Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10141 2024-06-24 15:51 pumairld.txt.ps1  

19a7f5e2e7fd8e14d8129dcdf6c8b992


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows Discord ComputerName DNS Cryptographic key
2 3 8.4 17 ZeroCERT

10142 2024-06-25 02:50 http://l.instagram.com/?235901...  


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
3 3 2 4.2 guest

10143 2024-06-25 05:28 https://l.instagram.com/?23590...  


AntiDebug AntiVM PNG Format MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3 1 3.8 guest

10144 2024-06-25 05:29 https://business.instagram.com...  


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PNG Format MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 2 2 4.8 guest

10145 2024-06-25 05:29 http://l.instagram.com/?235901...  


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
3 3 2 4.2 guest

10146 2024-06-25 07:44 ExtExport2.exe  

901a623dbccaa22525373cd36195ee14


Suspicious_Script_Bin UPX PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces IP Check installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 8 8 9.4 M 40 ZeroCERT

10147 2024-06-25 07:57 Main.exe  

9ec7f08c85bfa1b267761f225b68ab0b


Malicious Library Antivirus UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram MachineGuid Malicious Traffic WMI Tofsee ComputerName DNS crashed
2 5 3 6.2 M 61 ZeroCERT

10148 2024-06-25 09:12 notorious.doc  

2d1b096a33d1b673fd06db9f3e861761


MS_RTF_Obfuscation_Objects RTF File doc RedLine Malware download VirusTotal Malware RWX flags setting exploit crash suspicious TLD IP Check Tofsee Stealer Exploit Browser DNS crashed
3 10 9 4.8 M 27 ZeroCERT

10149 2024-06-26 10:13 nelb.doc  

6b9167056af49bf702c833ae4f581ef1


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself suspicious TLD Tofsee Exploit DNS crashed
4 9 4 4.4 M 33 ZeroCERT

10150 2024-06-26 10:16 build.exe  

71b44c9a55f3b40681f6a5524ca9821d


[m] Generic Malware Generic Malware Suspicious_Script_Bin task schedule Malicious Library UPX Socket DGA Http API ScreenShot PWS DNS Internet API AntiDebug AntiVM PE File PE32 OS Processor Check Malware download Dridex VirusTotal Malware Microsoft AutoRuns Code Injection Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities AppData folder malicious URLs WriteConsoleW Tofsee Windows ComputerName Remote Code Execution DNS
3 6 9 13.2 M 47 ZeroCERT

10151 2024-06-26 10:18 a.f.f.f.f.fff.doc  

6476133e6fcd5bb5fad7d39d1d214a6a


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 5 2 5.0 M 36 ZeroCERT

10152 2024-06-26 10:36 av_downloader1.1.exe  

759f5a6e3daa4972d43bd4a5edbdeb11


Generic Malware Malicious Library Malicious Packer UPX Antivirus AntiDebug AntiVM PE File PE32 MSOffice File PNG Format JPEG Format VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Disables Windows Security powershell.exe wrote suspicious process Tofsee Windows Exploit ComputerName DNS Cryptographic key crashed
2 1 12.4 M 57 ZeroCERT

10153 2024-06-27 04:33 https://t.co/J5c3B3lHDS  

a447b2274aa6e2ebdb080e3def9263db


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PNG Format MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 2 4.2 guest

10154 2024-06-27 10:05 b.j.c.c.cc.doc  

809e5331e9ead88825e560d3077cb6da


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 5 3 5.0 M 32 ZeroCERT

10155 2024-06-27 10:11 vi.exe  

baa9e1a92bab85279dca0aed641f1fa9


Malicious Library Antivirus UPX PE File PE32 OS Processor Check VirusTotal Malware Malicious Traffic Tofsee crashed
1 4 1 3.4 M 52 ZeroCERT