Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
15016 2023-03-09 10:01 PO-465514-180820.doc  

d7e6921bfd008f707ba52dee374ff3db


Generic Malware VBA_macro MSOffice File VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Exploit crashed
6 10 1 3.8 M 47 ZeroCERT

15017 2023-03-09 10:01 cred64.dll  

7b4ebf09cf37a88ab510a9fc4657f15e


Ave Maria WARZONE RAT UPX Malicious Library OS Processor Check DLL PE File PE64 VirusTotal Malware PDB Checks debugger installed browsers check Browser ComputerName crashed
2.4 M 47 ZeroCERT

15018 2023-03-09 09:59 clip64.dll  

5ff83d0896db3f702f09bcd8c943cea7


UPX Malicious Library Admin Tool (Sysinternals etc ...) OS Processor Check DLL PE32 PE File VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 53 ZeroCERT

15019 2023-03-09 09:59 cred64.dll  

d0bf0d14fe6110f185c8b98423c7b152


Ave Maria WARZONE RAT UPX Malicious Library OS Processor Check DLL PE File PE64 VirusTotal Malware PDB Checks debugger unpack itself installed browsers check Browser ComputerName crashed
2.8 M 42 ZeroCERT

15020 2023-03-09 09:57 ChromeFIX_error.exe  

26db14ad0b3f52784f53f5a9cde42d6a


RedLine stealer[m] RAT UPX Malicious Library AntiDebug AntiVM OS Processor Check PE32 PE File Browser Info Stealer VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Windows Browser ComputerName DNS Cryptographic key crashed
2 10.8 30 ZeroCERT

15021 2023-03-09 09:57 DefendUpdate.exe  

bbabecb60a7d91dc4b01da5359280b92


PE File PE64 VirusTotal Malware crashed
1.8 21 ZeroCERT

15022 2023-03-09 09:55 vbc.exe  

ece373b3964de43caf73e842e38703ae


AgentTesla PWS .NET framework browser info stealer Generic Malware Google Chrome User Data Downloader UPX Anti_VM Antivirus Create Service Socket DNS Internet API PWS[m] Sniff Audio KeyLogger Escalate priviledges AntiDebug AntiVM .NET EXE PE32 PE File Remcos VirusTotal Malware powershell AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process Windows ComputerName DNS Cryptographic key DDNS crashed keylogger
1 4 2 13.4 M 31 ZeroCERT

15023 2023-03-09 09:55 ss37.exe  

078fb584923487706390abc1a27a0459


Gen2 Gen1 UPX Malicious Library Malicious Packer PE File PE64 VirusTotal Malware PDB Remote Code Execution
1.2 5 ZeroCERT

15024 2023-03-09 09:55 vbc.exe  

174e78cfa74be3d0d0f7eeb4eec0450c


RAT SMTP KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName Cryptographic key Software crashed
12.2 M 29 ZeroCERT

15025 2023-03-09 09:45 10032b.exe  

9cb2c1a445f74bdee85086381dc80d7e


UPX Malicious Library OS Processor Check PE32 PE File VirusTotal Malware unpack itself Remote Code Execution
2.0 25 ZeroCERT

15026 2023-03-08 18:45 RemoteConfig.sqlite3  

00dc9f7c16006e1935b5042b9bfae851


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.4 BRY

15027 2023-03-08 18:31 AccountChooser.loctable  

7fa46218594ac176dfd14f88d6c1e633


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.4 BRY

15028 2023-03-08 17:41 vbc.exe  

f10caa63bef70662a123611402191200


RAT Generic Malware Antivirus .NET EXE PE32 PE File VirusTotal Malware powershell PDB suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
1 6.2 M 27 ZeroCERT

15029 2023-03-08 17:40 setup.exe  

9926000294771eb592dd85d1b894b76e


Malicious Library PE32 PE File VirusTotal Malware WMI Creates executable files RWX flags setting Checks Bios anti-virtualization ComputerName DNS
1 6.2 33 ZeroCERT

15030 2023-03-08 17:39 vbc.exe  

21f7fd1bf4759b63e04892f4ecbdf0e4


RAT Generic Malware Antivirus .NET EXE PE32 PE File VirusTotal Malware powershell PDB suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key crashed
5.6 20 ZeroCERT