Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8926 2021-04-20 09:28 invoice_115521.doc  

10ea6889fd7ca096c9b307b276a03b99


LokiBot Malware download VirusTotal Malware c&c Malicious Traffic exploit crash unpack itself Tofsee Windows Exploit Trojan DNS crashed
2 7 12 4.8 M 29 ZeroCERT

8927 2021-04-20 09:26 zuPrmTisZ3pMewf.exe  

93675693e8fcb6b339a5529f49fadf6f


VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS crashed
4 5 4 14.6 M 32 ZeroCERT

8928 2021-04-20 09:23 g1mrfi.rar  

340994098deb6bf6fa91f73350af7c15


Gen2 Gen1 VirusTotal Malware PDB Malicious Traffic unpack itself Tofsee Windows DNS crashed
3 2 4 3.2 8 ZeroCERT

8929 2021-04-20 09:05 catalog-1301901571.xlsm  

b7a0b0ca21ea1ec602751681d5c60b11

Check memory unpack itself Tofsee DNS crashed
6 2 3.4 ZeroCERT

8930 2021-04-20 09:04 catalog-1321576138.xlsm  

0b6cef78cf09fe70881452faab47918f

Check memory unpack itself Tofsee crashed
6 2 2.8 ZeroCERT

8931 2021-04-20 09:03 catalog-1356110994.xlsm  

8b7f402856f3d80cb0d041a26f35ec99

Check memory unpack itself Tofsee DNS crashed
6 2 3.4 ZeroCERT

8932 2021-04-20 09:02 catalog-134300255.xlsm  

c1bbead8915e662c20f05437a1966028

Check memory unpack itself suspicious TLD Tofsee crashed
6 2 3.2 ZeroCERT

8933 2021-04-20 07:49 Pvcjjru.exe  

6581f25476a8e4009877ba7498489ef6


Gen1 AsyncRAT backdoor Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check installed browsers check Tofsee OskiStealer Stealer Windows Browser Email ComputerName crashed Password
9 5 6 1 19.4 M 23 ZeroCERT

8934 2021-04-20 07:41 Ddsfrkgc.pdf  

764abd8daf6dddba262e3bbae25fdbf5


AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
3 8 4 14.2 22 ZeroCERT

8935 2021-04-20 07:39 Nnojr.exe  

0223c7c933d538790ea29c9975490088


PWS .NET framework Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 13.2 21 ZeroCERT

8936 2021-04-19 13:53 a268e9e152c260a0e80431aa8d6df1...  

a58394937da9d3adb33e948058fde4e9


VBA_macro Vulnerability VirusTotal Malware Malicious Traffic unpack itself Tofsee
14 1 4.8 M 50 guest

8937 2021-04-19 10:22 a268e9e152c260a0e80431aa8d6df1...  

a58394937da9d3adb33e948058fde4e9


VBA_macro Vulnerability VirusTotal Malware Malicious Traffic unpack itself Tofsee
14 1 4.8 M 50 r0d

8938 2021-04-18 10:36 a268e9e152c260a0e80431aa8d6df1...  

a58394937da9d3adb33e948058fde4e9

Vulnerability VirusTotal Malware Malicious Traffic unpack itself Tofsee
14 1 4.8 M 50 guest

8939 2021-04-17 10:24 catalog-342909133.xlsm  

2f6bd277a917a4bca6216444ecbc1d62

ICMP traffic unpack itself Tofsee DNS
1 10 2 4.2 M ZeroCERT

8940 2021-04-17 10:22 catalog-323305862.xlsm  

fcb2af95d2b6abd32e4886d302b207aa

Check memory unpack itself Tofsee crashed
1 9 2 3.2 M ZeroCERT