Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10201 2024-07-05 11:13 software.exe  

1ed6f9d578e14edad0bf47edf1f6269f


Vidar Client SW User Data Stealer LokiBot RedLine stealer ftp Client info stealer Malicious Library .NET framework(MSIL) UPX ASPack Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
3 5 3 1 16.4 32 ZeroCERT

10202 2024-07-05 14:54 sostener.vbs  

c45cccf34e0483bbb46f55d04ccb781b


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware VBScript powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process Tofsee Windows ComputerName DNS Cryptographic key Dropper
3 3 2 10.0 M 7 ZeroCERT

10203 2024-07-05 15:01 Scandoc1114.exe  

1028a0939cb0ce3475e93dcab08ebba8


Process Kill Generic Malware Suspicious_Script_Bin Malicious Library FindFirstVolume CryptGenKey UPX PE File PE32 Device_File_Check OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AgentTesla suspicious privilege Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
1 4 5 9.4 M 51 ZeroCERT

10204 2024-07-05 15:54 Report.ps1  

054618073752ea5823c98130114a3241


Hide_EXE Generic Malware task schedule Antivirus KeyLogger AntiDebug AntiVM Malware download AsyncRAT NetWireRC VirusTotal Malware Code Injection Check memory buffers extracted unpack itself DDNS
2 3 7.2 10 ZeroCERT

10205 2024-07-06 18:20 mkl.js  

b0d0cfe2e3d3285272c07d5c32c96e44


AgentTesla Malicious Library Malicious Packer UPX PE File OS Memory Check .NET EXE PE32 OS Name Check OS Processor Check Browser Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Windows Gmail Browser Email ComputerName crashed keylogger
2 2 9.6 14 ZeroCERT

10206 2024-07-06 18:35 build.exe  

2dece3353cda5321fff7c92a697c37ee


Vidar Generic Malware Malicious Library Antivirus UPX AntiDebug AntiVM PE File PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram MachineGuid Code Injection Malicious Traffic Check memory WMI unpack itself Windows utilities Collect installed applications suspicious process AppData folder sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
3 5 3 1 11.0 M 60 ZeroCERT

10207 2024-07-07 18:55 buildj.exe  

7debc473f9ec83c3d000a57466eab9b2


Vidar Generic Malware Malicious Library Antivirus UPX AntiDebug AntiVM PE File PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram MachineGuid Code Injection Malicious Traffic Check memory WMI unpack itself Windows utilities Collect installed applications suspicious process AppData folder sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
3 5 3 1 11.0 M 58 ZeroCERT

10208 2024-07-07 19:11 go.exe  

d1a881d79ea584b074ae23f9279c5bd0


Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check MSOffice File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
8 6 1 6.4 44 ZeroCERT

10209 2024-07-08 07:52 PACKAGE_DEMO.exe  

e450ca946d4bf6173ebe3f00c3d08d81


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check Browser Info Stealer Malware download VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Check memory Creates shortcut Collect installed applications sandbox evasion IP Check installed browsers check Tofsee Ransomware MeduzaStealer Stealer Browser Email ComputerName Trojan Banking DNS
3 8 11.8 M 56 ZeroCERT

10210 2024-07-08 09:46 Installer.exe  

bed8cdced2d57be2bd750f0f59991ecd


Malicious Library UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Cryptocurrency wallets Cryptocurrency Telegram AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Ransomware Windows ComputerName DNS
4 4 9.8 M 63 ZeroCERT

10211 2024-07-08 09:54 Client.exe  

86108d3bcc19fe774cc81b71494d31f9


Generic Malware Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check PNG Format Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Browser Email ComputerName DNS Software crashed
1 4 3 7.8 M 61 ZeroCERT

10212 2024-07-08 10:04 Update.js  

affe7c07da3776a191c69b73e50d491a

VBScript wscript.exe payload download Tofsee crashed Dropper
1 2 2 10.0 guest

10213 2024-07-08 11:11 archive.rar  

2074be740d489e298715968ed68fd122


Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself IP Check Tofsee Windows Discord DNS
10 26 18 7 5.2 M ZeroCERT

10214 2024-07-08 14:09 INVESTIGATION_OF_SEXUAL_HARASS...  

9345d52abd5bab4320c1273eb2c90161


ZIP Format Word 2007 file format(docx) VirusTotal Malware unpack itself Tofsee
2 4 1 2.0 4 ZeroCERT

10215 2024-07-08 14:24 INVESTIGATION_OF_SEXUAL_HARASS...  

9345d52abd5bab4320c1273eb2c90161


ZIP Format Word 2007 file format(docx) VirusTotal Malware exploit crash unpack itself Tofsee Exploit crashed
2 4 1 1 2.6 M 4 ZeroCERT