Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3916 2024-05-20 10:32 setup.exe  

5cc472dcd66120aed74de36341bfd75a


Generic Malware Malicious Library Antivirus AntiDebug AntiVM PE File PE32 PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger WMI Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Checks Bios powershell.exe wrote suspicious process WriteConsoleW anti-virtualization Windows ComputerName Cryptographic key
12.2 M 56 ZeroCERT

3917 2024-05-20 10:30 AppGate2103v01.exe  

5ede7f188f5353878c0e62808ce3e770


Generic Malware UPX MPRESS PE64 PE File OS Processor Check VirusTotal Malware heapspray unpack itself Windows Remote Code Execution crashed
4.8 M 21 ZeroCERT

3918 2024-05-20 10:28 GroceryExtensive.exe  

fb88fe2ec46424fce9747de57525a486


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
6.8 M 25 ZeroCERT

3919 2024-05-20 10:27 online_security_mkl.exe  

b80362872ea704846e892f16aab924c3


Generic Malware Malicious Library UPX PE File PE32 MZP Format OS Processor Check PE64 VirusTotal Malware Checks debugger unpack itself Check virtual network interfaces AppData folder Tofsee crashed
1 3 1 3.8 M 4 ZeroCERT

3920 2024-05-20 10:27 start-pub.exe  

52bcb73bddd7e3b613ec7fb1367c91c1


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 P VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key crashed
6 11 3 5 11.2 M 17 ZeroCERT

3921 2024-05-20 10:25 lumma1234.exe  

c4ffab152141150528716daa608d5b92


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself WriteConsoleW crashed
2.2 M 39 ZeroCERT

3922 2024-05-20 09:36 206.238.220.102.dll  

dc22b7f350d6cd3e08f155d26e431e3a


Malicious Library UPX PE File DLL DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware Checks debugger unpack itself Remote Code Execution DNS
1 3.6 M 53 ZeroCERT

3923 2024-05-20 08:59 csrss.exe  

591deb3212cb1720fa03640f6257b5dc


Browser Login Data Stealer Gen1 EnigmaProtector Generic Malware UPX Malicious Library Malicious Packer AntiDebug AntiVM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram MachineGuid Code Injection Malicious Traffic Check memory WMI Creates executable files unpack itself Collect installed applications suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 3 13 12.8 M 49 ZeroCERT

3924 2024-05-20 08:55 gena.exe  

e520f65d2af59a1c69a96809fd025d9b


EnigmaProtector Malicious Packer PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted unpack itself Windows utilities Collect installed applications suspicious process AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 5 7 13.4 M 46 ZeroCERT

3925 2024-05-20 08:55 sdf34ert3etgrthrthfghfghjfgh.e...  

7fce620eed38da6eb6552e1713e4fa84


Malicious Library Downloader Malicious Packer UPX PE File PE32 MZP Format OS Processor Check VirusTotal Malware Check memory unpack itself crashed
2.2 M 31 ZeroCERT

3926 2024-05-20 07:45 random.exe  

d0d9b758764ced5f38eddd0f9c765b79


Amadey Gen1 RedLine stealer RedlineStealer XMRig Miner Generic Malware NSIS Downloader Malicious Library UPX .NET framework(MSIL) Malicious Packer MPRESS Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal cr Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Cryptocurrency Miner Malware Cryptocurrency powershell Microsoft Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files ICMP traffic RWX flags setting unpack itself Windows utilities Disables Windows Security Checks Bios Collect installed applications Detects VMWare powershell.exe wrote Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VMware anti-virtualization VM Disk Size Check installed browsers check Kelihos Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed CoinMiner
35 45 22 32.2 M 42 ZeroCERT

3927 2024-05-20 07:42 1234.exe  

d3a80c7a3a80478b08cc17522a55bb44


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself DNS crashed
3 4.4 M 48 ZeroCERT

3928 2024-05-20 07:40 Document0984757478.exe  

c36f798f2646092c180c6fc904c418f7


Gen1 Process Kill Generic Malware Suspicious_Script_Bin Malicious Library FindFirstVolume CryptGenKey UPX Malicious Packer PE File Device_File_Check PE32 OS Processor Check DLL FormBook Browser Info Stealer Malware download VirusTotal Malware Checks debugger buffers extracted Creates executable files unpack itself AppData folder Browser DNS
12 22 3 7.2 M 47 ZeroCERT

3929 2024-05-20 07:40 build13.exe  

b99a7c6c9e6a2eb2945d894b2ce2c63b


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself DNS crashed
3 4.4 M 48 ZeroCERT

3930 2024-05-20 07:35 conhost.exe  

be320b59ef29060678bcb78d6c8fa059


Malicious Library UPX PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself crashed
2.0 20 ZeroCERT