyigfsadiuygfsadiulkhgfasdiluksdaguifksdagiukfgasduifklgasdkjgfsduakhygvfuyksadgfuiyasdglfiusad
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\tfewukjahgdfskyhiujfgsaiyufgsadyigfsadiuygfsadiulkhgfasdiluksdaguifksdagiukfgasduifklgasdkjgfsduakhygvfuyksadgfuiyasdglfiusad
Size 7.4KB
Processes 2548 (mshta.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 63a19f9a7bdf8b695a13d44069e8d103
SHA1 998a31d466ae6d3ab0121cf525a18e08e5109dc0
SHA256 5d50f2c85b1c5954fc43aed577818924336ace89ee477dcfa29838df526190fa
CRC32 CB27545D
ssdeep 12:MwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwG:DfAJFoKzBovNME/CHqVzYYYc
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 33bc8912208acdc7_rio98i69.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\RIO98I69.txt
Size 239.0B
Processes 2960 (iexplore.exe)
Type ASCII text
MD5 116a4fc341369a8c8ffa5a60653ba59b
SHA1 a1df1f3df012bb7235ca0f117a8fa010fc524a65
SHA256 33bc8912208acdc75982ae198ec50206d6799eee4a30072e4dfd9326f5adfa0a
CRC32 98A507A4
ssdeep 6:swOVxX/hpNW+ClnnEh9Jz6eKYaIN9UiZJKvSXDLJ/:s3VfpKlnEh9JmeRau9l+SXh
Yara None matched
VirusTotal Search for analysis
Name f2a7aae25f0f7a81_recoverystore.{c77bbc11-5065-11ef-948e-94de278c3274}.dat
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C77BBC11-5065-11EF-948E-94DE278C3274}.dat
Size 4.5KB
Processes 2764 (iexplore.exe)
Type Composite Document File V2 Document, Cannot read section info
MD5 58d040edc8a1144591e0347148c32919
SHA1 7479826d69bc7ffc613b14c88f55dc60a96bd9b7
SHA256 f2a7aae25f0f7a811caeceda314aeeb7fc254d388103472bca8b27edf1275431
CRC32 4E8FF1BA
ssdeep 12:rlfF2YorEg5+IaCrI0F7+F2XrEg5+IaCrI0F7ugQNlTqbaxQ+NlTqbaxQ:rq/5/1X5/3QNlW6NlW
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 468e579fe1210fa5_kfolcnqeu92fr1mmwulfbbc-[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
Size 19.4KB
Processes 2960 (iexplore.exe)
Type Web Open Font Format, TrueType, length 19888, version 1.1
MD5 cf6613d1adf490972c557a8e318e0868
SHA1 b2198c3fc1c72646d372f63e135e70ba2c9fed8e
SHA256 468e579fe1210fa55525b1c470ed2d1958404512a2dd4fb972cac5ce0ff00b1f
CRC32 A6819AC9
ssdeep 384:0c6bX9TSzYzCrQH+qXM6C0ouF0xcYye+5x/U3S0X5v+obEgm:0cCV8GuPVyzx/MS0X5v+oI/
Yara None matched
VirusTotal Search for analysis
Name 74c398f97c8c0db5_FEQKX2F6.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\FEQKX2F6.txt
Size 317.0B
Type ASCII text
MD5 704cfd4d30aac2c81baabdfe293b546c
SHA1 0582b1e6f9d1a7c98664cc75ddc6865fc6835ab9
SHA256 74c398f97c8c0db58e552dd3c9417200ae109b5ce10515e27f929834c55b31e3
CRC32 F563546B
ssdeep 6:kpwa+td7CYpec8k3OgdAwmq+EbKBa1GnBc4jpccX0Wp+SXlQZWjdc8XzdxD:kpwa+LveA9dAwM8AnBLcPa+SXlQIBD
Yara None matched
VirusTotal Search for analysis
Name 6ca93f088a47e332_js[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\js[1].js
Size 254.5KB
Processes 2960 (iexplore.exe)
Type ASCII text, with very long lines
MD5 5ae44c339d8c2d9874e9fc8c2e48ae76
SHA1 6dc016f2bb5d4c66c36125127c9d22e330bd4d65
SHA256 6ca93f088a47e332129beb93284bf1390592877fdd97832702c79b4e8101f926
CRC32 5B858AF5
ssdeep 6144:8XjX8OX6r151mENFhR1xE48iFpF9ijUjih02BBk:EjLCnNFPDgu
Yara None matched
VirusTotal Search for analysis
Name 1570f866bf6eae82_kfomcnqeu92fr1mu4mxm[1].woff
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\KFOmCnqEu92Fr1Mu4mxM[1].woff
Size 19.4KB
Processes 2960 (iexplore.exe)
Type Web Open Font Format, TrueType, length 19824, version 1.1
MD5 bafb105baeb22d965c70fe52ba6b49d9
SHA1 934014cc9bbe5883542be756b3146c05844b254f
SHA256 1570f866bf6eae82041e407280894a86ad2b8b275e01908ae156914dc693a4ed
CRC32 6BF23A7A
ssdeep 384:ozNCb8EbW9Wg166uwroOp/taiap3K6MC4fsPPuzt+7NCXzS65XZELt:K4zbWcDVwt230hfs+x+Bb65X2
Yara None matched
VirusTotal Search for analysis
Name 1beb05868ce93bcc_IE9CompatViewList[1].xml
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTDTA402\IE9CompatViewList[1].xml
Size 141.8KB
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 9b63e0fb3785ffa49686dd75e303d177
SHA1 e3992de5a1b8f58a11a52ad71f275ae413927eb4
SHA256 1beb05868ce93bcc8fafc46adccdda6d104f3c6f6c6ed454d8a6c0c208d9bd0e
CRC32 F778EDEF
ssdeep 3072:AoSMrEDL1FwhdFFaz6l8vHG+TbFPAzepobjyG7I1K1IB2+Tir8v1IG9aIedyPcFC:dSMrEDL1FwhdFFaz6l8vHG+TbFPAzepR
Yara None matched
VirusTotal Search for analysis
Name de36e50194320a7d_analytics[1].js
Submit file
Filepath C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\analytics[1].js
Size 51.7KB
Processes 2960 (iexplore.exe)
Type ASCII text, with very long lines
MD5 575b5480531da4d14e7453e2016fe0bc
SHA1 e5c5f3134fe29e60b591c87ea85951f0aea36ee1
SHA256 de36e50194320a7d3ef1ace9bd34a875a8bd458b253c061979dd628e9bf49afd
CRC32 A310A200
ssdeep 768:oHzaMKHBCwsZtisP5XqYofL+qviHOlTjdNoVJDe6VyKaqgYUD0ZTTE8yVfZsk:caMKH125hYiM8O9dNoVJ3N48yVL
Yara None matched
VirusTotal Search for analysis
Name 7fa4b58350d7f076_generatedscript_20240330010339.vbs
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\GeneratedScript_20240330010339.vbs
Size 5.6KB
Processes 2868 (certutil.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 541387f56fe5e5c47555158f04975fe6
SHA1 6aba8c9cd5950b491baca8176f34b2c6f5c4f7b8
SHA256 7fa4b58350d7f0766c8fc9f54c48a8061c64e20cd37ed0c53b27a418baa8be4e
CRC32 D9D3210A
ssdeep 12:oWdPF6AtDzeIPJHGk8w8G1TPq7H5U5U5U5U5U5U5U5U5U5x:BPFNPQG1TP+gggggggggx
Yara None matched
VirusTotal Search for analysis