Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45226 2024-06-10 10:10 loader-1001.exe  

58ca6d5068fa4fed981cf5ef8a04e4d5


NSIS Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 Pow VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process AppData folder Tofsee Windows ComputerName Cryptographic key crashed
5 9 1 3 10.2 M 31 ZeroCERT

45227 2024-06-10 10:37 DUU.exe  

e26a8ce5b2f2b9730cc15713a4b1d4a1


Process Kill Generic Malware Suspicious_Script_Bin Malicious Library FindFirstVolume CryptGenKey UPX PE File Device_File_Check PE32 OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
1 2 3 7.6 34 ZeroCERT

45228 2024-06-11 07:36 dmshell.exe  

a62abdeb777a8c23ca724e7a2af2dbaa


Metasploit Meterpreter Generic Malware PE64 PE File VirusTotal Malware DNS crashed
1 3.6 M 62 ZeroCERT

45229 2024-06-11 07:36 meta0906.exe  

05a1e80be42d093214516f6862c84ad9


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 45 ZeroCERT

45230 2024-06-11 07:39 conhost.exe  

8378455f7c8a30d74b355adaf576a10b


XMRig Miner Emotet Cryptocurrency Miner Suspicious_Script_Bin Generic Malware CoinHive Cryptocurrency task schedule Downloader Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) Create Service Socket DGA Http API ScreenShot Escalate pri VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName DNS Cryptographic key
4 3 6 13.2 M 35 ZeroCERT

45231 2024-06-11 07:43 License_counter.exe  

25eef633906e50e331cbb6a2ab4e14a2


Generic Malware Malicious Library UPX PE File ftp PE32 OS Processor Check VirusTotal Malware Malicious Traffic ICMP traffic DNS
1 3 4.2 M 20 ZeroCERT

45232 2024-06-11 08:14 Update.exe  

99f4956e54717c033294558697b73fc6


Generic Malware Hide_EXE PDF Suspicious Link Malicious Library Malicious Packer UPX PE File ftp PE32 OS Processor Check DLL Emotet VirusTotal Malware AppData folder Ransomware Windows
263 4 4 4.0 M 46 ZeroCERT

45233 2024-06-11 09:19 payload.dll  

43296c4ac197f6feae234bb99e90ad57


PE File DLL PE32 VirusTotal Malware
1.2 61 ZeroCERT

45234 2024-06-11 09:22 alpha.doc  

4447ab2143a08d8b67f131c4cbd9c316


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware RWX flags setting exploit crash suspicious TLD Tofsee Exploit DNS crashed
1 2 2 4.0 M 32 ZeroCERT

45235 2024-06-11 10:45 Update.exe  

41ba5678a81003f4f12cfda4c800f61f


Generic Malware Malicious Library Malicious Packer UPX PE File PE32 OS Processor Check VirusTotal Malware
1.4 M 29 ZeroCERT

45236 2024-06-11 10:50 payload.dll  

43296c4ac197f6feae234bb99e90ad57


Swrort DLL PE32 PE File VirusTotal Malware
1.2 M 61 r0d

45237 2024-06-11 13:20 lionsisthekingofjunglewhosuffe...  

b308dd4cfaa85d4a22260a2ce88e1995


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself suspicious TLD Windows Exploit DNS crashed
10 12 7 5.4 34 ZeroCERT

45238 2024-06-11 13:27 c45d209f666f77d70bed61e6fca48b...  

c45d209f666f77d70bed61e6fca48bc2


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 7.6 30 ZeroCERT

45239 2024-06-11 13:34 cmdline.exe  

ca005ebe9454f30c2cedd73080677f56


Malicious Library Malicious Packer .NET framework(MSIL) .NET EXE PE32 PE File VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName
2.2 32 ZeroCERT

45240 2024-06-11 13:37 강연의뢰서_ 엄구호 교수님 .docx.lnk...  

52d073c181531c7f0b8b3aa764c6551d


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.4 26 ZeroCERT