Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
2146 2024-07-18 10:51 4c12d617aa51bb0c0108242da6aa00...  

4c12d617aa51bb0c0108242da6aa0071


VBA_macro Word 2007 file format(docx) ZIP Format VirusTotal Malware
1.6 25 ZeroCERT

2147 2024-07-18 08:31 LuckySetup.exe  

0384b1d87ff3be1c490657a34233dc9d


Gen1 Generic Malware Malicious Library Malicious Packer UPX Antivirus .NET framework(MSIL) PE File PE32 MZP Format OS Processor Check DLL .NET DLL .NET EXE Lnk Format GIF Format PE64 VirusTotal Malware suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Browser ComputerName crashed
5.8 11 ZeroCERT

2148 2024-07-18 08:29 appmodedrivme.exe  

ffe6422dff4cbe7efdbd7ac4983504d4


Malicious Library .NET framework(MSIL) PE File ftp .NET EXE PE32 Check memory Checks debugger unpack itself ComputerName
1.4 ZeroCERT

2149 2024-07-18 08:27 sc2.exe  

0bb47290ac45642ac44a00846eda74e2


AsyncRAT Malicious Library Malicious Packer .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check Malware download AsyncRAT NetWireRC VirusTotal Malware DNS DDNS
2 4 1.6 56 ZeroCERT

2150 2024-07-17 21:14 6696629242869_crypted.exe  

9579c9ca9e85cfd4436f4acb8e11642b


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 52 ZeroCERT

2151 2024-07-17 21:12 669698e482bd9_finesoft.exe  

5e7ccedcf6a3958320c46d90e9cd604e


Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library .NET framework(MSIL) UPX ASPack Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 17.2 M 40 ZeroCERT

2152 2024-07-17 21:00 greatlionloveroseentierworldlo...  

899326d947e7833eb5e0e9a94bddae5c


Generic Malware Antivirus PowerShell Malware download Malware VBScript powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key Dropper
2 3 5 2 10.0 M ZeroCERT

2153 2024-07-17 21:00 bh..x.x.xbh.....x.x.x.xbhbh.do...  

f4e21b4629aaf817a7bd3410d1910c52


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
3 4 5 2 4.6 M 32 ZeroCERT

2154 2024-07-17 20:58 66979ab41b05f_crypta.exe  

4fdec920bb078c6636323ec0d77be95d


Malicious Library .NET framework(MSIL) UPX ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself DNS
1 8.0 15 ZeroCERT

2155 2024-07-17 20:57 669662d10259b_file150724.exe  

b3757b09ed2150ce857f446c0c61363c


Suspicious_Script_Bin Malicious Library UPX Socket DGA Http API ScreenShot PWS DNS Internet API AntiDebug AntiVM PE File PE32 OS Processor Check Malware download VirusTotal Malware Microsoft AutoRuns Code Injection Checks debugger buffers extracted ICMP traffic unpack itself malicious URLs Tofsee Windows ComputerName DNS
2 4 6 10.2 M 56 ZeroCERT

2156 2024-07-17 20:56 java.exe  

cf8827cf86ed8c72f1276eb9c2456278


UPX PE File PE64 VirusTotal Malware suspicious privilege Windows utilities WriteConsoleW Windows Java DNS
1 4.8 M 50 ZeroCERT

2157 2024-07-17 20:55 ZHR.txt.exe  

d34f0dab54d1463e8ab9d016f6a78440


Malicious Library Malicious Packer .NET framework(MSIL) UPX PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 6 9 7.8 50 ZeroCERT

2158 2024-07-17 20:55 client.exe  

d585cbc4612c2fd171d7b20bf62241d7


Gen1 Generic Malware Malicious Library UPX Anti_VM PE File PE64 OS Processor Check DLL ZIP Format ftp VirusTotal Malware Check memory Creates executable files
2.4 41 ZeroCERT

2159 2024-07-17 20:54 66967d2323cae_cry.exe  

156d89382dd0eb5cd6fd5ef7d1cb9006


Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library .NET framework(MSIL) UPX ASPack Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 16.4 36 ZeroCERT

2160 2024-07-17 20:50 shell.bat  

4baea5b66334a3be30d12b1956fe889e


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 7.6 25 ZeroCERT