Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44746 2024-05-30 10:15 o25ac2exe.exe  

2adb3aef1723e5c5fa45c5d33a5ecfb2


Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE64 PE File ftp OS Processor Check DLL ZIP Format VirusTotal Malware Check memory Creates executable files Ransomware
3.6 M 45 ZeroCERT

44747 2024-05-30 10:17 TweaksAlt.exe  

7c066067ec3b865ea08f31c9aa005027


Generic Malware Malicious Library UPX Antivirus PE File PE32 icon PE64 suspicious privilege Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
5.0 M ZeroCERT

44748 2024-05-30 10:17 o12c2exe.exe  

1fbec493cbadaa0e3d0f39b30ad17414


Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE64 PE File ftp OS Processor Check DLL ZIP Format VirusTotal Malware Check memory Creates executable files Ransomware
3.2 M 28 ZeroCERT

44749 2024-05-30 10:19 oc2exe.exe  

377affaaf48d912ad3bdad417064f6f6


Gen1 Generic Malware Malicious Library ASPack UPX Malicious Packer Anti_VM PE64 PE File ftp OS Processor Check DLL ZIP Format VirusTotal Malware Check memory Creates executable files Ransomware
3.4 M 37 ZeroCERT

44750 2024-05-30 10:20 download.php  

9432487a269c081629913454ecb414df


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check unpack itself
1.2 ZeroCERT

44751 2024-05-30 10:22 logista.hta  

976649b232d3525dd239f7139a65dd92


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process suspicious TLD Windows ComputerName Cryptographic key
2 5.8 M 36 ZeroCERT

44752 2024-05-30 11:27 vhcrvdh iobv.exe  

e6f4bb8ed235f43cb738447fbf1757c3


Malicious Library .NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.2 35 ZeroCERT

44753 2024-05-30 17:35 http://malaygxproj.com  


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PNG Format MSOffice File JPEG Format VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 2 4.6 guest

44754 2024-05-31 07:32 mixinte.exe  

629866cf7074c354fc4bcc86f9c3994a


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check .NET EXE VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName DNS
2 2 3 1 8.0 M 58 ZeroCERT

44755 2024-05-31 07:33 IerLRtXpEcMnUjz.exe  

148b2c38cf0726535d760a703f803c80


XWorm Generic Malware task schedule WebCam Malicious Library .NET framework(MSIL) Antivirus PWS KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell Telegram AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName DNS Cryptographic key keylogger
4 6 14.2 M 57 ZeroCERT

44756 2024-05-31 07:33 winlogon.exe  

7a70779d9d7de5e370fac0fa2d4ccd13


Generic Malware Antivirus PE File .NET EXE PE32 PowerShell VirusTotal Malware powershell PDB suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
5.2 M 27 ZeroCERT

44757 2024-05-31 07:36 inte.exe  

b7fcd8d0429e1001ac2b10de60a2d42e


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Malicious Traffic WMI Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName DNS
2 2 1 6.6 M 60 ZeroCERT

44758 2024-05-31 07:38 gold.exe  

0b7e08a8268a6d413a322ff62d389bf9


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check PDB unpack itself crashed
1.6 M ZeroCERT

44759 2024-05-31 07:38 sarra.exe  

2f1168a237b3b15e3e2c7b6fd1b41702


PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare suspicious process AntiVM_Disk sandbox evasion WriteConsoleW VMware anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 9 8 15.6 ZeroCERT

44760 2024-05-31 07:40 lenin.exe  

cd1dfa093d37dff12f11f8c1c06d565e


Themida Packer UPX PE File PE32 Malware download Malware AutoRuns MachineGuid Checks debugger unpack itself Windows utilities Checks Bios Detects VMWare suspicious process WriteConsoleW VMware anti-virtualization IP Check Tofsee Windows RisePro ComputerName DNS crashed
1 6 5 9.6 M ZeroCERT