Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
42766 2021-08-18 11:32 Insidious.exe  

f3d648c4f3a0f9cfbead90e546efe8f6


RAT PWS .NET framework Generic Malware UPX PE File OS Processor Check .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware PDB suspicious privilege MachineGuid Check memory Checks debugger unpack itself Check virtual network interfaces Browser Software crashed
4.4 M 47 ZeroCERT

42767 2021-08-18 11:31 winDriversavesruntimecrt.exe  

728f3575ead222e4e13b9558291547be


RAT Generic Malware UPX Malicious Packer PE File OS Processor Check .NET EXE PE32 VirusTotal Malware AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces AntiVM_Disk VM Disk Size Check Windows ComputerName DNS crashed
5 1 5 7.4 M 32 ZeroCERT

42768 2021-08-18 11:31 obinnazx.exe  

a3ab9dcf6e3ba0e1f026fcf4b18065a0


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
3 6 1 8.2 M 26 ZeroCERT

42769 2021-08-18 11:29 test.exe  

aba88ae23ef00a022dd6a09105b5a740


RAT Generic Malware UPX Malicious Packer PE File OS Processor Check .NET EXE PE32 VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces AntiVM_Disk IP Check VM Disk Size Check Tofsee Windows ComputerName DNS Cryptographic key crashed
3 3 3 5.8 M 48 ZeroCERT

42770 2021-08-18 11:28 hot.exe  

5fcbfeae2b818e9eab95723a87460401


UPX Malicious Library PE File OS Processor Check PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Malicious Traffic unpack itself DNS
3 7 1 3.8 M 32 ZeroCERT

42771 2021-08-18 11:26 BIN.exe  

2b26fb332ceca5db7983d7734d26db2d


RAT Generic Malware Admin Tool (Sysinternals etc ...) PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
2.8 M 39 ZeroCERT

42772 2021-08-18 11:26 osamazx.exe  

c0fc593778f04e09b617854121aaca04


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key crashed
9.4 M 40 ZeroCERT

42773 2021-08-18 11:25 ashleyzx.exe  

c36a8f55e7338503e15ef4d91bb39eff


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows utilities AppData folder Windows Cryptographic key
7 15 1 3 11.2 M 23 ZeroCERT

42774 2021-08-18 11:24 kbinzx.exe  

3038c63be8eb4248dcb08e75fa8da3c1


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName DNS Cryptographic key crashed
1 11.0 M 42 ZeroCERT

42775 2021-08-18 11:22 tzd.exe  

fb4b33133ac61d537322520e6aacdf44


RAT Generic Malware Admin Tool (Sysinternals etc ...) PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
2.8 M 39 ZeroCERT

42776 2021-08-18 11:22 arinzezx.exe  

35f1d0f2f60b193c004a81b219c0dcc7


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 12.8 M 35 ZeroCERT

42777 2021-08-18 11:20 JABKA9983.exe  

2093d467e65e9dbad2a55577d9f8d396


RAT PWS .NET framework Generic Malware UPX Malicious Library VMProtect PE File OS Processor Check .NET EXE PE32 DLL Browser Info Stealer FTP Client Info Stealer VirusTotal Malware AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder suspicious TLD installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
3 5 4 11.6 M 48 ZeroCERT

42778 2021-08-18 11:20 cd13.exe  

af366ca287f4fff65e730d609d3f6bd2


RAT PWS .NET framework Generic Malware UPX PE File OS Processor Check .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 2 6.2 M ZeroCERT

42779 2021-08-18 11:19 rcd.exe  

679b38d3297913cec51412919546f0fc


RAT PWS .NET framework Generic Malware UPX PE File OS Processor Check .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 2 7.4 M 43 ZeroCERT

42780 2021-08-18 11:07 vbc.exe  

24de92095889ef49c35dcc6f687627e5


RAT PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
1 2 1 12.0 M 27 ZeroCERT