Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
4081 2024-05-13 10:53 [Content_Types].xml  

ded1b06d92c5c6b15c0b12c176ff3355


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

4082 2024-05-13 09:27 Scanner.exe  

9de1ede890852d25d1a9a37561c85881


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
2.8 M 51 ZeroCERT

4083 2024-05-13 09:12 amers.exe  

802263fb14b84944b5d41a2abbb4cf55


Amadey RedLine stealer RedlineStealer Gen1 XMRig Miner Generic Malware NSIS Malicious Library .NET framework(MSIL) UPX Malicious Packer PE File PE32 .NET EXE OS Processor Check PE64 Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware Microsoft AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization VM Disk Size Check installed browsers check Kelihos Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
8 16 15 1 20.2 M 32 ZeroCERT

4084 2024-05-13 09:11 install.exe  

0f52e5e68fe33694d488bfe7a1a71529


Gen1 XMRig Miner Generic Malware Malicious Library UPX Malicious Packer PE File PE32 PE64 OS Processor Check VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files Windows utilities AppData folder AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check Windows DNS
1 6.6 M 48 ZeroCERT

4085 2024-05-13 09:09 leadiadequatepro.exe  

b149f82964b1e269ade2686612a9e777


Emotet Gen1 Hide_EXE Malicious Library UPX .NET framework(MSIL) PE64 PE File CAB OS Processor Check .NET EXE PE32 VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself AppData folder Windows ComputerName Remote Code Execution
5.0 M 44 ZeroCERT

4086 2024-05-13 09:07 toolspub1.exe  

6bcbbfac4eb7dbecb5a44983645a75db


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Remote Code Execution
2.2 M 44 ZeroCERT

4087 2024-05-13 09:07 alex.exe  

31841361be1f3dc6c2ce7756b490bf0f


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself DNS crashed
1 3.4 M 57 ZeroCERT

4088 2024-05-13 09:06 go.exe  

dc540b21dd7ea520b4390010baee443f


Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check MSOffice File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
8 6 1 5.8 M 17 ZeroCERT

4089 2024-05-13 09:04 swizzhis.exe  

808c0214e53b576530ee5b4592793bb0


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
2.8 M 41 ZeroCERT

4090 2024-05-13 09:02 poter.exe  

3acbdb001a0be2555921f0361189f9b5


EnigmaProtector Malicious Packer PE File PE32 Malware download VirusTotal Malware AutoRuns MachineGuid unpack itself Windows utilities suspicious process WriteConsoleW IP Check Tofsee Windows RisePro ComputerName DNS crashed
1 5 4 6.6 M 35 ZeroCERT

4091 2024-05-13 09:02 assistant_v7.exe  

008d9913e8ce8bb934b93c559a2e32fa


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.4 M 38 ZeroCERT

4092 2024-05-13 09:00 lenin.exe  

d8fb06472e78cb03a2f651dc9d1b05f1


Themida Packer Malicious Packer PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare suspicious process AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName Firmware DNS Software crashed
1 5 8 15.2 M 40 ZeroCERT

4093 2024-05-13 09:00 lumma1.exe  

56e7d98642cfc9ec438b59022c2d58d7


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
1 2.8 M 46 ZeroCERT

4094 2024-05-13 07:29 f.exe  

7b910a871a5bb36d8f47094f51eaac46


Generic Malware PE File PE32 VirusTotal Malware suspicious privilege suspicious process sandbox evasion WriteConsoleW shadowcopy delete Windows
4.2 55 ZeroCERT

4095 2024-05-13 07:27 e_win.exe  

7deb707e7d264c73ce6b4dd905b6465d


Generic Malware Antivirus PE File PE32 ftp wget VirusTotal Malware suspicious privilege suspicious process sandbox evasion WriteConsoleW shadowcopy delete Ransom Message Ransomware Windows crashed
7.2 56 ZeroCERT