Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45376 2024-06-16 10:36 1234.exe  

4d85d7bdb9b2d6163ebc289af01f023d


HermeticWiper Generic Malware PhysicalDrive Malicious Packer Malicious Library Downloader UPX Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges PWS Internet API AntiDebug AntiVM PE File PE32 CAB OS Processor Check DllRegisterSer PDB Check memory Creates executable files ICMP traffic unpack itself AppData folder malicious URLs AntiVM_Disk China anti-virtualization VM Disk Size Check Tofsee Windows Remote Code Execution
8 20 5 6.6 M ZeroCERT

45377 2024-06-16 10:37 gold.exe  

70a578f7f58456e475facd69469cf20a


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 62 ZeroCERT

45378 2024-06-16 10:40 ticket_dat.exe  

58204293fa2d102fe00bacd2cbaaf7bf


Malicious Library PE File PE32 MZP Format VirusTotal Malware unpack itself Remote Code Execution
2.0 M 21 ZeroCERT

45379 2024-06-16 10:41 ticket2w.exe  

db063c7f3eeed0ac66c3c42fd3797f59


Malicious Library PE File PE32 MZP Format VirusTotal Malware unpack itself Remote Code Execution
1.6 M 21 ZeroCERT

45380 2024-06-16 10:43 ticket2c.exe  

ce4737e2002d128dea02d50d2ab010cb


Malicious Library PE File PE32 MZP Format VirusTotal Malware unpack itself WriteConsoleW Remote Code Execution
1.6 M 14 ZeroCERT

45381 2024-06-16 10:46 x86_0929_1.exe  

cedd4cef78da5751af380902c89f1352


Generic Malware Malicious Packer Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware AutoRuns PDB suspicious privilege sandbox evasion WriteConsoleW Windows Advertising Remote Code Execution Firmware DNS crashed
1 7.6 M 30 ZeroCERT

45382 2024-06-16 10:48 clips.exe  

49b56d5b9af9bf4027adf9b2b89971c4


Generic Malware Malicious Packer Antivirus PE File PE32 VirusTotal Malware powershell AutoRuns suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder WriteConsoleW Windows ComputerName Remote Code Execution Cryptographic key
8.0 M 51 ZeroCERT

45383 2024-06-17 09:17 adobe.exe  

5fb6f9de46e67ad7d07418a02417aa92


PE64 PE File VirusTotal Cryptocurrency Miner Malware Cryptocurrency unpack itself DNS CoinMiner
2 1 3.6 26 ZeroCERT

45384 2024-06-17 09:23 ClientCaller.exe  

b90b8f1b397bcaeb8ead207d5d9af8e4


Malicious Library Downloader UPX DllRegisterServer dll PE File PE32 MZP Format VirusTotal Malware Check memory unpack itself
2.4 41 ZeroCERT

45385 2024-06-17 09:24 3306.exe  

eb896b51453c804f14c11eee64c0ff79


Malicious Library AntiDebug AntiVM PE File PE32 VirusTotal Malware AutoRuns Code Injection Check memory unpack itself Windows utilities suspicious process AppData folder Windows
2 8.0 M 61 ZeroCERT

45386 2024-06-17 09:26 ClientCaller.exe  

a0c8b9f6054a0700915a3df02d3d07ee


Malicious Library Downloader UPX DllRegisterServer dll PE File PE32 MZP Format VirusTotal Malware Check memory unpack itself
2.2 37 ZeroCERT

45387 2024-06-17 09:26 bas.bat  

e3dd1f8ee9c65b8c514003384a81a3c9


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM MSOffice File PNG Format JPEG Format VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut RWX flags setting exploit crash unpack itself Windows utilities suspicious process WriteConsoleW Windows Exploit ComputerName Cloudflare DNS Cryptographic key crashed
3 1 1 7.6 10 ZeroCERT

45388 2024-06-17 09:26 lib.php.ps1  

ec1b518541228072eb75463ce15c7bce


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
2.0 31 ZeroCERT

45389 2024-06-17 09:28 oldbas.bat  

c7b0fc36d7fd3a1accb4f8d85f78ac96


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PNG Format MSOffice File JPEG Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut RWX flags setting exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Exploit ComputerName Cloudflare DNS Cryptographic key crashed
3 1 1 7.6 11 ZeroCERT

45390 2024-06-17 09:31 lib.php_1.ps1  

f05991652398406655a6a5eebe3e5f3a


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.8 M 27 ZeroCERT