Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3991 2020-12-29 12:31 ask.exe  

08ce06744e5fa947d7639cf606c4ff5c


VirusTotal Malware DNS
1.8 21 ZeroCERT

3992 2020-12-29 13:05 Arcserve_Unified_Data_Protecti...  

d41d8cd98f00b204e9800998ecf8427e

0.4 guest

3993 2020-12-29 14:39 askinstall102.exe  

dee19dc1523b455fe966856b1e40c318


VirusTotal Malware unpack itself malicious URLs
3.2 M 39 ZeroCERT

3994 2020-12-29 14:42 askinstall5.exe  

1700d52ae8e1b07c16d2efbd2439fc7d


Browser Info Stealer VirusTotal Malware PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Checks debugger WMI Creates executable files exploit crash unpack itself Windows utilities suspicious process AppData folder malicious URLs suspicious TLD WriteConsoleW installed browsers check Tofsee Ransomware Windows Exploit Browser ComputerName Remote Code Execution DNS crashed
4 8 3 14.0 47 ZeroCERT

3995 2020-12-29 14:50 200k.exe  

b66dbb305a9c9454b5dd5a894d257dbc


unpack itself
2.2 ZeroCERT

3996 2020-12-29 14:53 a.exe  

15957b219a58f8a3379a7fe9eb5dd1b4


Malware download Amadey FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows Email ComputerName Software
3 2 3 10.8 M 50 ZeroCERT

3997 2020-12-29 15:16 pic.gif  

b7e359f7786b76b7657659e7a6f12a5f


VirusTotal Malware unpack itself
1.6 M 9 guest

3998 2020-12-29 15:48 Gj9giC7OQR.dll  

478876fb3045479a977aec13ec429c7c


VirusTotal Malware
0.8 M 6 ZeroCERT

3999 2020-12-29 15:50 backupss.exe  

b5694bcb27502718430e41427126deb9


VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName Cryptographic key
12.4 M 35 ZeroCERT

4000 2020-12-29 15:59 Q76T.dll  

bf6a524f5543cde20b6fb911edb2a467

0.4 guest

4001 2020-12-29 16:01 Q76T.dll  

bf6a524f5543cde20b6fb911edb2a467

0.4 guest

4002 2020-12-29 16:03 Q76T.dll  

bf6a524f5543cde20b6fb911edb2a467

0.4 guest

4003 2020-12-29 16:04 Q76T.dll  

bf6a524f5543cde20b6fb911edb2a467

0.4 guest

4004 2020-12-29 16:05 Q76T.dll  

bf6a524f5543cde20b6fb911edb2a467


unpack itself crashed
1.4 guest

4005 2020-12-29 16:11 backupss.exe  

b5694bcb27502718430e41427126deb9


VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName Cryptographic key
12.4 M 35 ZeroCERT