Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
41236 2021-09-23 17:13 vbc.exe  

1c3047465bb31dd2ac45101680301992


PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself ComputerName
9 12 1 9.4 26 ZeroCERT

41237 2021-09-23 17:12 rundll32.exe  

cf830ea1d8bb5b8e007a18559f626a8c


PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself
8.0 17 ZeroCERT

41238 2021-09-23 16:21 sss.exe  

86e23a23cfe74c3076103ae580c0621c


RAT Generic Malware Antivirus Malicious Packer PE64 PE File VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
7.4 43 ZeroCERT

41239 2021-09-23 15:55 specification-1114748542.xls  

bcf85cb453a5827d672791aa29c7f398


MSOffice File RWX flags setting unpack itself suspicious process Tofsee
3 5 2 1 4.0 M ZeroCERT

41240 2021-09-23 15:41 kinsing  

648effa354b3cbaad87b45f48d59c616


Generic Malware Malicious Packer Anti_VM ELF VirusTotal Malware crashed
1.2 M 38 Kim.GS

41241 2021-09-23 10:10 file6.exe  

a92ecf7fef1451c1ebd6f7886a9e22d5


MPRESS PE File PE32 VirusTotal Malware Malicious Traffic unpack itself Checks Bios Detects VirtualBox Detects VMWare VMware anti-virtualization Tofsee Windows Firmware crashed
1 2 1 6.8 M 31 r0d

41242 2021-09-23 09:34 specification-1115180443.xls  

fd6cc864407f1dbd7e1bb73100f7fd58


MSOffice File RWX flags setting unpack itself suspicious process Tofsee
3 5 2 4.0 guest

41243 2021-09-23 09:32 specification-1114748542.xls  

bcf85cb453a5827d672791aa29c7f398


KeyLogger ScreenShot AntiDebug AntiVM MSOffice File Code Injection unpack itself
2.0 guest

41244 2021-09-23 09:32 0922_2541267277276.doc  

93cf89d232b8e35b0de0b11d1b99f680


VBA_macro Generic Malware MSOffice File GIF Format Malware Malicious Traffic Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic RWX flags setting unpack itself Check virtual network interfaces suspicious TLD IP Check ComputerName
3 5 1 8.6 guest

41245 2021-09-23 09:19 sdf.wbk  

5a90386e6f0f0e9b7f60409fdcfcb597


Lokibot RTF File doc AntiDebug AntiVM LokiBot Malware download VirusTotal Malware c&c MachineGuid Malicious Traffic Check memory exploit crash unpack itself Windows Exploit DNS crashed Downloader
2 3 13 1 5.2 M 27 ZeroCERT

41246 2021-09-23 09:19 vbc.exe  

78655ced01a57dc43915294cc1e5d887


Malicious Library PE File OS Processor Check PE32 PDB unpack itself RCE
1.6 M ZeroCERT

41247 2021-09-23 09:08 vbc.exe  

a4906a4f5ece9910c5d49e2cfea35ee3


PWS .NET framework Generic Malware PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself ComputerName
5.6 M 15 ZeroCERT

41248 2021-09-23 09:06 nd.exe  

04b038bcd154d89ee1e7758d734c0766


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName crashed
10.4 M 30 ZeroCERT

41249 2021-09-23 09:05 bie.exe  

19892e4eaa5acc4d15853a76566ac7c5


Generic Malware UPX Malicious Library PE File OS Processor Check PE32 PE64 DLL VirusTotal Malware AutoRuns suspicious privilege WMI Creates executable files Windows utilities WriteConsoleW Windows ComputerName RCE
2 7.0 M 58 ZeroCERT

41250 2021-09-23 09:04 vbc.exe  

7d61098bd6413d9eaa84abca69c207b9


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself RCE DNS
1 3.0 M 50 ZeroCERT