Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3931 2020-12-24 09:47 https://popcash.net/world/go/2...  

20a9e246228be4bbb6c098ff278257f3


Dridex VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
3 8 3 4.6 M ZeroCERT

3932 2020-12-24 10:23 55555555555.jpg.exe  

c7f979b367bf63800dda59db4898321b


DNS
1.2 ZeroCERT

3933 2020-12-24 10:24 ac.exe  

d48449979ab0c5751e432b6743268ccd


VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
2 12.4 M 34 ZeroCERT

3934 2020-12-24 10:27 aguerox.scr  

90b585b2f2737b2c4492708b54c9359d


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Ransomware Windows Browser Tor Email ComputerName Cryptographic key Software crashed keylogger
2 4 1 14.6 M 23 ZeroCERT

3935 2020-12-24 10:31 ascvjkfd.exe  

115d4ac308403ea6cffaf5d7ff23a501


Browser Info Stealer Emotet Malware download FTP Client Info Stealer Vidar Azorult VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency powershell Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Collect installed applications powershell.exe wrote Check virtual network interfaces suspicious process AppData folder malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Ransomware Interception Zeus OskiStealer Stealer Windows Browser Email ComputerName DNS Cryptographic key Software Downloader
12 10 9 29.2 M 25 ZeroCERT

3936 2020-12-24 10:37 ds2.exe  

909bafa3ad6f8f92a6a3f6e43657766b


VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Disables Windows Security powershell.exe wrote suspicious process malicious URLs Windows ComputerName Cryptographic key
10.8 M 27 ZeroCERT

3937 2020-12-24 10:37 ds1.exe  

a17b2168e387499d984ce735b429c203


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself malicious URLs DNS crashed
9.4 M 33 ZeroCERT

3938 2020-12-24 10:52 ds1.exe  

a17b2168e387499d984ce735b429c203


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself malicious URLs crashed
8.8 M 33 ZeroCERT

3939 2020-12-24 10:52 ds2.exe  

909bafa3ad6f8f92a6a3f6e43657766b


VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Disables Windows Security powershell.exe wrote suspicious process malicious URLs Windows ComputerName DNS Cryptographic key
11.4 M 27 ZeroCERT

3940 2020-12-24 11:28 Hiring & Working Conditions..d...  

e7f658ee69fb3bb6f5bd9ae81d2400cd


Vulnerability VirusTotal Malware unpack itself malicious URLs
4.0 M 26 ZeroCERT

3941 2020-12-24 11:28 fJFvQerztXQCWBaMQcu6.dll  

43af5eee7704a7ce4914a279dad5b8c7


VirusTotal Malware Malicious Traffic Checks debugger RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
2 7.8 M 13 ZeroCERT

3942 2020-12-24 13:39 I6NABH.doc  

15bbcf602204407d7e9acb87b6f16920


Vulnerability VirusTotal Malware unpack itself malicious URLs DNS
4.0 M 22 ZeroCERT

3943 2020-12-24 13:40 Notificacao-Judicial.doc  

cd929ccba2c3615256dcbf4ea0ef8062


Vulnerability VirusTotal Malware Creates executable files unpack itself malicious URLs
4.6 M 33 ZeroCERT

3944 2020-12-24 13:42 yarobelo.scr  

c7c46db118df6a8d6c9deb69fa6b765b


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Ransomware Windows Browser Tor Email ComputerName Cryptographic key Software crashed keylogger
2 4 1 15.0 M 18 guest

3945 2020-12-24 13:44 7f38e3a99fb22f52_ms.exe  

d346cb431e94bc1c8399fecfc7db0e84


PDB Check memory RWX flags setting unpack itself Remote Code Execution DNS
1 2.2 ZeroCERT