Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44281 2024-05-14 08:10 sarra.exe  

6c5eff575235162e48d1343214977dec


PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare suspicious process AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 5 6 16.0 M 39 ZeroCERT

44282 2024-05-14 08:12 vnc.exe  

1b6d04ab5d5e03ec81db2c856b86d98d


NSIS Malicious Library UPX PE File PE32 PNG Format DLL JPEG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.4 M 20 ZeroCERT

44283 2024-05-14 08:13 my.exe  

19d05221bdd0110e564e00074a7f6636


Malicious Library Malicious Packer Antivirus .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 51 ZeroCERT

44284 2024-05-14 08:14 lox.exe  

70b96a07a3624e8f408a98d0e7908820


Generic Malware Themida Packer Malicious Library UPX Admin Tool (Sysinternals etc ...) Anti_VM PE64 PE File OS Processor Check .NET EXE PE32 VirusTotal Malware PDB Creates executable files unpack itself AppData folder Remote Code Execution DNS
1 1 3.8 M 27 ZeroCERT

44285 2024-05-14 08:15 setup%E6%9F%A5%E7%9C%8B.exe  

405dbea7123e931820e7dd4fcf6e67c1


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware AutoRuns Check memory RWX flags setting unpack itself Windows DNS
1 4.4 M 41 ZeroCERT

44286 2024-05-14 08:32 random.exe  

906505cc5818955f1793017c1d83206d


Themida Packer Malicious Packer PE File PE32 Malware download Malware AutoRuns MachineGuid unpack itself Windows utilities Checks Bios Detects VirtualBox Detects VMWare suspicious process WriteConsoleW VMware anti-virtualization IP Check Tofsee Windows RisePro ComputerName Firmware DNS crashed
1 5 4 8.0 M ZeroCERT

44287 2024-05-14 08:33 DbVisualizer_Pro.exe  

c059c2e1a13ba50f4c8d9dffea0f4e57


Generic Malware Malicious Library Malicious Packer UPX PE64 PE File DllRegisterServer dll OS Processor Check
0.4 M ZeroCERT

44288 2024-05-14 08:33 %E5%90%8D%E5%8D%95%E5%86%8C%E7...  

87c800dac6fb2709eafd6561f100035a


Generic Malware Downloader Malicious Library Malicious Packer Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Code Injection Check memory Creates executable files sandbox evasion WriteConsoleW Browser
2 4.2 M ZeroCERT

44289 2024-05-14 08:33 build.exe  

735c15c37831cdc319c03f4f7971da49


RedLine Infostealer RedLine stealer RedlineStealer Malicious Library .NET framework(MSIL) UPX Anti_VM PE File .NET EXE PE32 OS Processor Check PE64 Browser Info Stealer RedLine Malware download FTP Client Info Stealer Cryptocurrency Miner Malware Cryptocurrency suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications Check virtual network interfaces IP Check installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed CoinMiner SilentCryptoMiner
4 11 16 9.4 M ZeroCERT

44290 2024-05-14 08:33 Obrada.exe  

1f90151f3470f316a645a6617534a0be


Generic Malware Malicious Library .NET framework(MSIL) Antivirus AntiDebug AntiVM PE File .NET EXE PE32 Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself Check virtual network interfaces suspicious process Windows ComputerName Cryptographic key
1 2 1 10.8 M ZeroCERT

44291 2024-05-14 08:33 TextEditor.exe  

06d8a1accf0a9b34aaee3e1ec50552f0


Generic Malware Malicious Library Antivirus AntiDebug AntiVM PE File .NET EXE PE32 Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process Windows ComputerName Cryptographic key
1 4 1 12.4 M ZeroCERT

44292 2024-05-14 08:33 Kntgugii.exe  

f5fe6435df7702338b1320b55f96caa4


PE File .NET EXE PE32 suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName DNS Cryptographic key crashed
1 2.8 M ZeroCERT

44293 2024-05-14 08:34 file.exe  

5db8857cca603a760cfb6955f5c309cf


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check Check memory Checks debugger unpack itself ComputerName DNS
1 2.0 M ZeroCERT

44294 2024-05-14 08:35 yar.exe  

9e8baf127b832943d4fae218ce90191a


UPX PE File .NET EXE PE32 OS Processor Check AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName
5.6 M ZeroCERT

44295 2024-05-14 08:37 Layout.exe  

8eb6ed01392a5cbba283febd7c9aa16a


Generic Malware Malicious Library Antivirus AntiDebug AntiVM PE64 PE File powershell PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
9.0 M ZeroCERT