Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3301 2020-11-25 18:13 https://zoomba619.blogspot.com...  

c89486438fea2dd19f18900689a2ea43


Dridex VirusTotal Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
30 21 3 4.6 ZeroCERT

3302 2020-11-25 18:16 regasm.exe  

2c779eb8a99417d4512c130b00b0dbf0


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName DNS Software
1 2 9 14.8 M 20 ZeroCERT

3303 2020-11-25 18:19 svchost.exe  

3093fbc1285eae874e39161553540c6c


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs
7.4 M 18 ZeroCERT

3304 2020-11-25 18:22 svchost.exe  

3093fbc1285eae874e39161553540c6c


VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs
1 2 8.2 M 18 ZeroCERT

3305 2020-11-25 18:22 vbc.exe  

f3d05ab1f7e10173609506ba7f343cd6


VirusTotal Malware Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
1 2 1 4.6 M 11 ZeroCERT

3306 2020-11-25 18:28 vbc2.exe  

ec26b497c9a213858ee08585ff4b3f10


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName Software
1 2 7 14.0 M 30 ZeroCERT

3307 2020-11-25 18:28 whe.exe  

095e1574fea1e95a9ed568d2e679fb77


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself malicious URLs Ransomware Windows Browser Tor Email ComputerName DNS Cryptographic key Software crashed
8.4 M 52 ZeroCERT

3308 2020-11-25 18:31 winlog2.exe  

953183f2f75bd5550052ec78c16f1f28


VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows
9.2 M 24 ZeroCERT

3309 2020-11-25 18:32 winlog.exe  

a3369a332aebbd578c291cc27ccb354b


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW installed browsers check Windows Browser Email ComputerName Software
1 2 7 1 17.0 M 44 ZeroCERT

3310 2020-11-25 18:36 winlog2.exe  

953183f2f75bd5550052ec78c16f1f28


VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows
5 10 9.0 M 24 ZeroCERT

3311 2020-11-26 07:54 http://195.3.146.180/cia.exe  

a7d58a3a9f2ff3e1fefd69ed12cceeb1


Dridex VirusTotal Malware Code Injection Malicious Traffic Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder malicious URLs Tofsee Windows Exploit DNS crashed Downloader
1 7 6.6 M 49 ZeroCERT

3312 2020-11-26 09:31 a14.exe  

3eafc3e74deeffaccc2a203154265a30


Malware download Amadey FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows Email ComputerName DNS Software
3 1 5 11.8 M 34 ZeroCERT

3313 2020-11-26 09:31 ach.vbs  

7eb75ac29bcdb9b04ffd7be21be218c0


Malware powershell Buffer PE suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI heapspray Creates shortcut ICMP traffic unpack itself powershell.exe wrote Check virtual network interfaces malicious URLs WriteConsoleW Windows Java ComputerName DNS Cryptographic key DDNS
6 3 14.4 M ZeroCERT

3314 2020-11-26 10:01 Bbyzuwhvoljsm1.exe  

883025ad08af47c1efac400822932857


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee ComputerName DNS
1 3 1 4.0 M 21 ZeroCERT

3315 2020-11-26 10:03 CFILEE.exe  

018460c9c7fba779d2c0b79c824ad5d4


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs ComputerName DNS
9.8 M 41 ZeroCERT