Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3826 2020-12-19 22:06 AQW.exe  

6aa2322441883ae8dce5403dc0de0c83


Buffer PE AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself suspicious process malicious URLs Windows DNS Cryptographic key keylogger
2 14.0 ZeroCERT

3827 2020-12-19 22:23 AQW.exe  

6aa2322441883ae8dce5403dc0de0c83


VirusTotal Malware Buffer PE AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself suspicious process malicious URLs Windows ComputerName Cryptographic key crashed keylogger
2 15.4 M 18 ZeroCERT

3828 2020-12-20 18:08 Fireeye.exe  

70f2b6159dad55915ade4a201644f89c


VirusTotal Malware RWX flags setting unpack itself Windows crashed
3.2 M 51 ZeroCERT

3829 2020-12-20 18:09 CyberGuard.exe  

d259f32b74a652fd423459736e397f73


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs DNS
1 9.0 M 43 ZeroCERT

3830 2020-12-20 18:18 CyberGuard.exe  

d259f32b74a652fd423459736e397f73


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs DNS
1 10.0 M 43 ZeroCERT

3831 2020-12-21 11:15 HVH.exe  

36397bf0c63e9245a2dedde34076846f


VirusTotal Malware suspicious privilege unpack itself Windows DNS keylogger
1 6.8 M 54 ZeroCERT

3832 2020-12-21 11:15 HiddenEye.exe  

112702530b838997bb1accc464389564


VirusTotal Malware Buffer PE AutoRuns Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows DNS
1 9.2 M 53 ZeroCERT

3833 2020-12-21 12:35 imposter11.exe  

567204cbb8d1c5908a5316f9dfdcb353


VirusTotal Malware AutoRuns suspicious privilege Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW shadowcopy delete Turn off Windows Error Recovery notification window Ransomware Windows ComputerName DNS crashed
10.2 M 54 guest

3834 2020-12-21 20:04 rt.bat  

bbfa7ad2c4ba8d331141988b749282d5


VirusTotal Malware Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Checks Bios Detects VirtualBox Check virtual network interfaces suspicious process malicious URLs WriteConsoleW VMware anti-virtualization Tofsee Windows ComputerName Cryptographic key Software
3 2 1 10.8 M 42 guest

3835 2020-12-21 20:06 Program.exe  

f07004b986626ff5b27ddeb20da53abb


VirusTotal Malware AutoRuns PDB Check memory unpack itself Windows DNS
1 5.6 M 49 guest

3836 2020-12-21 20:22 RT16.exe  

3fd4fe03c91baa8e665854fbbc4d0c8b


VirusTotal Malware unpack itself Remote Code Execution
3.0 M 51 guest

3837 2020-12-21 20:26 stamper.exe  

0c5bc6e18eb91e1edc1a89eeef68e4bb


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs DNS
1 9.0 M 49 guest

3838 2020-12-21 20:39 to.exe  

d19e584fe7d4fef4ac2de596dc281bae


VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW human activity check Windows ComputerName DNS DDNS
2 1 17.2 M 23 guest

3839 2020-12-21 20:39 stamper.exe  

0c5bc6e18eb91e1edc1a89eeef68e4bb


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs DNS
1 9.0 M 49 guest

3840 2020-12-21 20:59 updatewin.exe  

9010fa92cc83afe00fab38703e6ffa77


VirusTotal Malware suspicious privilege Malicious Traffic unpack itself malicious URLs suspicious TLD Tofsee DNS
1 2 2 5.0 M 55 guest