Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1981 2024-07-24 07:40 winiti.exe  

6351e73e0fe9bb4bc8f56647a0c21f11


Malicious Library .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer Malware Telegram PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 6 9 12.6 M ZeroCERT

1982 2024-07-24 07:38 winiti.exe  

1832ae26a5094d286983ffb8b36a31da


Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 4 6 15.0 29 ZeroCERT

1983 2024-07-24 07:38 201.exe  

b42e6e906c622c0785c93e615ed2cc2b


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 37 ZeroCERT

1984 2024-07-24 07:33 JxTcJM84e3NbGP4mm.exe  

4faafbf754fc2dad8769ba54c564c22f


Generic Malware Malicious Library Antivirus PE File .NET EXE PE32 VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
5.2 52 ZeroCERT

1985 2024-07-24 07:22 server.exe  

fea9e6588163a319883a3b4d9b1f48fe


Hide_EXE Generic Malware Downloader Antivirus Create Service Socket DGA ScreenShot Escalate priviledges PWS Sniff Audio SMTP DNS Code injection Internet API KeyLogger Anti_VM AntiDebug AntiVM PE File .NET EXE PE32 Lnk Format GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process AppData folder malicious URLs Windows ComputerName Cryptographic key crashed keylogger
2 1 15.8 M 59 guest

1986 2024-07-23 18:36 #1. 프로젝트 정보 업데이트 요청사항.xlsx.lnk...  

e3eeeebb117b7c3128d87b6e027bd85d


Lnk Format GIF Format
11 ZeroCERT

1987 2024-07-23 18:36 #2. 금융당국 요청에 따른 프로젝트 정보 확인 요청의...  

05545d71b8afcc697faf751f81cf66fd


PDF
guest

1988 2024-07-23 18:26 금융당국 요청에 따른 프로젝트 정보 확인 요청의 건.z...  

6155d592e9083937ae5dadb304a69053


ZIP Format VirusTotal Malware
0.6 14 ZeroCERT

1989 2024-07-23 17:14 download.ics  

7be2232d72dff43cf090b194542cf229


email stealer DGA Http API ScreenShot Escalate priviledges PWS HTTP Internet API KeyLogger AntiDebug AntiVM Email Client Info Stealer MachineGuid unpack itself malicious URLs installed browsers check Browser Email
2.6 guest

1990 2024-07-23 16:35 Ref_7021929821US20240709031221...  

12fd2b8a8addfffe3f31c5d47e9def7a


NSIS Generic Malware Malicious Library UPX Antivirus PE File PE32 VirusTotal Malware powershell suspicious privilege Check memory Checks debugger WMI Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.6 39 ZeroCERT

1991 2024-07-23 15:08 Update (1).js  

9d28c59e246359f102981b014dd875ed

VBScript wscript.exe payload download Tofsee Dropper
1 2 2 10.0 guest

1992 2024-07-23 14:56 K1.zip  

eb834c6eb71e2a950f9123b506ab4763


ZIP Format Malware download VirusTotal Malware Malicious Traffic suspicious TLD CryptBot DNS
1 2 5 2.0 2 ZeroCERT

1993 2024-07-23 14:55 Setup.exe  

6a2cdd8709524999190f4b43a83108c9


Generic Malware Malicious Library Malicious Packer UPX PE File PE32 MZP Format VirusTotal Malware Remote Code Execution
1.4 1 ZeroCERT

1994 2024-07-23 14:40 PDF File.lnk  

44770e275c39bf3611eca4580aef573b


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell ZIP Format Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted heapspray Creates shortcut RWX flags setting unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Interception Windows ComputerName Cryptographic key
3 4 1 10.6 M ZeroCERT

1995 2024-07-23 14:35 Full Video HD (1080p).lnk  

12711edecea4d9342a2dab384761cc7b


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell ZIP Format Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI heapspray Creates shortcut RWX flags setting unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Interception Windows ComputerName Cryptographic key
3 4 1 11.2 M ZeroCERT