Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3241 2020-11-23 10:10 333.vbs  

98a361a32f05e5d35659b84c4a8a3d81


Malware download AsyncRAT Dridex NetWireRC TrickBot Malware powershell AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Kovter Windows ComputerName DNS Cryptographic key DDNS
4 3 16.0 M ZeroCERT

3242 2020-11-23 10:11 Daemon.exe  

dd3de309df5791a357534b613270ca3a


VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process malicious URLs sandbox evasion WriteConsoleW Windows Browser ComputerName DNS
1 5 11.8 M 40 ZeroCERT

3243 2020-11-23 10:15 nCoreManage41r.exe  

49479db345e2c3694c34f1326035a692


VirusTotal Malware Checks debugger unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows DNS
4.6 M 48 ZeroCERT

3244 2020-11-23 10:16 Daemon2.exe  

f3cc3e81c695a218ecfd71978d007ec0


VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process malicious URLs sandbox evasion WriteConsoleW Windows Browser ComputerName DNS
1 5 11.8 M 39 ZeroCERT

3245 2020-11-23 10:30 Daemon2.exe  

f3cc3e81c695a218ecfd71978d007ec0


VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process malicious URLs sandbox evasion WriteConsoleW Windows Browser ComputerName DNS crashed
1 5 12.0 M 39 admin

3246 2020-11-23 12:13 nCoreManage41r.exe  

49479db345e2c3694c34f1326035a692


VirusTotal Malware Checks debugger unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows
4.0 M 48 guest

3247 2020-11-23 12:14 This.exe  

c49dd8107b3624f824efe4f88cb3f792


VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process malicious URLs sandbox evasion WriteConsoleW Windows Browser ComputerName DNS Downloader
1 6 12.8 M 48 guest

3248 2020-11-23 14:00 This.exe  

c49dd8107b3624f824efe4f88cb3f792


VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process malicious URLs sandbox evasion WriteConsoleW Windows Browser ComputerName DNS Downloader
1 6 12.8 M 48 admin

3249 2020-11-23 14:01 5.exe  

f139bcd08ad8da406f7dd25411d1c9b3


VirusTotal Malware unpack itself malicious URLs
2.8 M 60 admin

3250 2020-11-23 14:03 Win0Defender2.exe  

eaa5442b86ae5808036863ffa4ca20e2


VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows ComputerName crashed
6.2 M 38 guest

3251 2020-11-23 14:14 5.exe  

f139bcd08ad8da406f7dd25411d1c9b3


VirusTotal Malware unpack itself malicious URLs
2.8 M 60 admin

3252 2020-11-23 14:23 5.exe  

f139bcd08ad8da406f7dd25411d1c9b3


VirusTotal Malware unpack itself malicious URLs
2.8 M 60 admin

3253 2020-11-23 14:26 document.doc  

d188556b8782a4594736c1aeef79f2f5


VirusTotal Malware Malicious Traffic ICMP traffic exploit crash unpack itself malicious URLs Tofsee Windows Exploit crashed
5 6 2 6.4 24 guest

3254 2020-11-23 14:43 5.exe  

f139bcd08ad8da406f7dd25411d1c9b3


VirusTotal Malware unpack itself malicious URLs
2.8 M 60 admin

3255 2020-11-23 15:55 5.exe  

f139bcd08ad8da406f7dd25411d1c9b3


VirusTotal Malware unpack itself malicious URLs
2.8 M 60 ZeroCERT