Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3856 2020-12-22 10:42 vbc.exe  

fcd369792aaf258ffbd27408e3d32f1f


VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows ComputerName DNS crashed
10.8 M 23 ZeroCERT

3857 2020-12-22 10:42 uninsxsd1218.exe  

a0e151a2b74b2816155c47f209761415


VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory WMI Creates executable files Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
2 11.0 M 41 ZeroCERT

3858 2020-12-22 11:01 1.exe  

09874cbb134851ff3b971960916ce5bb


VirusTotal Malware unpack itself Remote Code Execution
2.6 M 61 ZeroCERT

3859 2020-12-22 11:02 winlog.exe  

6afe65a67db47fb50ae3506d8e6e0e4d


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName Trojan DNS Software
1 2 8 1 13.2 M 35 ZeroCERT

3860 2020-12-22 11:12 Ableton Activator v.3.4.exe  

c59985a2a4b0a33ce346df4c605f61c4


Browser Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces suspicious process AppData folder malicious URLs VMware anti-virtualization installed browsers check Tofsee Ransomware Windows Browser ComputerName Firmware DNS Cryptographic key crashed
2 7 1 13.4 26 ZeroCERT

3861 2020-12-22 11:12 1WMZPO6LD84.doc  

c4a740227ca940d4bd157716f2c9f0e0


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 5 4 6.6 M 28 ZeroCERT

3862 2020-12-22 11:21 78983-4.xlsm  

e8fecc39968a9add2d38560e88d3c07a


Malware download Dridex TrickBot VirusTotal Malware suspicious privilege Checks debugger buffers extracted Creates executable files ICMP traffic RWX flags setting unpack itself Check virtual network interfaces malicious URLs Kovter Windows ComputerName DNS crashed Downloader
1 7 7 10.0 2 guest

3863 2020-12-22 11:39 config2.json.exe  

062f86194f7d3281a7eac6238c635237


VirusTotal Malware unpack itself malicious URLs DNS crashed
3.6 M 39 ZeroCERT

3864 2020-12-22 11:40 ANC1QRIZ0X.doc  

989c3a50ecfe2a54f97e739eee3154bf


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
1 7 5 1 6.6 M 28 ZeroCERT

3865 2020-12-22 12:20 file.exe  

6d048030d31349665bb357ad55cd79b1


VirusTotal Malware unpack itself Remote Code Execution
2.6 M 26 ZeroCERT

3866 2020-12-22 12:22 DE4GKQWD8CA.doc  

a6e82e49f8fac750dea41d36e926f4d9


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
2 7 5 1 6.6 M 26 ZeroCERT

3867 2020-12-22 12:24 HM68DCU.doc  

4f0f77186bc4b10b8f897f0313c6cda5


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 9 4 1 6.6 M 28 ZeroCERT

3868 2020-12-22 13:30 OXZ5JY.doc  

4f0f77186bc4b10b8f897f0313c6cda5


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 7 4 1 6.6 M 28 guest

3869 2020-12-22 13:30 L8MICS8W8.doc  

ab0df6e0ad74541979d7eeaf71f88c74


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 5 4 1 6.6 M 22 guest

3870 2020-12-22 14:31 XZ30IV23MGAC.doc  

95f5812b150c3ddf46908e4d65efa830


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 5 4 1 6.6 M 28 guest