Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8806 2021-05-21 10:14 Document%209863223.xls  

a3770e810232a6e15b4fd36a444ef8d4


VBA_macro MSOffice File VirusTotal Malware unpack itself Tofsee
2 20 2 2 3.2 M 21 ZeroCERT

8807 2021-05-21 10:09 Doc1.docm  

53e6579c2aad2ae7d6a3ce99045a114b


VBA_macro VirusTotal Malware unpack itself Tofsee DNS
1 2 3 4.2 M 32 ZeroCERT

8808 2021-05-20 16:39 invoice_996451.doc  

bee4631c31d5682a91174ee18d7c9335


RTF File doc VirusTotal Malware exploit crash unpack itself Tofsee Exploit DNS crashed
1 2 1 3.6 M 27 ZeroCERT

8809 2021-05-20 16:36 Inv%2006687243.xls  

5186a21d30bbf28909683c4767597481


VBA_macro MSOffice File VirusTotal Malware unpack itself Tofsee DNS
12 20 2 4.8 M 24 ZeroCERT

8810 2021-05-20 16:36 PO%2068601112.xls  

c389608ec63d30c2d36486bd7db8668f


VBA_macro MSOffice File VirusTotal Malware unpack itself Tofsee
12 20 2 3.2 M 27 ZeroCERT

8811 2021-05-20 16:34 Delivery%20Order%208323673.xls  

4100f7280e2ec85db09ee5e67b15b9dd


VBA_macro MSOffice File VirusTotal Malware unpack itself Tofsee DNS
6 4 2 4.0 M 30 ZeroCERT

8812 2021-05-20 10:09 H2AymTOp.txt  

6281865f1e7a60eca71ecce24d777c59


AsyncRAT backdoor PWS .NET framework DNS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware Buffer PE suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW human activity check Tofsee Windows ComputerName DNS DDNS
1 5 2 15.8 M 21 ZeroCERT

8813 2021-05-20 10:01 Delivery%20Order%2035933112.xl...  

5c1384a9073d57a8dcd0321d3f6a712c


VBA_macro MSOffice File VirusTotal Malware Checks debugger WMI unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Windows ComputerName DNS crashed
3 4 2 8.0 M 23 ZeroCERT

8814 2021-05-20 09:38 5.exe  

9e0637d40ac3dfd9fed6e63763394d96


Gen1 Gen2 PE File OS Processor Check PE32 DLL JPEG Format VirusTotal Email Client Info Stealer Malware MachineGuid Malicious Traffic Check memory buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser Email ComputerName DNS
4 3 4 9.2 46 ZeroCERT

8815 2021-05-20 09:34 Delivery%20Order%2026947238.xl...  

c245d6f79bca2e8e87381a68b842c4d2


VBA_macro MSOffice File VirusTotal Malware unpack itself Tofsee
10 20 2 3.0 M 19 ZeroCERT

8816 2021-05-19 17:34 testvba.dotm  

de000aa60d73ab904fe119294741e5c4


VBA_macro VirusTotal Malware Creates executable files unpack itself Tofsee
2 2 3.4 M 25 ZeroCERT

8817 2021-05-19 13:45 1.exe  

296546fc0093734f42dfa96729643b86


Anti_VM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Firmware DNS Cryptographic key Software crashed
2 3 2 10.0 M 28 ZeroCERT

8818 2021-05-18 17:58 diagram-1596364538.xls  

a3b0860623b4c70ff15d97fa2df88662


MSOffice File Check memory unpack itself Tofsee DNS crashed
2 2 2.6 guest

8819 2021-05-18 09:57 CBCbrowser.exe  

5cdf8ce1bcc26bf8473f09447cfa0c47


AsyncRAT backdoor PWS .NET framework BitCoin AntiDebug AntiVM .NET EXE PE File PE32 MSOffice File Browser Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic RWX flags setting exploit crash unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious TLD installed browsers check Tofsee Windows Exploit Browser ComputerName DNS Cryptographic key crashed
5 8 2 12.8 M ZeroCERT

8820 2021-05-18 09:56 diagram-58392516.xls  

3e58b8987074c6d6b6725e2cbdb0494d


MSOffice File VirusTotal Malware Check memory unpack itself Tofsee crashed
5 8 2 3.0 15 guest