Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2022-01-24 09:34 .winlogon.exe  

956d9a9e550cca451c2f56d896a70c4d


RAT PWS .NET framework Generic Malware PE File PE32 .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself ComputerName crashed
2.8 45 ZeroCERT

2 2022-01-20 10:47 BYiW5fs7bTwL3dw.exe  

575dd0654b98ef57269689581b55952e


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 13.0 M 46 ZeroCERT

3 2022-01-20 10:19 .winlogon.exe  

9eedecb718c16d02f2482875051ecdec


RAT NPKI email stealer Generic Malware TEST Socket DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer VirusTotal Email Client Info Stealer Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName DNS crashed
1 3 11.6 M 33 ZeroCERT

4 2021-10-13 09:29 .winlogon.exe  

5d388a0651d6bb853ebcd267f3571c6a


Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
10.6 32 ZeroCERT

5 2021-10-06 13:50 .winlogon.exe  

0518bf639cc856d129f734a20b6ec573


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
11.6 M 40 ZeroCERT

  • First
  • 1
  • Last
  • Total : 5cnts