Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2022-07-28 09:48 scrss.exe  

8b820acfe8df41893d619c947412c4e0


PWS[m] PWS .NET framework email stealer Generic Malware Antivirus Socket DNS Code injection KeyLogger Downloader Escalate priviledges persistence AntiDebug AntiVM PE32 .NET EXE PE File VirusTotal Malware powershell Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName DNS Cryptographic key
1 14.2 M 39 ZeroCERT

2 2022-05-20 13:29 .winlogon.exe  

e5de3d7a842f077da31aec68eec0a6e5


PWS[m] RAT NPKI email stealer Socket DNS Code injection KeyLogger Downloader Escalate priviledges persistence AntiDebug AntiVM PE32 .NET EXE PE File Browser Info Stealer VirusTotal Email Client Info Stealer Malware PDB MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key crashed
1 11.2 38 ZeroCERT

3 2022-05-19 11:16 .winlogon.exe  

23d55ec743bb3c696c73ac8e3c8266f1


PWS[m] RAT PWS .NET framework email stealer Socket DNS Code injection KeyLogger Downloader Escalate priviledges persistence AntiDebug AntiVM PE32 .NET EXE PE File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key crashed
1 9.8 43 ZeroCERT

4 2022-02-03 11:35 .winlogon.exe  

45fea56b0ab4e8de9f9dde4fa1dc0240


PWS .NET framework NPKI email stealer Generic Malware Anti_VM Antivirus DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key crashed
1 13.2 M 39 ZeroCERT

5 2022-02-03 10:51 .winlogon.exe  

993fd8d8df9fc454be51114836372360


RAT PWS .NET framework NPKI email stealer Generic Malware Anti_VM DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key crashed
3 11.4 M 35 ZeroCERT

6 2022-02-03 10:46 .winlogon.exe  

d5b2a781a0c3e3adf56ef8e66407e9dd


RAT Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
9.4 M 42 ZeroCERT

7 2022-01-27 11:42 .winlogon.exe  

5b2d51b6ab2c6225f3ff07b2df5761c0


RAT PWS .NET framework email stealer Generic Malware DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself DNS crashed
1 10.0 M 24 ZeroCERT

8 2021-11-30 11:34 .winlogon.exe  

ce4e0bd7b449f0ac895f24d06e6ef2b8


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key crashed
9.2 M 31 ZeroCERT

9 2021-11-26 09:17 .winlogon.exe  

6b4c344dbefa1c8ccf0f0559231bd51c


PWS .NET framework email stealer Generic Malware Socket DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself malicious URLs Windows ComputerName DNS Cryptographic key crashed
1 11.8 M 30 ZeroCERT

10 2021-11-25 12:19 .winlogon.exe  

f74d638dbfd6af55bd91dbea9144b207


PWS .NET framework Generic Malware AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
5 14 1 9.8 M 28 ZeroCERT

11 2021-11-24 10:18 .winlogon.exe  

48814ee2ed899d145ec99d6d0a7312cb


PWS .NET framework Generic Malware AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
8 20 2 9.8 ZeroCERT

12 2021-03-29 17:54 PO_7201_60_74.pdf  

83c01f327b9dad9768ca0e9703d4e34a


Antivirus AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
5 6 4 3 15.6 M 19 ZeroCERT

  • First
  • 1
  • Last
  • Total : 12cnts