Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44071 2024-05-01 16:55 svchostMon.exe  

f5a52d7f38e29a3749139aef116c1809


PE64 PE File Malware download Amadey VirusTotal Cryptocurrency Miner Malware Malicious Traffic unpack itself DNS CoinMiner SilentCryptoMiner
1 5 3 3.0 M 54 ZeroCERT

44072 2024-05-01 16:56 shitload.exe  

36010b83bccfcd1032971df9fc5082a1


Worm Phorpiex Generic Malware Malicious Library Downloader Admin Tool (Sysinternals etc ...) Malicious Packer UPX PE File PE32 Malware download VirusTotal Malware Buffer PE AutoRuns Malicious Traffic Checks debugger buffers extracted Creates executable files ICMP traffic Disables Windows Security AppData folder Windows Update DNS
9 25 4 3 13.8 M 57 ZeroCERT

44073 2024-05-01 16:57 iwanttokiswithlotoflovesheismy...  

d1ff78be8248efe25e0710b7508f4d59


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit DNS crashed
2 4 2 5.0 M 37 ZeroCERT

44074 2024-05-01 16:57 realtekmonitor.exe  

6adbec7e5713644931e8e5815ed56356


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware
1.4 M 24 ZeroCERT

44075 2024-05-01 16:59 wearegoingtobegoodwithmebecaus...  

f34f96b8cd842e5709a476360c30a4d2


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed Downloader
1 7 5.0 M 37 ZeroCERT

44076 2024-05-01 17:00 jfesawdr.exe  

9fb56dd5b5beb0b9c5d0102f22373c0b


Generic Malware Downloader Malicious Library UPX VMProtect Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 OS Processo VirusTotal Malware PDB Code Injection Creates executable files unpack itself AppData folder ComputerName Remote Code Execution
4.6 M 47 ZeroCERT

44077 2024-05-01 17:01 softmindwithagoodheartpersonwi...  

086511c0267905cbda55ede83eb8d7d0


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 5.0 M 37 ZeroCERT

44078 2024-05-01 17:01 bin.exe  

4160db87b054d159be5eb8ee4cd27c38


Generic Malware Malicious Library .NET framework(MSIL) AntiDebug AntiVM PE File .NET EXE PE32 DLL Browser Info Stealer VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder suspicious TLD Browser DNS
21 21 2 11.0 M 49 ZeroCERT

44079 2024-05-01 17:02 fishermansaidyouaremyloverbeca...  

1d4987e736173e36c054c48f4354ab4d


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 4 2 5.0 M 35 ZeroCERT

44080 2024-05-01 17:04 wedesingedfisherboattoundersta...  

0930bc0ba7c5af0fd2ee2a78a98faa22


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 3 2 5.0 M 37 ZeroCERT

44081 2024-05-02 07:20 scg.exe  

9e5e6b8901f999088856e0eb04746864


Malicious Library Malicious Packer UPX PE64 PE File VirusTotal Malware MachineGuid
2 3.2 44 ZeroCERT

44082 2024-05-02 07:20 see.exe  

e908276b036728bc78a3dea637580af2


AgentTesla Generic Malware Malicious Library .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
1 2 3 13.2 32 ZeroCERT

44083 2024-05-02 07:22 jSB8SNaV.exe  

af593a9f7ef816da78b444227537c5f2


Gen1 Generic Malware Malicious Library Malicious Packer UPX PE64 PE File OS Processor Check VirusTotal Malware PDB
1.6 36 ZeroCERT

44084 2024-05-02 07:23 get.php  

378532ba8c8073c2639528b08b15047b


Malicious Library PE File .NET EXE PE32 Malware download njRAT VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself DNS
3 3 2.8 61 ZeroCERT

44085 2024-05-02 07:24 HJCC.exe  

f28b5bcde00e5c363cb764426ec76324


AgentTesla Malicious Library Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName Cryptographic key Software crashed
12.6 51 ZeroCERT