Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8716 2021-06-08 10:44 BTQbrowser.exe  

b12fbbf68290508b870ea4f9d38a25b4


AsyncRAT backdoor PWS .NET framework BitCoin AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious TLD Tofsee Windows DNS Cryptographic key
1 4 1 10.6 28 ZeroCERT

8717 2021-06-08 10:22 BLI_057702308.exe  

6f86775cd014c339e3c8b25563fd51d9


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 10.0 M 26 ZeroCERT

8718 2021-06-08 10:14 RFL_0570103064.exe  

ea5b036e25672815c17e85213586f118


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 10.0 M 22 ZeroCERT

8719 2021-06-08 10:12 IMG_0001_205_60_37.exe  

c222dad25c8ba8ab2af48692ad261bcf


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 10.0 M 27 ZeroCERT

8720 2021-06-08 10:10 RFL_0731_60_127.exe  

52757942734a95026f4499e2747f8007


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 10.0 M 23 ZeroCERT

8721 2021-06-08 10:07 BLI_0610_36_31.exe  

a8ad861ef6877f243bdfbb00ddf2f37b


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 10.4 M 40 ZeroCERT

8722 2021-06-08 10:06 IMG_52_67_21_33.exe  

becc9c4709bbee070275cd42acfc02c9


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 9.4 M 23 ZeroCERT

8723 2021-06-08 10:05 9011.exe  

ed4a90d8b23e1ca80bb595a9d9630be8


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 5 4 10.2 M 30 ZeroCERT

8724 2021-06-08 10:03 RFT_056_17_30_81.exe  

c1f2b32fc6c1f69190516de627f9fa43


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 14.6 M 34 ZeroCERT

8725 2021-06-08 10:02 BLI_0617851034.exe  

5346c6935008b47b700b97482463099c


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.2 M 22 ZeroCERT

8726 2021-06-08 10:00 BTL_01880433.exe  

bdccbcaabf832a0a2b0f74afcc3ba8a1


SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 4 4 10.0 M 21 ZeroCERT

8727 2021-06-08 09:55 br.exe  

1c85f40e4abe47f93982099c8d9753c1


AsyncRAT backdoor PWS .NET framework Anti_VM Malicious Library DGA DNS SMTP Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection Internet API ScreenShot Downloader AntiDebug AntiVM PE File .NET EXE PE32 Malware download NetWireRC VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Ransomware BitRAT Windows ComputerName DNS Cryptographic key keylogger
1 1 13.4 M 40 ZeroCERT

8728 2021-06-08 09:32 dootakim.vbs  

7bf15c10dd4e523a1338d054c0ace9d9

Malware Malicious Traffic buffers extracted WMI wscript.exe payload download Creates shortcut Creates executable files ICMP traffic Tofsee Windows ComputerName DNS
2 4 2 6.8 M ZeroCERT

8729 2021-06-08 09:16 https://smyun0272.blogspot.com...  

aea34c0a7532eeebd2f9d29b312ef6a0


AntiDebug AntiVM PNG Format JPEG Format MSOffice File Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
20 16 2 4.2 ZeroCERT

8730 2021-06-08 09:04 vbc.exe  

5313f320a680a992243c59f38561ba9a


PWS .NET framework Admin Tool (Sysinternals Devolutions inc) Malicious Library DNS Socket Sniff Audio KeyLogger Code injection AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key keylogger
2 4 1 12.6 16 ZeroCERT