Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9286 2024-01-26 09:13 rost.exe  

03135ee6d7c5c029982e63d36d368267


Themida Packer Malicious Packer UPX PE32 PE File Malware download VirusTotal Malware AutoRuns MachineGuid unpack itself Windows utilities suspicious process WriteConsoleW IP Check Tofsee Windows RisePro ComputerName DNS crashed
2 7 4 7.2 M 38 ZeroCERT

9287 2024-01-26 09:28 somzx.exe  

e899fbf28973beed105f99e209e11be5


AgentTesla Malicious Library .NET framework(MSIL) UPX PWS KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Discord Browser Email ComputerName DNS Software crashed keylogger
1 4 6 14.0 M 40 ZeroCERT

9288 2024-01-26 12:11 vnextofficeupdationwaitingfort...  

869dc88123916a7193c56809db6b5e97


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself IP Check Tofsee Windows Exploit DNS crashed
1 3 9 5.0 M 32 ZeroCERT

9289 2024-01-26 12:11 currentupdationoftheexplertsay...  

bfc3ef7d2fa438d76b535b0410fe1296


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
3 3 3 4.6 M 31 ZeroCERT

9290 2024-01-26 12:13 ibmSever.vbs  

bb9a31982bd53b29cc81e3027709727b

VirusTotal Malware wscript.exe payload download Tofsee
2 2 2 2.6 M 3 ZeroCERT

9291 2024-01-27 15:59 ISIcentos.vbs  

860f242d1a6e895bbd7c2c204c466511

VirusTotal Malware wscript.exe payload download Tofsee
2 2 2 2.6 M 4 ZeroCERT

9292 2024-01-27 16:00 hotels.exe  

77709112275d51ebd4d9491673c93a62


.NET framework(MSIL) UPX Malicious Library Socket ScreenShot Steal credential DNS Code injection AntiDebug AntiVM PE32 PE File .NET EXE DLL OS Processor Check PNG Format ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Buffer PE AutoRuns PDB MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 5 7 19.0 25 ZeroCERT

9293 2024-01-27 16:10 amers.exe  

a2694e00b509f5192ab406b4c4dbd5d4


Amadey RedLine Infostealer RedlineStealer RedLine stealer UltraVNC Generic Malware NSIS UPX Malicious Library Antivirus Admin Tool (Sysinternals etc ...) .NET framework(MSIL) Malicious Packer Anti_VM AntiDebug AntiVM PE32 PE File PNG Format OS Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Email Client Info Stealer Cryptocurrency Miner Malware Cryptocurrency wallets Cryptocurrency Microsoft AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Disables Windows Security Collect installed applications Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization IP Check VM Disk Size Check human activity check installed browsers check Tofsee Ransomware Stealer Windows Update Exploit Browser RisePro Email ComputerName DNS Cryptographic key Software crashed Downloader CoinMiner
24 26 25 11 25.6 M ZeroCERT

9294 2024-01-28 10:00 ko.exe  

f7942f50665070dee333d0df2bebc4c6


Generic Malware Malicious Library UPX Code injection AntiDebug AntiVM PE32 PE File OS Processor Check MSOffice File Browser Info Stealer VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself Windows utilities malicious URLs installed browsers check Tofsee Ransomware Windows Exploit Browser DNS crashed
8 6 1 10.4 16 ZeroCERT

9295 2024-01-28 10:01 ORDEN_EMBARGO.js  

7874b7e03b57bb11f63f6a0904f51296


Generic Malware Antivirus ActiveXObject VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.0 9 ZeroCERT

9296 2024-01-28 10:02 neweraroc.exe  

796f63c42ca69a07ce61a45fcbed1c8d


Generic Malware NSIS Malicious Library UPX Antivirus Admin Tool (Sysinternals etc ...) Malicious Packer Anti_VM PE32 PE File .NET EXE PNG Format OS Processor Check PE64 ZIP Format MZP Format JPEG Format BMP Format ftp CHM Format DLL icon CAB MSOffice Fi VirusTotal Cryptocurrency Miner Malware AutoRuns Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Ransomware Windows ComputerName DNS CoinMiner
2 7 7 2 11.6 M 51 ZeroCERT

9297 2024-01-28 10:05 360TS_Setup_Mini_WW.Ginmobi.CP...  

3016285c9eb979ba1703d25012457567


HermeticWiper PhysicalDrive Generic Malware Malicious Library Malicious Packer Downloader UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges PWS Internet API AntiDebug AntiVM PE32 PE File CAB OS Processor Check DLL DllRegiste VirusTotal Malware PDB Check memory Creates executable files ICMP traffic unpack itself AppData folder malicious URLs AntiVM_Disk China anti-virtualization VM Disk Size Check Tofsee Windows Remote Code Execution DNS keylogger
8 22 5 8.6 3 ZeroCERT

9298 2024-01-29 08:00 vinu.exe  

b999d160106e9c1cc130e81cb65cb6c1


Malicious Packer Anti_VM PE32 PE File Malware download Malware AutoRuns MachineGuid unpack itself Windows utilities suspicious process WriteConsoleW IP Check Tofsee Windows RisePro ComputerName DNS crashed
2 12 6 5.6 M ZeroCERT

9299 2024-01-29 08:02 btcgood.exe  

52457d397f4d5abc4d9de5dc74fd42c5


Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check Browser Info Stealer Malware download Email Client Info Stealer Malware Check memory buffers extracted Creates shortcut unpack itself Collect installed applications IP Check installed browsers check Tofsee Browser Email ComputerName Trojan Banking DNS
3 6 9.8 M ZeroCERT

9300 2024-01-29 08:02 plata.exe  

7c36240fbc9b608d4847cbaedf7f031a


Malicious Packer UPX PE32 PE File Malware download Malware AutoRuns MachineGuid unpack itself Windows utilities suspicious process WriteConsoleW IP Check Tofsee Windows RisePro ComputerName DNS crashed
2 7 4 6.2 ZeroCERT