Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8926 2023-10-19 10:49 himeffectivelyproress.exe  

fa9494dcb5bd42e61e89231dfc8eb0da


Gen1 Emotet Malicious Library UPX AntiDebug AntiVM PE File PE64 CAB PE32 .NET EXE OS Processor Check PNG Format MSOffice File JPEG Format VirusTotal Malware AutoRuns PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces AppData folder Tofsee Windows Exploit Remote Code Execution DNS crashed
1 3 4 1 10.2 M 22 ZeroCERT

8927 2023-10-19 18:27 sevenththththththth.vbs  

f9145a219ca855c79279b94e9b902068


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.6 4 ZeroCERT

8928 2023-10-19 18:28 westartagain.vbs  

a19e87eb4cfc892ad7ccf43fd3a2a114


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.6 3 ZeroCERT

8929 2023-10-19 18:28 gfhdsggssdgfsFile.vbs  

50530ad3f7a59a70e2ad275d8eca6e34


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.6 5 ZeroCERT

8930 2023-10-19 18:42 HTMLcache8.dOC  

2b81d6d754937ab82947a76d395df643


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic exploit crash Tofsee Exploit DNS crashed
1 3 2 3.6 M 29 ZeroCERT

8931 2023-10-20 07:31 newumma.exe  

dfd00cebfa70ea1470514e2c03770fd4


Malicious Library UPX Malicious Packer AntiDebug AntiVM PE File PE32 OS Processor Check PE64 Malware download Amadey Cryptocurrency Miner Malware AutoRuns PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Kelihos Tofsee Windows ComputerName DNS CoinMiner
4 13 10 3 12.6 M ZeroCERT

8932 2023-10-20 07:32 truever0510dn.exe  

93556130a3846a62780b2b331cd19ea0


Gen1 Generic Malware Malicious Library UPX Admin Tool (Sysinternals etc ...) Malicious Packer Anti_VM PE File PE32 CAB OS Processor Check PE64 DLL ftp DllRegisterServer dll PNG Format Malware PDB Malicious Traffic Check memory buffers extracted Creates executable files unpack itself Tofsee ComputerName DNS
1 7 2 3.4 M ZeroCERT

8933 2023-10-20 09:26 HTMLincache.doc  

0f8b57f118a80ad75a56a9bb3f1206ea


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
1 3 2 4.0 M 28 ZeroCERT

8934 2023-10-20 16:35 a3.jpg.exe  

ca0299d9cfce19b30bedc50656f16983


AsyncRAT UPX Malicious Packer .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check Malware download AsyncRAT NetWireRC Malware DNS DDNS
2 4 0.4 ZeroCERT

8935 2023-10-20 17:36 lllllillilililiil.vbs  

c22b3eab9a5dbb2ac744e6d3c683bc30


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.6 7 ZeroCERT

8936 2023-10-20 18:12 Setup.7z  

72b145dcb4456a0892b5b725eec5d1b4


Stealc Vidar PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Discord Browser RisePro Trojan DNS Downloader
68 127 56 36 7.8 M ZeroCERT

8937 2023-10-20 18:34 setup2.7z  

3735adf80a188c2b01494f4c914ad709


Stealc Vidar PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Dridex VirusTotal Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader
60 116 52 39 7.4 M 1 ZeroCERT

8938 2023-10-23 09:31 HTMLcachies.dOC  

e8277a6ee73ffeb63f76e8343e1ac5e4


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 3 2 4.2 M 34 ZeroCERT

8939 2023-10-23 12:18 abyx.vbs  

a4b27b7143e37f8c1c3d038e22fab7e5


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 8.8 17 ZeroCERT

8940 2023-10-23 12:18 droidwednesdayyyFile.vbs  

c6cc9287c08464bfe297be623543d72d


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 8.6 4 ZeroCERT