Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44926 2020-11-30 12:07 osk.exe  

315efcfaf3329dc6fb4a67bbb0b89620


VirusTotal Malware suspicious privilege Check memory Checks debugger Creates executable files unpack itself Windows utilities WriteConsoleW Windows ComputerName DNS
6.0 M 42 ZeroCERT

44927 2020-11-30 12:01 images.exe  

ee4555ac614048e36aae067b6a032951


Malware download Nanocore VirusTotal Malware c&c Buffer PE AutoRuns suspicious privilege MachineGuid Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW human activity check Windows ComputerName DNS
1 1 12.8 M 58 ZeroCERT

44928 2020-11-30 12:01 a.exe  

2764acacf3bd324b63fb660859fa28f9


Malware download VirusTotal Malware Code Injection Checks debugger buffers extracted unpack itself malicious URLs Windows ComputerName Remote Code Execution DNS
2 1 3 9.6 M 47 ZeroCERT

44929 2020-11-28 10:17 Pdxpforzum1.exe  

1cb0218248ea6be6b4fc59e43bb88c99


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
3.0 M 36 ZeroCERT

44930 2020-11-28 10:17 Nmsdmwkbi4.exe  

224e779ff4d39ce90878ae3e630197e7


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
2.8 M 22 ZeroCERT

44931 2020-11-28 10:15 Jqeofcirr6.exe  

0998148d355b1e7bad7b44558aa4c125


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself malicious URLs Windows ComputerName DNS Cryptographic key
4.4 M 35 ZeroCERT

44932 2020-11-28 10:15 5901777.pdf.exe  

7e26e87ab642008d934824d509559859


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
3.0 M 38 ZeroCERT

44933 2020-11-28 10:11 oxiba.exe  

9817218c055db1b75d64df2ae2f40f53


Browser Info Stealer VirusTotal Email Client Info Stealer Malware powershell AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Disables Windows Security powershell.exe wrote Check virtual network interfaces suspicious process malicious URLs WriteConsoleW IP Check Tofsee Ransomware Windows Browser Tor Email ComputerName Cryptographic key crashed keylogger
3 6 1 1 19.0 M 27 ZeroCERT

44934 2020-11-28 10:10 0mrxdv.exe  

b7679c443e22238291f5603f016ff56e


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself malicious URLs Windows ComputerName DNS Cryptographic key
4.2 23 ZeroCERT

44935 2020-11-28 09:40 http://115373.com/  

3b7b28992c82645f61bf6329cfa120c2


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 10 5 5.6 M guest

44936 2020-11-27 17:55 oxiba.exe  

9817218c055db1b75d64df2ae2f40f53


VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut unpack itself Disables Windows Security powershell.exe wrote Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 1 11.2 M 27 ZeroCERT

44937 2020-11-27 17:48 Yvvtz1.exe  

0d2637cb8d991ba05dd78136d2e01321


VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName DNS Cryptographic key crashed
3.4 M 15 ZeroCERT

44938 2020-11-27 17:46 YAS2231.exe  

99b81672c6ec04e7e6e6063b40d9127c


VirusTotal Malware PDB suspicious privilege Creates executable files unpack itself AppData folder malicious URLs sandbox evasion ComputerName
4.8 M 51 ZeroCERT

44939 2020-11-27 17:44 xqakn8b.jpg.exe  

1ba0b20a2d03d8af03a7faa42b06417f


VirusTotal Malware unpack itself Remote Code Execution crashed
2.6 M 55 ZeroCERT

44940 2020-11-27 17:42 winlog.exe  

e54d832cb872b7dc086ab7a7878d38fb


VirusTotal Malware suspicious privilege Check memory unpack itself
3.6 M 51 ZeroCERT