Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44431 2024-05-20 09:36 206.238.220.102.dll  

dc22b7f350d6cd3e08f155d26e431e3a


Malicious Library UPX PE File DLL DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware Checks debugger unpack itself Remote Code Execution DNS
1 3.6 M 53 ZeroCERT

44432 2024-05-20 10:25 lumma1234.exe  

c4ffab152141150528716daa608d5b92


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself WriteConsoleW crashed
2.2 M 39 ZeroCERT

44433 2024-05-20 10:27 start-pub.exe  

52bcb73bddd7e3b613ec7fb1367c91c1


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 P VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key crashed
6 11 3 5 11.2 M 17 ZeroCERT

44434 2024-05-20 10:27 online_security_mkl.exe  

b80362872ea704846e892f16aab924c3


Generic Malware Malicious Library UPX PE File PE32 MZP Format OS Processor Check PE64 VirusTotal Malware Checks debugger unpack itself Check virtual network interfaces AppData folder Tofsee crashed
1 3 1 3.8 M 4 ZeroCERT

44435 2024-05-20 10:28 GroceryExtensive.exe  

fb88fe2ec46424fce9747de57525a486


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
6.8 M 25 ZeroCERT

44436 2024-05-20 10:30 AppGate2103v01.exe  

5ede7f188f5353878c0e62808ce3e770


Generic Malware UPX MPRESS PE64 PE File OS Processor Check VirusTotal Malware heapspray unpack itself Windows Remote Code Execution crashed
4.8 M 21 ZeroCERT

44437 2024-05-20 10:32 setup.exe  

5cc472dcd66120aed74de36341bfd75a


Generic Malware Malicious Library Antivirus AntiDebug AntiVM PE File PE32 PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger WMI Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Checks Bios powershell.exe wrote suspicious process WriteConsoleW anti-virtualization Windows ComputerName Cryptographic key
12.2 M 56 ZeroCERT

44438 2024-05-20 10:49 AppStoreEvalLighthousePlugin.c...  

c0d7d66ce4b870e075e5d4b4f087383b


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.8 guest

44439 2024-05-20 11:24 dr.bat  

ce802b6e8add0c59b4c1ceea614bafa3


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM VirusTotal Malware Code Injection Check memory RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Windows
3.8 2 ZeroCERT

44440 2024-05-20 12:06 ph.exe  

89cedf0a5b3833dc294ffc066350aebe


Generic Malware Malicious Library Malicious Packer Antivirus UPX Escalate priviledges Code injection AntiDebug AntiVM PE File PE32 OS Processor Check PE64 VirusTotal Malware Buffer PE PDB Code Injection buffers extracted Creates executable files
5.6 M 52 ZeroCERT

44441 2024-05-20 12:08 net.exe  

75a1801e4dc8e7c3deddae31b79d08f2


XMRig Miner Generic Malware Malicious Library Malicious Packer UPX PE64 PE File OS Processor Check VirusTotal Malware unpack itself ComputerName
1.8 M 42 ZeroCERT

44442 2024-05-21 07:23 winresinet.exe  

c3736d21ee30c4dd5eec74b630e39b46


Malicious Library Malicious Packer UPX PE64 PE File OS Processor Check VirusTotal Malware crashed
0.8 M 8 ZeroCERT

44443 2024-05-21 07:25 file.exe  

119e01fd513495f8f572f286b56e1563


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
2.4 M 34 ZeroCERT

44444 2024-05-21 07:25 RiseGood.exe  

863fd1cebb05495d4ef4bb6c7333db30


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself WriteConsoleW crashed
2.4 M 40 ZeroCERT

44445 2024-05-21 07:26 oiii.exe  

a59664f37c25edaa69c39a65490ed3a9


HermeticWiper Generic Malware Malicious Library UPX PE64 PE File OS Processor Check JPEG Format PNG Format icon PE32 MSOffice File VirusTotal Malware PDB suspicious privilege buffers extracted Creates executable files unpack itself suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Ransomware Windows ComputerName Remote Code Execution crashed
3 2 2 6.8 M 16 ZeroCERT