Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8896 2021-04-23 09:59 catalog-1605517361.xlsm  

bf83672739e7a17d2851279684a73ad0


Check memory unpack itself Tofsee DNS crashed
4 2 3.4 ZeroCERT

8897 2021-04-23 09:59 catalog-1605179562.xlsm  

082645e6b13d4cdd417b3d82c15a8c83


Check memory unpack itself Tofsee crashed
4 2 2.8 ZeroCERT

8898 2021-04-23 09:55 catalog-1604441556.xlsm  

414c41ce670225a38e8c4aeda37df315


Check memory unpack itself Tofsee DNS crashed
4 2 3.4 ZeroCERT

8899 2021-04-23 09:54 catalog-1600996489.xlsm  

aae89be1368bd7f31a17df732c50520c


Check memory unpack itself Tofsee crashed
4 2 2.8 ZeroCERT

8900 2021-04-22 18:25 IMG_10540078520047.pdf.exe  

0584b79b0075099a377c30ffa0bfee28


KeyBase Keylogger Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.4 M 17 r0d

8901 2021-04-22 17:23 melo.jpg.exe  

82b9be6f5cc10510495e9a3368683747


Process Kill FindFirstVolume CryptGenKey Antivirus VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
5 5 3 13.4 M 19 ZeroCERT

8902 2021-04-22 17:15 IMG_10540078520047.pdf.exe  

0584b79b0075099a377c30ffa0bfee28

Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.4 M 17 ZeroCERT

8903 2021-04-22 13:39 DLI_0251_053_021.pdf  

873fc3f0fdfae3505a3de1bca97e40f9


AgentTesla Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.6 M 21 r0d

8904 2021-04-22 10:51 DLI_0251_053_021.pdf  

873fc3f0fdfae3505a3de1bca97e40f9

Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.6 M 21 ZeroCERT

8905 2021-04-22 09:53 file.rtf  

9ca89139d0918e5078122113fc883a7e


RTF File doc Malware Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit crashed
3 2 1 3.0 M r0d

8906 2021-04-22 07:29 file.rtf  

9ca89139d0918e5078122113fc883a7e

Malware Malicious Traffic buffers extracted unpack itself Tofsee
8 4 1 2.8 ZeroCERT

8907 2021-04-21 13:58 https://prestasicash.com.ar/er...  

223975e6f03f5cc32074a00e82f8cf99

VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 2 4.8 guest

8908 2021-04-21 10:36 CamLiveSetup1.0.0.exe  

82ab12bcd6402e68ae9b1e3cff33699c


Emotet Gen1 VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder Tofsee Windows Exploit DNS crashed
56 22 2 6.2 14 ZeroCERT

8909 2021-04-21 09:39 catalog-532402110.xlsm  

3c783f26d920978c063be2e392954da0

Check memory unpack itself Tofsee DNS crashed
2 8 2 3.8 ZeroCERT

8910 2021-04-21 09:38 catalog-334041965.xlsm  

8d70ebc40f4fdc94aaf8744bdc7879b0

Check memory unpack itself Tofsee crashed
2 8 2 3.2 ZeroCERT