Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
2476 2020-10-30 21:21 FAS_100120_OBW_103020.doc  

26e46a86e1386111f4c7790bab599869


Vulnerability Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
2 6 4 5.4 M admin

2477 2020-10-30 21:50 invoice_771275.doc  

2fabe873166b42d734a12c918f792764


Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself malicious URLs IP Check Tofsee Windows Exploit DNS DDNS crashed
3 8 8 5.4 M 22 admin

2478 2020-10-30 21:59 POP.exe  

8cf74500bb24624b63930bf263aafcb0


AutoRuns suspicious privilege Code Injection Check memory Checks debugger unpack itself malicious URLs Windows
5.2 M admin

2479 2020-10-30 22:39 win32.exe  

7c0ec544d981d901c7819996d90dacc8


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW IP Check VM Disk Size Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 6 5 17.6 M 22 admin

2480 2020-10-31 09:09 FILE_PO_10312020EX.doc  

b864ecba7b8fee96b95159cb9f4d30b2


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
2 6 4 6.0 M 18 admin

2481 2020-10-31 09:13 8.exe  

56564e2f274ac21803580be8a236518d


AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check human activity check Windows ComputerName DNS DDNS crashed
2 14.6 admin

2482 2020-10-31 09:14 donpyx.exe  

319a790ffd7c286a2ed494469ddd1357


Browser Info Stealer Malware download FTP Client Info Stealer Azorult VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications AppData folder malicious URLs sandbox evasion anti-virtualization installed browsers check Ransomware Browser Email ComputerName Software
1 2 1 15.6 27 admin

2483 2020-10-31 09:15 83iUuVObiSnKzI9WfkpU.exe  

cc0b69abe8dd0a2cf87ffe7e1a1e1d2f


Malware Malicious Traffic RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 3 7.2 M admin

2484 2020-10-31 09:31 Inf_EDV_100120_URP_103120.doc  

11b0ade6c38d27ba741294173f088621


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
2 6 4 6.0 M 17 admin

2485 2020-10-31 09:36 mBhuyP.exe  

2acfebc586eac54f79cc41fd78e897ce


Malware Malicious Traffic RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 3 7.2 M admin

2486 2020-10-31 09:41 ePh0eJZNL1NJpMw.exe  

d3c3cff0bfce9f34418da4cf2fdfb027


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Ransomware Windows Tor ComputerName crashed
13.6 40 admin

2487 2020-10-31 09:42 ike.exe  

5b938ccc78b8b6af082c85f969d188f7


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger unpack itself malicious URLs Ransomware Windows Browser Tor Email ComputerName Cryptographic key Software crashed
11.0 25 admin

2488 2020-10-31 09:46 https://bitbucket.org/soyag/la...  

9ada122303e6dee1c0f0171bf2e59253


Dridex Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
3 3 4.2 admin

2489 2020-10-31 09:47 regasm.exe  

355e70c00a060f1e2a0680676227d7ce


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName Trojan DNS Software
1 2 10 14.0 38 admin

2490 2020-10-31 09:50 UNTITLED_FY4695778951OT.doc  

dfa215f2b84d0df40c221d76309acb13


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
2 6 4 6.0 M 16 admin