Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44131 2021-01-05 10:11 ac.exe  

29e43b9937420f643f53af873c84b858


VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
3 11.0 M 20 ZeroCERT

44132 2021-01-05 10:09 A8QXXV0I33NDQDZ.doc  

faf2165619d1daa46b0d172147a52541


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
1 3 4 1 5.2 M 21 ZeroCERT

44133 2021-01-05 09:49 3DSXMACC6MUCS0N.doc  

379b78c9d16039d7993e1e7703c2d524


Vulnerability VirusTotal Malware Malicious Traffic unpack itself malicious URLs Windows DNS
3 4 5.2 M 21 ZeroCERT

44134 2021-01-05 08:03 http://menol.eu/wp/mT/  

14f59a1ea2283c858ea95fc4b14e719c


Dridex VirusTotal Malware Code Injection Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Tofsee Windows Exploit DNS crashed
2 6 5.0 M ZeroCERT

44135 2021-01-04 22:38 SGHKTD.exe  

62e18a39916c9bf82ef1b8d19d429925


AutoRuns Check memory Checks debugger WMI Creates shortcut Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check human activity check Windows ComputerName DNS DDNS
2 1 9.4 M ZeroCERT

44136 2021-01-04 22:31 qf2rlXEs14oPFz6.exe  

f697a082ed2e8ce81ee8bb46fe8b6896


suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Checks Bios Detects VirtualBox suspicious process AppData folder malicious URLs WriteConsoleW VMware anti-virtualization Windows ComputerName DNS Software
14.4 M ZeroCERT

44137 2021-01-04 22:31 scriptxls_4e270c39-ab5b-40af-9...  

5ac28f78814ba152cbeb7ca435cc32fe


VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Tofsee Windows ComputerName Cryptographic key
4 2 8.2 M 1 ZeroCERT

44138 2021-01-04 22:23 PROYECTO_FINAL_WF_1.exe  

8b3404eba184e959ce1975a34dc5399a


Malware PDB suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself malicious URLs human activity check Tofsee ComputerName
2 6 1 3.6 M ZeroCERT

44139 2021-01-04 22:23 po.exe  

145d08f897eb350ba87e8003ff45723e


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Checks debugger unpack itself malicious URLs Tofsee Windows Browser Email ComputerName DNS Software crashed
4 2 4 9.6 M 53 ZeroCERT

44140 2021-01-04 22:18 Order.exe  

ff54a5c5816d0bbb3722a504f9979fdd


Buffer PE AutoRuns suspicious privilege MachineGuid Check memory Checks debugger buffers extracted unpack itself human activity check Windows ComputerName DNS DDNS
2 1 8.4 M ZeroCERT

44141 2021-01-04 22:18 me.exe  

421de22e246d416e7309e54268052ada


suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
10.4 M ZeroCERT

44142 2021-01-04 22:15 GWqhcX68z24xeAO.exe  

88d3d51b7b9153aa613d4ce1253ba022


suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Ransomware Windows ComputerName DNS keylogger
1 3 1 14.2 M ZeroCERT

44143 2021-01-04 22:14 me.exe  

421de22e246d416e7309e54268052ada


suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
10.4 M ZeroCERT

44144 2021-01-04 22:07 me.exe  

421de22e246d416e7309e54268052ada


suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
10.4 M ZeroCERT

44145 2021-01-04 22:06 GWqhcX68z24xeAO.exe  

88d3d51b7b9153aa613d4ce1253ba022


suspicious privilege Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS
9.0 M ZeroCERT