Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44251 2024-05-12 19:12 beautifulthingshappenedwithgre...  

0a95eb4fe0f14eeb018e0f9488261092


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit DNS crashed
2 3 2 4.4 M 21 ZeroCERT

44252 2024-05-12 19:14 crypted.exe  

796cbba02beaae7cdffd1e5afa234fcb


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 50 ZeroCERT

44253 2024-05-12 19:15 file.exe  

4de76ad34e9ccffc91bbec7a3c4e79e0


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.6 M 45 ZeroCERT

44254 2024-05-12 19:17 update_3.exe  

701681a2abe57ee6dd443b0174fc8706


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware
1.8 M 34 ZeroCERT

44255 2024-05-12 19:17 xplugzx.scr  

98b68b6a40d3ad9c093efcb2a2a15eb0


AgentTesla Malicious Library .NET framework(MSIL) UPX PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Browser Email ComputerName DNS Software crashed
1 11.2 M 49 ZeroCERT

44256 2024-05-12 22:13 Video.scr  

a20727b81b50a20483ba59ae65443dfe


Gen1 Generic Malware Malicious Library UPX PE File PE32 OS Processor Check DLL .NET DLL Malware download VirusTotal Malware AutoRuns suspicious privilege Check memory Creates executable files ICMP traffic unpack itself suspicious process AppData folder anti-virtualization Windows ComputerName DNS Mozi Botnet
1 3411 10 9.8 58 ZeroCERT

44257 2024-05-12 22:55 CShield.dll  

db5198ea4d04bad9c91dc04ba2033579


Malicious Library PE File DLL PE32 VirusTotal Malware Check memory crashed
1.8 M 23 guest

44258 2024-05-12 22:58 CShield.dll  

db5198ea4d04bad9c91dc04ba2033579


Malicious Library PE File DLL PE32 VirusTotal Malware Check memory crashed
1.8 M 23 guest

44259 2024-05-13 07:25 pclient.exe  

ae13c23cad4370cdaaaa690a8a7e3c14


Generic Malware Malicious Library UPX PE64 PE File OS Processor Check VirusTotal Malware Check memory crashed
1.6 M 10 ZeroCERT

44260 2024-05-13 07:27 e_win.exe  

7deb707e7d264c73ce6b4dd905b6465d


Generic Malware Antivirus PE File PE32 ftp wget VirusTotal Malware suspicious privilege suspicious process sandbox evasion WriteConsoleW shadowcopy delete Ransom Message Ransomware Windows crashed
7.2 56 ZeroCERT

44261 2024-05-13 07:29 f.exe  

7b910a871a5bb36d8f47094f51eaac46


Generic Malware PE File PE32 VirusTotal Malware suspicious privilege suspicious process sandbox evasion WriteConsoleW shadowcopy delete Windows
4.2 55 ZeroCERT

44262 2024-05-13 09:00 lumma1.exe  

56e7d98642cfc9ec438b59022c2d58d7


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
1 2.8 M 46 ZeroCERT

44263 2024-05-13 09:00 lenin.exe  

d8fb06472e78cb03a2f651dc9d1b05f1


Themida Packer Malicious Packer PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare suspicious process AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName Firmware DNS Software crashed
1 5 8 15.2 M 40 ZeroCERT

44264 2024-05-13 09:02 assistant_v7.exe  

008d9913e8ce8bb934b93c559a2e32fa


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.4 M 38 ZeroCERT

44265 2024-05-13 09:02 poter.exe  

3acbdb001a0be2555921f0361189f9b5


EnigmaProtector Malicious Packer PE File PE32 Malware download VirusTotal Malware AutoRuns MachineGuid unpack itself Windows utilities suspicious process WriteConsoleW IP Check Tofsee Windows RisePro ComputerName DNS crashed
1 5 4 6.6 M 35 ZeroCERT