Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
22876 2022-12-19 06:30 filedata  

ca62dedce3746031d27eb65dd395c3ab


Generic Malware Malicious Packer UPX OS Processor Check DLL PE File PE64 VirusTotal Malware
1.2 25 guest

22877 2022-12-16 09:48 x.png.ps1  

cba6879539919f8e6bb25973b2bf6ac9


Hide_EXE Generic Malware Anti_VM Antivirus VirusTotal Malware powershell AutoRuns suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 8.6 M 10 ZeroCERT

22878 2022-12-16 09:46 bb.png.ps1  

39e3fa050d14b95af5226a1eb4d2afab


Generic Malware task schedule Antivirus KeyLogger AntiDebug AntiVM Malware download AsyncRAT NetWireRC VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key DDNS
2 3 13.2 M 9 ZeroCERT

22879 2022-12-16 09:43 http://156.96.156.177:222/pp.h...  

d1e4ae002f5f1b89f5d3efd745e6f8aa


Antivirus AntiDebug AntiVM powershell Code Injection unpack itself Windows utilities Windows DNS
2 1 3 2.4 2 ZeroCERT

22880 2022-12-16 09:42 NanoSetup_29823.exe  

1a6d33d472c53935aeea41b5d4c45468


PWS[m] Gen2 Generic Malware Malicious Library ASPack Admin Tool (Sysinternals etc ...) UPX Escalate priviledges AntiDebug AntiVM PE32 OS Processor Check PE File DLL PE64 VirusTotal Malware PDB MachineGuid Code Injection Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee RCE crashed
1 6 3 7.0 M 30 ZeroCERT

22881 2022-12-16 07:54 RMLLauncher.exe  

2a8c8ff714ed2627dcca029ec4b1739c


RAT PWS .NET framework Antivirus PE32 .NET EXE PE File VirusTotal Malware PDB suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee Windows Cryptographic key
1 2 1 5.8 M 23 ZeroCERT

22882 2022-12-15 17:47 Client_zffz.exe  

9a3e1eee1cc88d5e7955f8a42f9cce61


UPX Malicious Library PE32 PE File VirusTotal Malware Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files AppData folder human activity check Windows DNS
3 1 1 5.2 M 8 ZeroCERT

22883 2022-12-15 17:44 Update_zffz.exe  

4a4e1f0722c32721ded4034184e2055e


UPX PE32 PE File VirusTotal Malware Check memory Checks debugger
1.8 3 ZeroCERT

22884 2022-12-15 17:44 bnb.exe  

37da979d87ef402b50cb00266bc00808


Generic Malware Malicious Library UPX Antivirus PDF PE32 PE File icon .NET EXE DLL PE64 OS Processor Check JPEG Format VirusTotal Malware powershell AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder Windows ComputerName DNS Cryptographic key crashed
1 1 3 10.4 50 ZeroCERT

22885 2022-12-15 17:42 nopersis_miner.exe  

598d16e6316cde59bb452bdd23e91b14


RAT PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself
2.8 34 ZeroCERT

22886 2022-12-15 17:41 jettyhead.exe  

f87672ca39c11764995388966e69d8fb


Generic Malware Malicious Library UPX Antivirus PDF PE32 PE File DLL PE64 JPEG Format VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key crashed
7.4 40 ZeroCERT

22887 2022-12-15 15:55 AllmakeString2.exe  

5b7db76369cfda2450af6bebdc62ff15


Malicious Library Malicious Packer UPX OS Processor Check PE File PE64 VirusTotal Malware PDB crashed
1.8 42 ZeroCERT

22888 2022-12-15 13:46 file.exe  

e35f0679b35b25a3757086d817ba7a75


Gen1 Confuser .NET Malicious Library ASPack UPX PE32 PE File PE64 CHM Format DLL OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger Creates executable files unpack itself AppData folder Windows ComputerName crashed
4.2 13 ZeroCERT

22889 2022-12-15 10:29 MEMZ.exe  

19dbec50735b5f2a72d4199c4e184960


Malicious Library PE32 PE File VirusTotal Malware Check memory unpack itself crashed
2.0 M 63 ZeroCERT

22890 2022-12-15 10:21 BRDbdWBB.bat  

bc9ac7c15b87ae4439fc51991d20388e


PWS[m] Downloader Malicious Library Create Service DGA Socket ScreenShot DNS Internet API Code injection Sniff Audio HTTP Steal credential KeyLogger P2P Escalate priviledges FTP Http API persistence AntiDebug AntiVM PE32 PE File VirusTotal Malware Code Injection Creates executable files unpack itself AppData folder malicious URLs WriteConsoleW crashed
4.6 30 ZeroCERT