Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
2356 2020-10-27 18:23 rep_0HHSEI8DAP5IFU0.doc  

f0ff84c95b97ee41cf9869d9bc25eb15


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee DNS
4 10 1 6.0 M 19 guest

2357 2020-10-28 07:37 http://103.153.79.195/0pp.exe  

605eef77a212754b476a215f3b6c02f7


VirusTotal Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
2 5 3 11.8 M guest

2358 2020-10-28 07:40 http://oreillyautolawsuit.com/...  

0c4816564a04182f082efe99506f5f94


VirusTotal Malware Code Injection Creates executable files exploit crash unpack itself Windows utilities Windows Exploit DNS crashed Downloader
1 3 2 4.6 guest

2359 2020-10-28 07:47 http://www.josejuanarroyo.com/...  

2e9b6b2fd1f6f1a4e7f9df6b0aefb6bb


VirusTotal Malware AutoRuns Code Injection Malicious Traffic Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Auto service malicious URLs AntiVM_Disk sandbox evasion VM Disk Size Check human activity check Windows Exploit Advertising ComputerName DNS Cryptographic key crashed
2 4 2 12.2 guest

2360 2020-10-28 08:07 http://jiehost.com/wp-admin/6Z...  

fe40bfc067dd10f30aae16fc5bb543f3


Malware AutoRuns Code Injection Malicious Traffic Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Auto service malicious URLs AntiVM_Disk sandbox evasion VM Disk Size Check human activity check Windows Exploit Advertising ComputerName DNS Cryptographic key crashed
2 5 2 12.8 M guest

2361 2020-10-28 09:03 CtjEwdljmr.exe  

81f9fa473a516670504b796b8ae63d6b


Malware Malicious Traffic RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 2 6.4 guest

2362 2020-10-28 09:03 Inv. 0655554.doc  

240b691234655ab6f8d51f62d3ea7d71


Vulnerability VirusTotal Malware Malicious Traffic ICMP traffic unpack itself malicious URLs Tofsee DNS
3 6 1 6.8 17 guest

2363 2020-10-28 09:34 Adobe.pdf.exe  

bbad437e472d66b7702a2c7671260b27


VirusTotal Malware Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Checks Bios Detects VirtualBox Check virtual network interfaces malicious URLs WriteConsoleW VMware anti-virtualization Tofsee Windows ComputerName Cryptographic key Software
2 2 1 10.0 44 guest

2364 2020-10-28 09:36 infostati.exe  

6f952b81a92f7f780923635648b428c0


VirusTotal Malware unpack itself malicious URLs
2.6 37 guest

2365 2020-10-28 09:37 torn.exe  

02137910a963fac7169db7c3e30e667a


VirusTotal Malware suspicious privilege Check memory Creates executable files unpack itself Check virtual network interfaces AppData folder malicious URLs anti-virtualization Ransomware Windows Tor ComputerName DNS crashed keylogger
6 6 11.2 54 guest

2366 2020-10-28 09:42 0uu.exe  

38f441527edd249d93a5c9ee0f37b1ba


VirusTotal Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities malicious URLs Windows
2 4 10.2 14 guest

2367 2020-10-28 09:45 PO-1511.exe  

bd1774eb4111b1427dab606545da4a76


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows Tor ComputerName DNS
4 4 11.6 27 guest

2368 2020-10-28 09:45 0pp.exe  

605eef77a212754b476a215f3b6c02f7


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs
8.4 M 24 guest

2369 2020-10-28 09:57 0pp.exe  

605eef77a212754b476a215f3b6c02f7


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs
3 10.4 M 24 admin

2370 2020-10-28 10:02 lilbaa.exe  

51400134bdd5b0eae07a5685c3560771


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger buffers extracted WMI ICMP traffic unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
1 4 5 12.2 M 25 admin