Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8971 2023-10-25 18:27 File.7z  

86f0e6986a754d96179b2c20d8db49b6


PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Cryptocurrency Miner Malware Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Discord Browser Trojan DNS Downloader CoinMiner
80 153 51 29 8.4 M ZeroCERT

8972 2023-10-26 10:40 foto1661.exe  

7613290b26555e6b7b16131d17331960


Amadey RedLine stealer Gen1 Emotet Generic Malware Malicious Library UPX Antivirus .NET framework(MSIL) Confuser .NET Malicious Packer Admin Tool (Sysinternals etc ...) ScreenShot PWS AntiDebug AntiVM PE File PE32 CAB OS Processor Check .NET E Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware powershell Microsoft AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Collect installed applications powershell.exe wrote suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Stealc Stealer Windows Exploit Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed Downloader
25 14 18 6 24.8 40 ZeroCERT

8973 2023-10-26 10:41 HTMLIECachesBrowser.dOC  

a08ca8e6fd0e7002499434aa2547d160


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 4 2 4.0 M 29 ZeroCERT

8974 2023-10-26 10:43 HTMLEVENbrowser.dOC  

8ff3248ebdfa3b7dd737f7bee9b9dae6


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 4 2 4.0 M 29 ZeroCERT

8975 2023-10-26 13:23 eveningFile.vbs  

088dd62ff5ed6d7e15caab5a0bb62f10


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 3 ZeroCERT

8976 2023-10-26 13:23 jajajjajapapapappanananan.vbs  

7e9d44a6c4367491ad178bf62548f136


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 9.0 3 ZeroCERT

8977 2023-10-26 17:12 HTMLcacheIEsession.dOC  

55588a5b96ec028485a99a5bcd648d0e


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware exploit crash unpack itself Tofsee Exploit crashed
2 3 2.8 M 30 ZeroCERT

8978 2023-10-26 17:14 updates_installer.exe  

898cb4fca84ad5e7009d15b2ec04f3a6


UPX Malicious Library Http API ScreenShot Internet API AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check DLL Browser Info Stealer Malware download VirusTotal Malware Cryptocurrency wallets Cryptocurrency PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder sandbox evasion WriteConsoleW installed browsers check Tofsee Ransomware Lumma Stealer Windows Browser ComputerName Firmware Cryptographic key
1 4 4 15.8 34 ZeroCERT

8979 2023-10-26 17:16 pvtHTMLbroswer.dOC  

541a8be00b26a27ed851731d47a0ae31


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
2 4 2 4.2 M 30 ZeroCERT

8980 2023-10-26 17:20 privateexploiteveningFile.vbs  

5dc2c5a74a18f3b1e8d24101e8bac3cc


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 1 ZeroCERT

8981 2023-10-26 17:21 HTMLcachesIE.vbs  

b70068430fab03962b3fe2d15588c894


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 1 ZeroCERT

8982 2023-10-26 17:22 VIBINVES.vbs  

0b92e010b599dc8280e4ab32c1ed02ed


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 9.0 2 ZeroCERT

8983 2023-10-27 10:13 obuxu.vbs  

136abae59cb3eb697de1c5e20778ecd6


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 9.0 2 ZeroCERT

8984 2023-10-27 10:13 ereeeeeeeeeeeefereFile.vbs  

73d2fd40cb82f20bb3d340720da666d0


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 3 ZeroCERT

8985 2023-10-27 10:54 bdolsx.vbs  

44c457dd13efcd6622b1b6dbab5c1965

VirusTotal Malware buffers extracted wscript.exe payload download Tofsee
1 2 2 3.0 M 5 ZeroCERT