Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
18076 2023-05-03 09:27 %23%23%23%23%23%23%23%23%23%23...  

dfe1daa92531bdf7c7f6665de38bcbd6


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed Downloader
1 2 7 4.6 M 32 ZeroCERT

18077 2023-05-03 09:25 newvice.hta  

dc6d1be99f44f1ef994a923c6003e817


PWS .NET framework Generic Malware Antivirus SMTP PWS[m] KeyLogger AntiDebug AntiVM PowerShell .NET EXE PE32 PE File Malware download VirusTotal Malware powershell Telegram suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted heapspray Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder malicious URLs WriteConsoleW IP Check Tofsee Windows ComputerName DNS Cryptographic key DDNS keylogger
2 6 9 17.8 M 16 ZeroCERT

18078 2023-05-03 09:25 vice.exe  

0d4950c69afb9b3c9b2d52b7b5ae9d41


PWS .NET framework SMTP PWS[m] KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Malware download VirusTotal Malware Telegram PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs IP Check Tofsee DNS DDNS keylogger
1 4 9 10.0 42 ZeroCERT

18079 2023-05-03 09:00 IMG_5435.exe  

3121ecc67e64fdf65b2b3c9f5966ed11


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
2 1 2.6 44 guest

18080 2023-05-02 17:43 officeFluidOneDsSink.f9690cf3....  

03c5f86a62e83d48d204b2231d1a92c2

crashed
0.2 BRY

18081 2023-05-02 17:15 setup1.exe  

5d1d87f12f1fb0dd0b00af611c09557e


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself
2.2 58 ZeroCERT

18082 2023-05-02 16:43 zxz668%20%282%29.exe  

5812c5ec8f81f425d2bc75343e13358d


UPX Malicious Library OS Processor Check PE32 PE File VirusTotal Malware unpack itself
1.2 26 ZeroCERT

18083 2023-05-02 09:59 vbc.exe  

7df31d97b98a8830fddfc9f2930683ea


Formbook RAT Hide_EXE AntiDebug AntiVM .NET EXE PE32 PE File FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
2 4 1 8.6 45 ZeroCERT

18084 2023-05-02 09:54 Oilio.bat  

5ca1e10316dbc25689e663dc437e79c9


Downloader Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot AntiDebug AntiVM suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities WriteConsoleW Windows ComputerName Cryptographic key
3.0 ZeroCERT

18085 2023-05-02 09:20 ######################.doc  

88a907c3e36d9ddfb106c9ad66408b46


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed Downloader
2 4 8 4.6 M 33 ZeroCERT

18086 2023-05-02 09:19 IMG_5435.exe  

3121ecc67e64fdf65b2b3c9f5966ed11


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
1 6 1 3.8 44 ZeroCERT

18087 2023-05-02 09:16 SvCpJuhbT.exe  

c726a4eba148b17c9ccf3692fbc90701


UPX Malicious Packer Malicious Library PE64 PE File VirusTotal Malware Check memory
1.6 M 19 ZeroCERT

18088 2023-05-02 07:43 MsMpEng.hta  

6bf27371c148d5fc227f4acf45cec231


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 11.0 M 21 ZeroCERT

18089 2023-05-02 07:40 Korsakoff.exe  

d03d1839ba1d7c4c5a1941d8e3fb35eb


Generic Malware UPX Antivirus Malicious Library OS Processor Check PE64 PE File PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut unpack itself Windows utilities Disables Windows Security suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.0 M 6 ZeroCERT

18090 2023-05-02 05:25 bryanwalling  

10b03a981cdac8bf7408667a60f5cb6f


AntiDebug AntiVM Email Client Info Stealer Code Injection Check memory Checks debugger unpack itself installed browsers check Browser Email
3.2 BRY