Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2021-12-20 15:08 INVOICE_6464568682646487494965...  

28513ec46760b0cc74c0aafe4a9e5a83


Gen1 Emotet RAT Gen2 NPKI PDF Suspicious Link Generic Malware WinRAR Malicious Library UPX Malicious Packer Antivirus ASPack Admin Tool (Sysinternals etc ...) PDF AntiDebug AntiVM PE File OS Processor Check PE32 DLL GIF Format PNG Format .NET EXE MSOffice Malware download NetWireRC VirusTotal Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Tofsee DCRat Windows Exploit ComputerName Remote Code Execution DNS Cryptographic key crashed
11 4 3 14.0 M 43 ZeroCERT

2 2021-11-05 11:23 rat_client_x32_windows.exe  

028d46daecc32df5eabf16e28b1e4174


NPKI Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer PE File OS Processor Check PE32 DLL VirusTotal Malware Check memory Creates executable files AppData folder crashed
2.0 27 ZeroCERT

  • First
  • 1
  • Last
  • Total : 2cnts