Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
17926 2023-05-10 10:17 123.exe  

851dfeb9035473532d796a9b41608b3c


PE64 PE File VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.0 M 22 ZeroCERT

17927 2023-05-10 10:15 50050291542339510009.bin  

88e6deee81ba6c70e517b7b4dcf56b5e


Gen1 UPX Malicious Library OS Processor Check PE32 PE File VirusTotal Malware unpack itself Windows utilities WriteConsoleW Windows ComputerName crashed
3.6 M 52 ZeroCERT

17928 2023-05-10 10:13 forscan.exe  

50ef79424f390cfba341d58e90329b3f


RedLine stealer[m] Gen2 Loki_b Loki_m RAT Generic Malware UPX Malicious Library AntiDebug AntiVM OS Processor Check PE64 PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications AppData folder installed browsers check Windows Browser ComputerName DNS Cryptographic key Software crashed
1 13.0 M 15 ZeroCERT

17929 2023-05-10 10:12 ghjkl.exe  

9453b414b969dc9b52b9327e324dc1eb


Generic Malware Antivirus ScreenShot AntiDebug AntiVM .NET EXE PE32 PE File VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process AppData folder Windows ComputerName Cryptographic key crashed
10.8 M 50 ZeroCERT

17930 2023-05-10 10:09 obi.exe  

07d31d6b30d2925b4664dc957f2235e9


Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
1 2 1 14.0 M 36 ZeroCERT

17931 2023-05-10 10:07 httpsNccapskuh.exe  

fbb4b3a3458a459bb60e1c3e51f8a1f4


ScreenShot AntiDebug AntiVM .NET EXE PE32 PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key crashed
7.8 M 51 ZeroCERT

17932 2023-05-10 10:05 vbc.exe  

a4e7abd7fda183a69db7ac1bfc9e18b1


Formbook PWS .NET framework RAT UPX ASPack Malicious Library AntiDebug AntiVM .NET EXE PE32 PE File OS Processor Check FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces Windows ComputerName DNS Cryptographic key crashed
3 6 1 12.0 M 39 ZeroCERT

17933 2023-05-10 10:02 olotiiss.exe  

3e22ae167ceabafcaa798453a48444fa


PWS .NET framework UPX SMTP KeyLogger AntiDebug AntiVM OS Processor Check .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
1 2 1 11.4 M 45 ZeroCERT

17934 2023-05-10 10:00 Had.exe  

71ae692fbca5a94d85b2a994b4426c4e


PE64 PE File VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.0 M 33 ZeroCERT

17935 2023-05-10 10:00 originalbuild.exe  

946640d04e9bc3419f1ca9183e5da8f6


RAT Generic Malware Malicious Library Antivirus .NET EXE PE32 PE File PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 6.4 M 40 ZeroCERT

17936 2023-05-10 09:17 워싱턴선언, 북핵 위협 대응에 얼마나 도움이 될까.ln...  

445e7fd6bb684420d6b8523fe0c55228


Generic Malware Downloader Antivirus Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot Hide_URL AntiDebug AntiVM HWP MSOffice File GIF Format .NET VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 4 1 10.8 18 ZeroCERT

17937 2023-05-09 19:28 std2.7z  

8c47460fa4cce4ce9c672c5390472e03


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM suspicious privilege Check memory Checks debugger Creates executable files unpack itself
2.0 M ZeroCERT

17938 2023-05-09 19:23 103.184.128.244_update.7z  

068a57341223a3d3d024b524cd67df5e


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM SMB Traffic Potential Scan suspicious privilege Check memory Checks debugger Creates executable files ICMP traffic unpack itself DNS
133 1 3.4 ZeroCERT

17939 2023-05-09 19:14 103.40.123.34_update.7z  

f91cf94c3ba6073a885f53e8c32bfa1b


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM SMB Traffic Potential Scan suspicious privilege Check memory Checks debugger Creates executable files unpack itself DNS
276 1 2.6 ZeroCERT

17940 2023-05-09 18:59 update.7z  

c9027a96969b77612260fd952c632a54


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM SMB Traffic Potential Scan suspicious privilege Check memory Checks debugger Creates executable files unpack itself DNS
131 1 2.6 M ZeroCERT