Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
39916 2021-10-30 11:44 AsyncClient6121.exe  

4c2634725187d2ccebaaaf92b231a1f0


RAT PWS .NET framework Generic Malware task schedule Malicious Packer Malicious Library UPX Create Service DGA Socket Steal credential DNS Internet API Code injection Sniff Audio HTTP KeyLogger FTP Escalate priviledges Downloader ScreenShot Http API P2P A Malware download AsyncRAT Dridex NetWireRC TrickBot VirusTotal Malware AutoRuns Code Injection Windows utilities suspicious process AppData folder WriteConsoleW Kovter Windows ComputerName DNS DDNS
2 3 5.2 44 ZeroCERT

39917 2021-10-30 11:41 nano6129.exe  

4c342f040ad8b94e4f814e1f62e488ed


Generic Malware Malicious Packer PE File PE32 .NET EXE Malware download Nanocore VirusTotal Malware c&c Buffer PE AutoRuns suspicious privilege MachineGuid Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
2 2 10.0 56 ZeroCERT

39918 2021-10-29 21:37 temp.dll  

1788ff60c96f28ec0386a838edaa48fb


Malicious Library UPX PE64 PE File OS Processor Check DLL VirusTotal Malware unpack itself WriteConsoleW crashed
2.0 2 guest

39919 2021-10-29 18:35 bypass.txt.ps1  

529abb09970a8b6464375da0613893ea


Generic Malware Antivirus VirusTotal Malware powershell Malicious Traffic Check memory buffers extracted unpack itself Check virtual network interfaces WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 1 5.4 12 ZeroCERT

39920 2021-10-29 18:33 temp.dll  

388c3456276b8e6e9fa8a827c4f37a76


TA551 BazarLoader PE64 PE File DLL VirusTotal Malware Check memory ICMP traffic unpack itself Windows utilities Windows
3.2 16 ZeroCERT

39921 2021-10-29 18:31 .csrss.exe  

4fb2f672e188592f43da7b4c6d64e80e


PWS Loki[b] Loki.m RAT Generic Malware UPX Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 2 6 1 13.6 M 13 ZeroCERT

39922 2021-10-29 18:30 test.exe  

5dfe5aee3f22321fe7efbb310a79a235


Malicious Library PE64 PE File VirusTotal Malware MachineGuid RWX flags setting Tofsee ComputerName
1 2 1 3.2 51 ZeroCERT

39923 2021-10-29 18:29 vbc.exe  

ca3406debaf00a3dda67a24153c4b2a8


NSIS Malicious Library UPX PE File PE32 OS Processor Check DLL Dridex TrickBot VirusTotal Malware Code Injection Check memory Creates executable files unpack itself AppData folder Kovter
2 1 5.4 32 ZeroCERT

39924 2021-10-29 18:27 B86b0mDlYqpH2306105pdf.exe  

ff8d08be90a98bf46f8f359ee4cb35f7


RAT PWS .NET framework Generic Malware Malicious Packer Malicious Library UPX Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE GIF Format Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW IP Check VM Disk Size Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 17.4 30 ZeroCERT

39925 2021-10-29 18:25 ConsoleApp11.exe  

cc63cb7d19ca8cffa27530b760c81528


RAT Generic Malware UPX AntiDebug AntiVM PE File PE32 .NET EXE DLL Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Stealer Windows Browser Email ComputerName DNS Cryptographic key crashed
3 5 5 17.2 M 19 ZeroCERT

39926 2021-10-29 18:25 .csrss.exe  

c2c509a61a1d811d29ade6067e54c011


Loki PWS Loki[b] Loki.m RAT Generic Malware UPX Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName Software
2 2 7 1 14.4 14 ZeroCERT

39927 2021-10-29 18:22 vbc.exe  

cd848603273b1d0f6227a7ef17180cc9


Loki PWS Loki[b] Loki.m RAT Generic Malware UPX Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName Software
2 2 7 1 12.8 18 ZeroCERT

39928 2021-10-29 18:22 vbc.exe  

d031d354378993ddf3aca597f723b301


Loki NSIS Malicious Library UPX PE File PE32 OS Processor Check DLL Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Creates executable files unpack itself AppData folder installed browsers check Browser Email ComputerName DNS Software
2 2 10 1 10.0 26 ZeroCERT

39929 2021-10-29 18:20 adal.jar  

e83ec42ad9c282b28e4561dc5fec346d

VirusTotal Malware Check memory heapspray unpack itself Java
2.2 19 ZeroCERT

39930 2021-10-29 18:20 rundll32.exe  

5273a14914db4656593872056f2ced12


RAT PWS .NET framework Generic Malware PE File PE32 .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself
5.2 16 ZeroCERT