Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44116 2021-01-05 15:45 Admin_Tools.exe  

1729da629b8b7da6915f50f95ef9204d


Browser Info Stealer FTP Client Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process malicious URLs installed browsers check Tofsee Ransomware Windows Browser ComputerName Remote Code Execution Cryptographic key Software crashed
2 8 2 11.8 9 guest

44117 2021-01-05 14:10 UKGHJ90ZEO3Y15PL.doc  

80509f5c54210bfa15c8bf805566c0bf


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 3 4 1 5.2 M 20 ZeroCERT

44118 2021-01-05 14:05 rc2.exe  

e3b457925bc3cba3821b5bdb00bdefc2


Emotet VirusTotal Malware Buffer PE AutoRuns Code Injection buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities malicious URLs Tofsee Interception Windows
1 7 1 11.6 M 13 ZeroCERT

44119 2021-01-05 14:05 rc.exe  

050e7be5bddc176e82d0ff30ac4791a0


Emotet VirusTotal Malware Buffer PE AutoRuns Code Injection buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities AppData folder malicious URLs Tofsee Interception Windows DNS
1 7 1 12.2 M 45 ZeroCERT

44120 2021-01-05 13:52 open.exe  

9e4a36969d6edc82ee97420dccd5ae94


Dridex VirusTotal Malware Buffer PE AutoRuns Code Injection buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder malicious URLs Tofsee Windows Exploit DNS crashed
1 2 3 10.6 M 11 ZeroCERT

44121 2021-01-05 13:51 PDFView.exe  

5550592bb2d7a6a4226975d1c80ac7a4


VirusTotal Malware PDB malicious URLs Remote Code Execution
2.4 M 19 ZeroCERT

44122 2021-01-05 13:22 LPXG5NYP6IOKKZ.doc  

413be7b6ad6a700647c63d645442db4b


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Tofsee Windows DNS
4 5 5 1 5.2 M 20 ZeroCERT

44123 2021-01-05 13:22 LwtKphm0VioM5i.dll  

01a02861ee9e23fc4c44bd829ee5c69c


VirusTotal Malware Malicious Traffic Checks debugger RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 6.0 M 9 ZeroCERT

44124 2021-01-05 12:28 JIYAOcNz9PnnHBPR8IE.dll  

8c5d3647e0f6ddc816f68672d676e185


Malware Malicious Traffic Checks debugger RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 1 6.2 M ZeroCERT

44125 2021-01-05 12:27 file2.exe  

cda50506fc8222349a4075117a896310


VirusTotal Malware RWX flags setting unpack itself malicious URLs Interception crashed
2 4.0 M 16 ZeroCERT

44126 2021-01-05 12:24 ds12.exe  

cffaa868ac7a83f2445cb1560cee3018


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself malicious URLs DNS crashed
9.0 M 18 ZeroCERT

44127 2021-01-05 12:24 ds2.exe  

a2a8aec5eb32af3ed72c1b9a13bbead5


VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Disables Windows Security powershell.exe wrote suspicious process malicious URLs Windows ComputerName Cryptographic key
11.2 M 55 ZeroCERT

44128 2021-01-05 11:32 aLOKKbSPhUWqcVCXI.dll  

ecad7f36a5e3c8fe798c5b04b50cd1a4


VirusTotal Malware Malicious Traffic Checks debugger RWX flags setting unpack itself malicious URLs sandbox evasion Windows Advertising ComputerName DNS Cryptographic key
1 1 1 6.8 M 12 ZeroCERT

44129 2021-01-05 11:32 ds1.exe  

923949852c2c3ee9e6badc9d8461bd34


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself malicious URLs crashed
10.0 M 48 ZeroCERT

44130 2021-01-05 10:13 ac2.exe  

b16432bd584c9117d4dee9abc137499c


VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS
3 13.4 M 53 ZeroCERT