Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
42871 2021-08-15 12:49 felix1008.exe  

f37bc82cabddf6a2435471b1ccaabd28


NPKI RAT Generic Malware Malicious Library UPX DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM PE Browser Info Stealer FTP Client Info Stealer VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 4 2 14.0 M 38 ZeroCERT

42872 2021-08-15 12:47 22.exe  

bb01110f000d6a06eb3bce0024aaedc1


RAT Generic Malware PE File PE64 VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself Windows Cryptographic key
3.0 M 30 ZeroCERT

42873 2021-08-15 12:46 file.exe  

4538e3df24ed8b8cd6a3474b2f0e1f74


UPX Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.2 M 24 ZeroCERT

42874 2021-08-15 12:45 wj1.png  

b3edf0682d10790927ec8cdf5f1f187e


PE File DLL PE32 VirusTotal Malware Checks debugger WMI unpack itself ComputerName crashed
3.4 M 28 ZeroCERT

42875 2021-08-15 12:44 lv.exe  

5da707c4db06e0549e3c2067df1a0256


Emotet Gen1 Gen2 Malicious Library UPX Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
1 7.4 M 42 ZeroCERT

42876 2021-08-15 12:43 lv.exe  

82e9bcd3cc8af226349d5f310b452213


Emotet Gen1 Gen2 Malicious Library UPX Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows DNS
2 7.0 M 19 ZeroCERT

42877 2021-08-15 12:41 sefile.exe  

970dac7d9d006a955e21a10241c65afc


UPX Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.2 M 24 ZeroCERT

42878 2021-08-15 12:41 svchost.exe  

4197eeb783ac6250fe918d469d0805f0


RAT Generic Malware DNS Socket Create Service BitCoin Escalate priviledges KeyLogger Code injection AntiDebug AntiVM PE File PE64 VirusTotal Malware AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Auto service Check virtual network interfaces suspicious process malicious URLs sandbox evasion WriteConsoleW Tofsee Windows Browser ComputerName Firmware
1 6 1 15.0 M 41 ZeroCERT

42879 2021-08-15 12:39 toolspab2.exe  

ea15500c87c5662e58d8539b47ff988c


UPX Malicious Library AntiDebug AntiVM PE File OS Processor Check PE32 VirusTotal Malware PDB Code Injection Checks debugger buffers extracted unpack itself
7.2 M 24 ZeroCERT

42880 2021-08-15 12:39 lv.exe  

39d1258b4cc2d9085157dc6c8e84f0fe


Emotet Gen1 Gen2 Malicious Library UPX Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
1 6.6 M 41 ZeroCERT

42881 2021-08-15 12:37 twixrf.exe  

f78f2e70b20587810b755e56821a0363


RAT PWS .NET framework Generic Malware UPX PE File OS Processor Check .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 2 7.4 M 43 ZeroCERT

42882 2021-08-15 12:37 wj3.png  

9dc3016597dfa1aa2980b346d16bebec


UPX Malicious Library PE File OS Processor Check DLL PE32 VirusTotal Malware Checks debugger unpack itself
1.8 M 16 ZeroCERT

42883 2021-08-15 12:36 5674d7511aa1fce0a68969dc57375b...  

7532236d0a13e60372fe249271fc4fd8


UPX Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.0 16 ZeroCERT

42884 2021-08-15 12:33 jushenkotak.exe  

4ff6c915da988f6746263dc2eb000261


NPKI RAT Generic Malware Malicious Library UPX DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM PE VirusTotal Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName
3 3 1 9.6 32 ZeroCERT

42885 2021-08-15 12:33 tonys1008.exe  

a08fedd1af1461cd057783b833b75c1a


NPKI RAT Generic Malware Malicious Library UPX Anti_VM DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug A Browser Info Stealer FTP Client Info Stealer VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 4 2 12.8 26 ZeroCERT