Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2021-09-12 14:56 ptl_062540167003231.exe  

7e016097a1123f48ba3d36b09b626190


RAT PWS .NET framework Generic Malware UPX Antivirus AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic RWX flags setting unpack itself powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key crashed
2 13.4 M 31 ZeroCERT

2 2021-09-08 10:15 BLT-7501033098.exe  

391130ad385ed32583fd74ab73bb6c8e


PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic RWX flags setting unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key crashed
3 11.8 M 24 ZeroCERT

3 2021-09-08 10:09 DLT_85620000107.exe  

18ca3863bfd1ea32400b29d56e2fdf1f


PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key crashed
8 13 1 13.0 14 ZeroCERT

4 2021-09-08 09:58 rrrem.exe  

c4ffb0ae8bc377ff6062360971fb1037


AgentTesla RAT PWS .NET framework browser info stealer Generic Malware Google Chrome User Data UPX Antivirus Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection Downloader AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic unpack itself powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
11 14.4 M 17 ZeroCERT

5 2021-09-08 09:56 BLT-750108002.exe  

4e3f9aaa521bd82e3b2902d528e51685


RAT PWS .NET framework Generic Malware UPX Antivirus AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic RWX flags setting unpack itself powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key crashed
10 12.2 M 28 ZeroCERT

6 2021-09-08 09:56 IMG_80350001.exe  

f88fe2ffbc0ac8b13baa8cdcb55bab28


RAT PWS .NET framework Generic Malware UPX Antivirus AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic RWX flags setting unpack itself powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key crashed
10 12.4 M 34 ZeroCERT

7 2021-09-08 09:46 TLH_110503078801.exe  

6f8bb2ff11646a8e47c1b2a27d475010


PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware powershell Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut ICMP traffic RWX flags setting unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key crashed
3 12.0 M 31 ZeroCERT

  • First
  • 1
  • Last
  • Total : 7cnts