Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8911 2021-04-21 09:36 catalog-2133469391.xlsm  

c08158e8674bb5ef097c64236f0b42aa


Check memory unpack itself Tofsee DNS crashed
2 8 2 3.8 ZeroCERT

8912 2021-04-21 09:36 catalog-349912341.xlsm  

df2938a470a7d5a3194207f5bd91fba8


Check memory unpack itself Tofsee crashed
2 8 2 3.2 ZeroCERT

8913 2021-04-21 09:25 ashleyx.exe  

8bb6b2cd59a316a1b2509a53d9b7bed5


AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software
3 6 4 15.6 M 19 ZeroCERT

8914 2021-04-21 09:22 km.dot  

94c2c8723c5275bbc57c76fca34e94f0

Vulnerability VirusTotal Malware exploit crash unpack itself Tofsee Exploit DNS crashed
2 2 3.8 M 27 ZeroCERT

8915 2021-04-20 16:13 a268e9e152c260a0e80431aa8d6df1...  

a58394937da9d3adb33e948058fde4e9


VBA_macro Vulnerability VirusTotal Malware Malicious Traffic unpack itself Tofsee
5 14 1 5 4.8 M 50 guest

8916 2021-04-20 15:50 setupapp.exe  

73eb70ca5994df6e2766bb5b799f04ec

VirusTotal Malware suspicious privilege WMI unpack itself Tofsee ComputerName DNS
5 16 1 7.0 M 54 ZeroCERT

8917 2021-04-20 09:48 Zzsvkpq.pdf  

542f3ea693d61187bd10db0376a6b3e7


Gen1 AsyncRAT backdoor Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee OskiStealer Stealer Windows Browser Email ComputerName DNS crashed Password
10 5 5 18.0 22 ZeroCERT

8918 2021-04-20 09:46 Zeqenylvg.pdf  

d20d0d39b52c812da0ae519d68aa889b


Gen1 AsyncRAT backdoor Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check installed browsers check Tofsee OskiStealer Stealer Windows Browser Email ComputerName DNS crashed Password
10 5 7 18.2 16 ZeroCERT

8919 2021-04-20 09:42 Iyjomdb_Signed_.xls  

bebcbeef93c5ee64473336c98c6a13c4

VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted RWX flags setting unpack itself Tofsee Interception Windows ComputerName DNS Cryptographic key crashed
1 5 1 11.8 52 ZeroCERT

8920 2021-04-20 09:40 Wvlvhrl.pdf  

149b0568e10ba3994c5c88440221fb2e


Gen1 AsyncRAT backdoor Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Phishing Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check installed browsers check Tofsee OskiStealer Stealer Windows Browser Email ComputerName crashed Password
12 6 7 17.6 18 ZeroCERT

8921 2021-04-20 09:37 Dmdckvjtg.pdf  

46ddcd557521e886e2548e72097e01d6


Gen1 AsyncRAT backdoor Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee OskiStealer Stealer Windows Browser Email ComputerName DNS crashed Password
10 6 6 1 18.0 M 21 ZeroCERT

8922 2021-04-20 09:35 Uekonhzz.pdf  

d4d8ef44275700e1b44a4c82fa18a7e7


AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
3 8 4 14.0 30 ZeroCERT

8923 2021-04-20 09:34 Dtiqyjksq.pdf  

f800c3f06fc079a0b96c979a887c4000


AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
3 7 4 13.2 20 ZeroCERT

8924 2021-04-20 09:31 Hyjgyn.pdf  

1ceae4d45ed09a9ed4d5c392a7654fa9


AsyncRAT backdoor VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows ComputerName crashed
1 3 1 10.6 20 ZeroCERT

8925 2021-04-20 09:29 Famtf.pdf  

a4326b69873c799207e4c9d30c2ed3ac


AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
3 7 4 14.0 19 ZeroCERT