Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
43741 2024-04-03 07:29 XClient.exe  

109adf5a32829b151d536e30a81ee96b


Generic Malware Malicious Library Antivirus UPX PE File .NET EXE PE32 OS Processor Check Lnk Format GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName Cryptographic key
8.4 M 57 ZeroCERT

43742 2024-04-03 07:31 Update.exe  

458cd83e99d40276aec2e4b228a489f9


Generic Malware Malicious Library UPX Antivirus AntiDebug AntiVM PE64 PE File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security powershell.exe wrote suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 1 10.6 M 56 ZeroCERT

43743 2024-04-03 07:33 conan.exe  

324b6dc1d74d0fa83010c59562203b31


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.2 M 57 ZeroCERT

43744 2024-04-03 07:35 5.exe  

cfd2733ba128f49a373042a1a6c3fe19


Craxs RAT PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
3.0 M 41 ZeroCERT

43745 2024-04-03 07:37 poc.exe  

7098e2467a9d9569b0a8054b2d9d3e96


PE64 PE File
0.4 M ZeroCERT

43746 2024-04-03 07:40 njhor.exe  

20d4f344fa2a4ad4cb48d90abfbab41f


njRAT backdoor Generic Malware Antivirus PE File .NET EXE PE32 PowerShell Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security powershell.exe wrote suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
1 5 2 11.6 M ZeroCERT

43747 2024-04-03 07:42 2.exe  

ed5d5872da0c90cfa64cdbf0afe49ee1


Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check .NET EXE PDB suspicious privilege Code Injection Check memory Checks debugger Creates executable files unpack itself WriteConsoleW Remote Code Execution
5.4 M ZeroCERT

43748 2024-04-03 07:44 poc.exe  

7098e2467a9d9569b0a8054b2d9d3e96


PE64 PE File
0.4 M ZeroCERT

43749 2024-04-03 07:46 Locker.exe  

45ec0c61105121da6fed131ba19a463b


UPX PE File .NET EXE PE32 OS Processor Check MachineGuid Check memory Checks debugger buffers extracted unpack itself Ransomware Windows Cryptographic key
3.0 M ZeroCERT

43750 2024-04-03 13:41 FVr.xls  

7ed6ac58a23ab36e89c5516c56af920d


PE File DLL PE32 .NET DLL VirusTotal Malware PDB DNS
1 1.8 M 39 ZeroCERT

43751 2024-04-03 13:42 retail.php  

bf0137e15637ddd2eefc0922092ba059


Malicious Library Malicious Packer PE File PE32 ZIP Format PNG Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency MachineGuid Check memory buffers extracted Creates shortcut RWX flags setting unpack itself Checks Bios Collect installed applications Detects VirtualBox Detects VMWare AntiVM_Disk sandbox evasion VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName Firmware DNS Software crashed
1 5 8 14.6 36 ZeroCERT

43752 2024-04-03 13:43 space.php  

1f3e864a338535e78391706a36779415


Craxs RAT Malicious Library Malicious Packer PE File PE32 ZIP Format .NET EXE PNG Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName Firmware DNS Software crashed
3 7 10 19.2 34 ZeroCERT

43753 2024-04-03 13:43 download.php  

f29bb9918f3803046c2bab24c20b458d


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
2.0 M 33 ZeroCERT

43754 2024-04-03 13:44 X5a.xls  

6a2575c58e16930a2c7d55cc51f6ac18


PE File DLL PE32 .NET DLL VirusTotal Malware PDB
1.0 M 27 ZeroCERT

43755 2024-04-03 13:44 Sjtsv.exe  

b14b3b1da5e2b04f3ddf04f55a090bd8


PE64 PE File VirusTotal Cryptocurrency Miner Malware Cryptocurrency Buffer PE AutoRuns suspicious privilege Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key CoinMiner
4 2 4.2 M 25 ZeroCERT