Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2021-09-01 09:34 win101.exe  

801affd34ae1974fd0965e7c1128eb96


Generic Malware Admin Tool (Sysinternals etc ...) ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
1 3 1 9.4 M 40 ZeroCERT

2 2021-08-14 09:57 refno3.exe  

c7cda00215a9747d2a6142919bd45227


Generic Malware Admin Tool (Sysinternals etc ...) .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.8 M 44 ZeroCERT

3 2021-08-13 09:53 mazx.exe  

bd2c6dc178b0c292a9f6d62a1c4121a4


Generic Malware Admin Tool (Sysinternals etc ...) ScreenShot AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious TLD Windows DNS Cryptographic key
2 4 4 1 8.6 M 34 ZeroCERT

4 2021-08-13 09:47 plugmanzx.exe  

864e2a02a8da7f5829616b793608b6a5


Generic Malware Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM .NET EXE PE File PE32 Malware download Nanocore VirusTotal Malware c&c Buffer PE AutoRuns PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
2 2 14.0 35 ZeroCERT

5 2021-08-13 09:45 bobbyzx.exe  

9a813a694390804d6d8cc05ac1efe79f


PWS Loki[b] Loki.m AgentTesla ftp Client info stealer email stealer Generic Malware PSW Bot LokiBot ZeusBot Admin Tool (Sysinternals etc ...) DNS Socket Escalate priviledges ScreenShot Steal credential persistence AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Malware download FTP Client Info Stealer Pony VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications AppData folder malicious URLs WriteConsoleW installed browsers check Windows Update Browser Email Cryptographic key Software Downloader
1 2 4 15.0 39 ZeroCERT

  • First
  • 1
  • Last
  • Total : 5cnts