Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
18061 2023-05-03 09:55 C713.wsf  

ad4bcd97e9014f9f76b05d5db8b1e273


VBScript WMI heapspray wscript.exe payload download ICMP traffic Tofsee ComputerName Dropper
4 8 2 10.0 ZeroCERT

18062 2023-05-03 09:44 vbc.exe  

f9fbfee491440e919bf3ee8df7f415aa


.NET EXE PE32 PE File VirusTotal Malware PDB Check memory Checks debugger unpack itself DNS
1 3.2 M 42 ZeroCERT

18063 2023-05-03 09:42 sc64.dll  

4c09e8e3a1d837f125ea9f9c0c2c5380


SystemBC Malicious Packer Antivirus DLL PE64 PE File VirusTotal Malware Checks debugger unpack itself DNS
2 2.4 M 50 ZeroCERT

18064 2023-05-03 09:40 v1.exe  

1c87be3086b35f72e87666036310df86


RAT Generic Malware UPX Malicious Library OS Processor Check PE64 PE File VirusTotal Malware unpack itself Windows crashed
3.8 M 35 ZeroCERT

18065 2023-05-03 09:38 vbc.exe  

5bc95f5d8d3bf878098d8527bc679545


Formbook PWS .NET framework RAT UPX AntiDebug AntiVM .NET EXE PE32 PE File FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
1 3 1 8.8 M 45 ZeroCERT

18066 2023-05-03 09:38 %23%23%23%23%23%23%23%23%23%23...  

4666ed7dbe4480fa15249382b4d8a296


MS_RTF_Obfuscation_Objects RTF File doc Malware download Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed Downloader
1 2 3 4.0 M ZeroCERT

18067 2023-05-03 09:37 am.exe  

c23d62c9166ae248fe9fe078328182f9


RAT SystemBC UPX Malicious Packer Malicious Library Antivirus OS Processor Check PE32 PE File .NET EXE DLL PE64 JPEG Format Malware download Amadey VirusTotal Malware AutoRuns PDB Malicious Traffic Check memory Checks debugger Creates executable files RWX flags setting unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS
6 5 2 10.2 M 53 ZeroCERT

18068 2023-05-03 09:35 %23%23%23%23%23%23%23%23%23%23...  

bdff5c8782a221578cb25c9a8c076ff3


MS_RTF_Obfuscation_Objects RTF File doc Malware download Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed Downloader
1 1 7 4.2 ZeroCERT

18069 2023-05-03 09:33 %23%23%23%23%23%23%23%23%23%23...  

fc01e8909cd645434c82378c485c6aa7


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed Downloader
2 4 9 5.0 M 31 ZeroCERT

18070 2023-05-03 09:33 Setup2.exe  

c80864ec4f40c15a4589d19a1e6cd3ca


RAT .NET EXE PE32 PE File VirusTotal Malware Check memory Checks debugger RWX flags setting unpack itself crashed
3.2 M 43 ZeroCERT

18071 2023-05-03 09:31 v1.exe  

2d1952dc0776774b3d9366412a44de4d


UPX Malicious Library OS Processor Check PE32 PE File VirusTotal Malware Buffer PE PDB Checks debugger buffers extracted unpack itself sandbox evasion ComputerName
1 4.0 M 49 ZeroCERT

18072 2023-05-03 09:31 rundll32.exe  

1d81057710dc737ffee88f7f8b0ef90c


RAT .NET EXE PE32 PE File VirusTotal Malware Check memory Checks debugger RWX flags setting unpack itself DNS crashed
1 3.2 M 16 ZeroCERT

18073 2023-05-03 09:29 vbc.exe  

407a4475933399d86b822c4ed5a6393b


PWS .NET framework Generic Malware Antivirus SMTP PWS[m] KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File VirusTotal Malware powershell AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key crashed
13.2 M 40 ZeroCERT

18074 2023-05-03 09:29 12.ocx  

c7c3f41117bfe6c2635686e7dc2bfc65


Generic Malware UPX VMProtect Malicious Library PE32 PE File VirusTotal Malware Check memory RWX flags setting unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check Browser
2 5.2 M 42 ZeroCERT

18075 2023-05-03 09:27 vbc.exe  

aee5842856560c4c7cec9b66f806f8a4


Loki_b Loki_m Socket DNS PWS[m] AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName DNS Software
2 14.2 M 42 ZeroCERT