Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44266 2024-05-13 09:04 swizzhis.exe  

808c0214e53b576530ee5b4592793bb0


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
2.8 M 41 ZeroCERT

44267 2024-05-13 09:06 go.exe  

dc540b21dd7ea520b4390010baee443f


Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check MSOffice File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
8 6 1 5.8 M 17 ZeroCERT

44268 2024-05-13 09:07 alex.exe  

31841361be1f3dc6c2ce7756b490bf0f


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself DNS crashed
1 3.4 M 57 ZeroCERT

44269 2024-05-13 09:07 toolspub1.exe  

6bcbbfac4eb7dbecb5a44983645a75db


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Remote Code Execution
2.2 M 44 ZeroCERT

44270 2024-05-13 09:09 leadiadequatepro.exe  

b149f82964b1e269ade2686612a9e777


Emotet Gen1 Hide_EXE Malicious Library UPX .NET framework(MSIL) PE64 PE File CAB OS Processor Check .NET EXE PE32 VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself AppData folder Windows ComputerName Remote Code Execution
5.0 M 44 ZeroCERT

44271 2024-05-13 09:11 install.exe  

0f52e5e68fe33694d488bfe7a1a71529


Gen1 XMRig Miner Generic Malware Malicious Library UPX Malicious Packer PE File PE32 PE64 OS Processor Check VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files Windows utilities AppData folder AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check Windows DNS
1 6.6 M 48 ZeroCERT

44272 2024-05-13 09:12 amers.exe  

802263fb14b84944b5d41a2abbb4cf55


Amadey RedLine stealer RedlineStealer Gen1 XMRig Miner Generic Malware NSIS Malicious Library .NET framework(MSIL) UPX Malicious Packer PE File PE32 .NET EXE OS Processor Check PE64 Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware Microsoft AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization VM Disk Size Check installed browsers check Kelihos Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
8 16 15 1 20.2 M 32 ZeroCERT

44273 2024-05-13 09:27 Scanner.exe  

9de1ede890852d25d1a9a37561c85881


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself crashed
2.8 M 51 ZeroCERT

44274 2024-05-13 10:53 [Content_Types].xml  

ded1b06d92c5c6b15c0b12c176ff3355


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44275 2024-05-13 10:54 [Content_Types].xml  

ded1b06d92c5c6b15c0b12c176ff3355


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

44276 2024-05-13 10:54 .rels  

77bf61733a633ea617a4db76ef769a4d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44277 2024-05-13 10:55 .rels  

77bf61733a633ea617a4db76ef769a4d


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44278 2024-05-13 10:56 [Content_Types].xml  

ded1b06d92c5c6b15c0b12c176ff3355


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

44279 2024-05-13 10:56 .rels  

77bf61733a633ea617a4db76ef769a4d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44280 2024-05-14 08:10 msgbox.exe  

69592b2d2f12c492e954ff8943b7900a


UPX PE64 PE File OS Processor Check VirusTotal Malware PDB
0.6 M 4 ZeroCERT