Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9166 2023-12-13 17:11 Microsoftdecidedtoupdateentire...  

abd08657ab33f8d1fb76b2757c0253b2


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 4 2 4.6 M 35 ZeroCERT

9167 2023-12-13 17:22 microsoftdecided.vbs  

191f2509a2a2ee5ca560be4cf1baccd7


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 5 ZeroCERT

9168 2023-12-13 17:22 microsoftcachedelete.vbs  

a69d043d32d4ac372b3901a54dc231d9


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 5 ZeroCERT

9169 2023-12-13 18:26 microsoftdecidedtoupdateentire...  

911181c9ce56b902706424dfcc600236


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash Tofsee Windows Exploit DNS crashed
1 3 7 4.2 M 34 ZeroCERT

9170 2023-12-14 08:00 abux.exe  

34793ade11411172d60e1eacf6c92bfd


AgentTesla .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs suspicious TLD Tofsee Browser Email ComputerName DNS Software crashed
1 3 3 13.4 M 45 ZeroCERT

9171 2023-12-14 08:04 PC_Cleaner.exe  

84326112ddead59fca719ef1d7d87685


Emotet Sality Generic Malware Malicious Library UPX Antivirus Admin Tool (Sysinternals etc ...) Anti_VM PE32 PE File ftp MZP Format OS Processor Check Lnk Format GIF Format DllRegisterServer dll URL Format DLL PE64 BMP Format Browser Info Stealer VirusTotal Malware Check memory Checks debugger Creates shortcut Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder AntiVM_Disk anti-virtualization VM Disk Size Check installed browsers check Tofsee Browser ComputerName DNS crashed
1 9 2 8.4 M 11 ZeroCERT

9172 2023-12-14 10:28 ORDER-232112.pdf.js  

ad919f29a6186c40a5bcb76d18803bfb

VirusTotal Malware VBScript wscript.exe payload download Tofsee Dropper
1 2 2 10.0 24 ZeroCERT

9173 2023-12-14 10:28 ORDER-232111.pdf.js  

ad919f29a6186c40a5bcb76d18803bfb

VirusTotal Malware VBScript wscript.exe payload download Tofsee Dropper
1 2 2 10.0 24 ZeroCERT

9174 2023-12-14 10:29 ORDER-231211.Xls.js  

516442412f0c621f39abd64b645f587c

VirusTotal Malware VBScript wscript.exe payload download Tofsee Dropper
1 2 2 10.0 22 ZeroCERT

9175 2023-12-14 19:14 agent.exe  

ca2de368c8a4930ce09986cd9f9f2280


Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware MachineGuid unpack itself Tofsee ComputerName
2 1 1.6 M 15 ZeroCERT

9176 2023-12-15 16:22 128.5.14-package.hta  

715d2502c51eddfd399a63042a259634


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3.8 ZeroCERT

9177 2023-12-15 17:45 release.rar  

57ab5e01e6e92d13ae33e587004ad918


Stealc PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Vidar Glupteba Open Directory Malware c&c Microsoft suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Discord Exploit Browser RisePro DNS Downloader plugin
62 75 62 12 7.6 M ZeroCERT

9178 2023-12-18 07:55 updater.exe  

6f0e94c80d8b9c98ea75bff456eff5a2


Gen1 Generic Malware UPX Antivirus Malicious Library PE32 PE File ftp DLL PE64 OS Processor Check ZIP Format Cryptocurrency Miner Malware Cryptocurrency powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key CoinMiner
1 7 3 1 6.6 M ZeroCERT

9179 2023-12-18 09:46 microsoftdecidedtodeleteentire...  

066232099ba8df43942395e4ebfa39a2


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Windows Exploit DNS crashed
1 3 7 4.6 M 34 ZeroCERT

9180 2023-12-18 09:55 Microsoftupgradedtechnologytoe...  

27447785fd8cb3c3f48f90e09a0c15c2


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
3 6 3 4.6 M 33 ZeroCERT