Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2024-07-04 07:36 injector.exe  

509c110ee54d73c3398140a5eb78c45a


NSIS Malicious Library UPX Confuser .NET PE File PE32 .NET EXE VirusTotal Malware Microsoft suspicious privilege Check memory Checks debugger Creates executable files unpack itself AppData folder ComputerName DNS crashed
1 2 5.2 57 ZeroCERT

2 2024-06-20 16:48 DamnedSetup.exe  

c431df16a0810e27345aa37df100a114


Gen1 NSIS Generic Malware Malicious Library UPX Antivirus Malicious Packer Obsidium protector Admin Tool (Sysinternals etc ...) Javascript_Blob Anti_VM PE File PE32 DLL OS Processor Check ftp PE64 VirusTotal Malware suspicious privilege Check memory Creates executable files unpack itself AppData folder Ransom Message Ransomware
4.8 1 ZeroCERT

3 2024-06-10 10:10 loader-1001.exe  

58ca6d5068fa4fed981cf5ef8a04e4d5


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 Pow VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder Tofsee Windows ComputerName Cryptographic key crashed
5 9 1 3 10.2 M 31 ZeroCERT

4 2024-05-20 10:27 start-pub.exe  

52bcb73bddd7e3b613ec7fb1367c91c1


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 P VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key crashed
6 11 3 5 11.2 M 17 ZeroCERT

5 2024-05-19 10:36 vpn-1002.exe  

ccb630a81a660920182d1c74b8db7519


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 PowerS VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key crashed
7 11 3 10.2 24 ZeroCERT

6 2024-05-17 09:30 vpn-1002.exe  

7282845f442c81d8f609bcc1a2853308


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 PowerS VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key crashed
7 12 3 12.4 M 43 ZeroCERT

7 2024-05-03 15:39 loader-1000.exe  

d58a180c5d85448472b4e1007fae4b2a


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 PowerS VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder suspicious TLD WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
6 7 9 11.6 M 22 ZeroCERT

8 2024-04-27 11:58 loader-1000.exe  

705685a8deace858e7fc849471c045f3


NSIS Generic Malware Malicious Library UPX Antivirus PE File PE32 PowerShell DLL OS Processor Check VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
8 8 7 12.0 M 24 ZeroCERT

9 2024-03-17 09:53 vbc.exe  

d7e7cdf137c9d5dfa8d07a6e99d40e98


Malicious Library UPX Admin Tool (Sysinternals etc ...) PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Creates executable files unpack itself AntiVM_Disk suspicious TLD VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software
2 1 10.8 M 51 guest

10 2024-02-29 07:49 DigitalCloud.exe  

f09529be487a02ca6637cdafae71bbcd


Emotet NSIS Generic Malware Malicious Library UPX Malicious Packer Antivirus PE File PE32 PE64 OS Processor Check DLL .NET DLL MZP Format Lnk Format GIF Format VirusTotal Malware AutoRuns Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW human activity check Windows ComputerName crashed
1 2 8.8 M 43 ZeroCERT

11 2024-01-06 10:51 kkm_fix_old.exe  

f12d41a888b7e3fd03c3c5347c6ee778


Malicious Library UPX .NET framework(MSIL) PE32 PE File DLL .NET DLL OS Processor Check PNG Format ftp .NET EXE Lnk Format GIF Format VirusTotal Malware AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder Windows ComputerName
3.8 M 34 ZeroCERT

12 2024-01-02 07:52 kkm_2337.exe  

d176d5132b461760213c52d026b04e08


Malicious Library UPX .NET framework(MSIL) Anti_VM PE32 PE File DLL .NET DLL OS Processor Check PNG Format ftp .NET EXE Lnk Format GIF Format AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder Windows ComputerName
2.8 M ZeroCERT

13 2024-01-02 07:50 kkm_new.exe  

b19b78b10092d1ac185bc35faf8c6efd


Malicious Library UPX .NET framework(MSIL) Anti_VM PE32 PE File DLL .NET DLL OS Processor Check PNG Format ftp .NET EXE Lnk Format GIF Format AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder human activity check Windows ComputerName DNS
1 3.8 M ZeroCERT

14 2024-01-02 07:45 kkm_2245.exe  

8c1279098d87e19ccc488a4b04a77e45


Malicious Library UPX .NET framework(MSIL) PE32 PE File DLL .NET DLL OS Processor Check PNG Format ftp .NET EXE Lnk Format GIF Format VirusTotal Malware AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder Windows ComputerName
3.4 M 17 ZeroCERT

15 2024-01-02 07:44 kkm.exe  

2bd2b08ca47144328cbc68041d8714be


Malicious Library UPX .NET framework(MSIL) Anti_VM PE32 PE File DLL .NET DLL OS Processor Check PNG Format Lnk Format GIF Format .NET EXE ftp VirusTotal Malware AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder Windows ComputerName
3.6 M 28 ZeroCERT