Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44551 2020-12-16 12:23 1312.gif.1.exe  

b2a9a4e1656bdb5749de4f228dc9f307


VirusTotal Malware
1.8 M 41 ZeroCERT

44552 2020-12-16 11:06 XokBnqWMZ4B9pbd.exe  

e9dbec32351a5bd0a3f94b8314e4d958


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW installed browsers check Windows Browser Email ComputerName DNS Software
1 17.6 M 43 ZeroCERT

44553 2020-12-16 10:37 win32.exe  

f4fccdb6286107ca3592406e356a6b5e


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName Trojan DNS Software
1 2 10 1 15.0 M 38 ZeroCERT

44554 2020-12-16 10:37 vbc.exe  

ebc762f4d1d6557fcfb73fc7eb1d5b7a


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName Software
1 2 7 1 14.2 M 46 ZeroCERT

44555 2020-12-16 09:55 Speeder_1.0.0.3_qd13.exe  

a6d2cae21d592a602211a854dc4dc91a


VirusTotal Malware suspicious privilege MachineGuid Malicious Traffic Check memory buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder malicious URLs AntiVM_Disk VM Disk Size Check human activity check installed browsers check Tofsee Browser ComputerName DNS
45 16 1 10.6 M 13 ZeroCERT

44556 2020-12-16 09:50 SkIoKdBiDxtQ2g1.exe  

89a6ece185d652883f32474e5c0df7c7


VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows DNS DDNS
2 1 14.8 M 47 ZeroCERT

44557 2020-12-16 09:46 SkIoKdBiDxtQ2g1.exe  

89a6ece185d652883f32474e5c0df7c7


VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself suspicious process malicious URLs WriteConsoleW Windows DNS DDNS
2 1 15.6 M 47 guest

44558 2020-12-16 09:46 Rep_LI6.doc  

8e842b5a5672e46538f5d6fea2275579


Vulnerability VirusTotal Malware unpack itself malicious URLs Windows
2 1 4.2 M 26 guest

44559 2020-12-16 09:15 regasm.exe  

b8561eed84f227c88c7b8d3a106be5ab


Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName Trojan DNS Software
1 2 10 1 15.2 M 49 guest

44560 2020-12-16 09:13 pdf.exe  

48a9add9e1b4b99548e564dfbdcb8a9f


VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs Tofsee
3 1 4.6 M 42 guest

44561 2020-12-16 09:11 KINO.exe  

e74426f4ab322e220a00be7558b892de


VirusTotal Malware Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Tofsee ComputerName DNS
1 2 1 5.4 M 21 guest

44562 2020-12-16 09:10 kingtroupxtwo.scr  

d19c1f5071b995ed4bdefa7dfa86a2f5


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
11.4 M 12 guest

44563 2020-12-15 18:19 kingtroupx.scr  

d16ccfd5f5e6cd6a6324c79c9a66a90a


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself malicious URLs Windows DNS Cryptographic key
6.6 M 40 guest

44564 2020-12-15 18:19 kdotx.scr  

4ddf98cd8e5a012c02850f0a988adf2c


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself malicious URLs Windows Cryptographic key
5.8 M 34 guest

44565 2020-12-15 18:11 JFjolfjed_.exe  

61ae277818f7f258b41cee010f3914d2


VirusTotal Malware Malicious Traffic RWX flags setting unpack itself malicious URLs Interception DNS crashed
1 4 6.4 M 39 guest