Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8896 2023-10-16 18:35 Roblox_Level_4_Exploit.exe  

01af0cd59dfa4e45fc8cb5d9ecbd6de3


Generic Malware PE File PE32 .NET EXE VirusTotal Malware Malicious Traffic Check memory Checks debugger Creates executable files unpack itself AppData folder Tofsee ComputerName
1 2 2 4.0 39 ZeroCERT

8897 2023-10-16 18:36 setup-lightshot.exe  

416c97ae7efb1385cf83a5fd277e68ee


Generic Malware PE File PE32 .NET EXE VirusTotal Malware Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Tofsee ComputerName
1 2 2 3.6 39 ZeroCERT

8898 2023-10-16 18:44 sihost.exe  

0855867efc0b10ff80a9237b8ee9ba3d


.NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Browser Email ComputerName Software crashed
2 2 11.0 24 ZeroCERT

8899 2023-10-17 07:44 pqAlGyUFhqdKYsx.exe  

991a0243b129e2086d31127247f0c630


LokiBot Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer powershell PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 12.0 ZeroCERT

8900 2023-10-17 09:43 artwork.hta  

b3a69d39ea2f074e520077721b475d51


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
2 3 2 10.6 26 ZeroCERT

8901 2023-10-17 10:07 555.bat  

758138cf292edc7fc200b8853a34dce3


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
2 3 4 2 11.6 M 1 ZeroCERT

8902 2023-10-17 10:12 test.pdf.url  

ff6018379580a0f672c47e2051e514fa


AntiDebug AntiVM Malware download VirusTotal Malware powershell Code Injection Malicious Traffic RWX flags setting exploit crash unpack itself Windows utilities Tofsee RedCurl Windows Exploit DNS crashed
1 1 4 1 4.6 M 4 ZeroCERT

8903 2023-10-17 10:18 xxx.vbs  

8565f26c1e4435a5645fee07d989e418


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 1 ZeroCERT

8904 2023-10-17 10:19 HJGHJGHJJGFile.vbs  

5ccfeb1c2b9afa98577b2d633b4b1166


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 1 ZeroCERT

8905 2023-10-17 10:52 at.hta  

b3a69d39ea2f074e520077721b475d51


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
1 3 2 1 12.4 M 26 ZeroCERT

8906 2023-10-17 16:28 Archive.7z  

14cf80a7fd8a77c3eaed98b8ec615eb4


Stealc PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Kelihos Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS plugin
56 80 54 21 6.4 M ZeroCERT

8907 2023-10-17 16:40 Ermnnolfu.exe  

7ba214f8174004943d83942dda0f9731


Downloader UPX PWS KeyLogger Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential Sniff Audio HTTP DNS Code injection Internet API FTP P2P AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 4 1 14.4 48 ZeroCERT

8908 2023-10-17 16:42 bQGy.exe  

a60c2e8459387329e1dbe2d3625ee2c8


PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee crashed
1 3 1 3.8 55 ZeroCERT

8909 2023-10-17 17:01 Setup.7z  

72cbddd810e52a32ffed4a5db1faeb1d


Stealc PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself IP Check PrivateLoader Tofsee Stealc Stealer Windows RisePro Trojan DNS
47 75 40 19 6.0 M ZeroCERT

8910 2023-10-18 07:53 ezy.exe  

68cf6b4b568cc8bcbfe7dc53607f0c90


LokiBot .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 10.2 M ZeroCERT