Dropped Files | ZeroBOX
Name a1dad75ae966830f_R5T3HKE5.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\R5T3HKE5.txt
Size 309.0B
Type ASCII text
MD5 f804cf5bc46bdc9aa8023878219312b5
SHA1 433819a76e7cb5cef1e8fb34288750d1fdb4de1d
SHA256 a1dad75ae966830fcd31e694d476aa11e69cc2ea60aa7bb2cd838cf8545040c8
CRC32 037015B4
ssdeep 6:zCPrX7xBXiGFrLKH2lMHXIgUVRJw5CPrX+RfKh4QLKH2lMHXIgUVRJwt:zU9x/KRXIzJwU+khdKRXIzJQ
Yara None matched
VirusTotal Search for analysis
Name ffb18189c8e04084_Cookies
Submit file
Filepath C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies
Size 36.0KB
Type SQLite 3.x database, last written using SQLite version 3033000
MD5 c19826403c4c8e5086a8d49e37c94838
SHA1 4d19768231a3373fb0fa91d5513e21ad772b137b
SHA256 ffb18189c8e040846bba547b243fda347516329d58a44b26fd8616549249e077
CRC32 36EBD488
ssdeep 48:ToLOpEO5J/KdGU1/X2ydikE6HDHCp0mSzW34KXEw:ENwudLE6jOSzLw
Yara None matched
VirusTotal Search for analysis
Name 19a8f34660080bd7_index.dat
Submit file
Filepath C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
Size 32.0KB
Type Internet Explorer cache file version Ver 5.2
MD5 9354a5a02533ed4cf90b8c547cfcb95b
SHA1 dfc84a2b78ee174f3ee4558c3a6ae9b4042c3b9d
SHA256 19a8f34660080bd707e8d377a76304fb3e90e125c69cf18d96318d49fda47653
CRC32 97BD9782
ssdeep 48:qAEEVULD0BfyEV2tWSlphRRwkPAMyaz4I0GNVVN:qAEEVIDI2H5KqBv4I00
Yara None matched
VirusTotal Search for analysis
Name f825dd89181e7435_d93f411851d7c929.customdestinations-ms
Submit file
Filepath c:\users\test22\appdata\roaming\microsoft\windows\recent\customdestinations\d93f411851d7c929.customdestinations-ms
Size 7.8KB
Processes 5292 (Powershell.exe)
Type data
MD5 61d3b003e73f968491bb9de05318fcbd
SHA1 abb40732bf72a072c5b176449fdb8f1c56383e03
SHA256 f825dd89181e743525684aff8d99cc6d78046e461147c33b6f7a182b98c58ea9
CRC32 76116DE9
ssdeep 96:wtuCiGCPDXBqvsqvJCwoNtuCiGCPDXBqvsEHyqvJCworc7HwxGlUVul:wt7XoNt7bHnorXxY
Yara
  • Antivirus - Contains references to security software
VirusTotal Search for analysis