Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45421 2024-06-18 09:38 arphaDump64.dll  

b60a81a659f6a8228c3e5df7f1c0819a


Malicious Library DLL PE64 PE File VirusTotal Malware PDB Checks debugger unpack itself
1.2 4 ZeroCERT

45422 2024-06-18 15:07 aspx.exe  

b81577dbe375dbc1d1349d8704737adf


Generic Malware Malicious Library UPX PE64 PE File OS Processor Check VirusTotal Malware Malicious Traffic Check memory Creates executable files unpack itself Windows utilities suspicious process sandbox evasion WriteConsoleW Windows ComputerName DNS crashed
1 3 7.6 54 ZeroCERT

45423 2024-06-18 18:16 AV520.exe  

39d865aa4171442b417c40479e63a03f


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.0 M 63 ZeroCERT

45424 2024-06-18 18:16 1.exe  

c51e84d4d53678605a1cb5feb6436c84


Malicious Library AntiDebug AntiVM PE File PE32 VirusTotal Malware AutoRuns Code Injection Check memory unpack itself Windows utilities suspicious process AppData folder Windows
2 7.4 M 66 ZeroCERT

45425 2024-06-18 18:18 Aripzlzup.exe  

f41b9a03e2cfb311197ac247e4e4416c


Generic Malware Malicious Library ASPack UPX PE File PE32 OS Processor Check JPEG Format VirusTotal Malware Checks debugger unpack itself sandbox evasion
2.6 M 45 ZeroCERT

45426 2024-06-18 18:21 127pos.exe  

3445e5cbc4f883d4c8db25e193ad30d2


Generic Malware Malicious Library ASPack UPX PE File PE32 OS Processor Check VirusTotal Malware Checks debugger unpack itself Windows
1 2 1 2.2 51 ZeroCERT

45427 2024-06-18 18:24 Radmin2018.exe  

6754696a342ef288c4eeac34bddb1ab1


Gen1 Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) Anti_VM AntiDebug AntiVM PE File PE32 DLL PE64 OS Processor Check MZP Format VirusTotal Malware AutoRuns PDB suspicious privilege MachineGuid Code Injection Checks debugger Creates executable files unpack itself Windows utilities Auto service suspicious process WriteConsoleW Firewall state off Windows
9.8 28 ZeroCERT

45428 2024-06-18 22:31 https://qrco.de/bfAK2I?onO=XTp...  

12dec78d031d4e022b462bf6373a6d21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File icon Code Injection Creates executable files exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
5 8 3 4.2 guest

45429 2024-06-19 09:34 murka.exe  

9e27ed6d9855b9bfae9234f0303a8bba


Malicious Packer UPX Anti_VM PE File PE32 ZIP Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted unpack itself Windows utilities Collect installed applications suspicious process AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 5 8 13.4 M 45 ZeroCERT

45430 2024-06-19 09:34 lamda.cmd  

c348551fa8fea00106049dd9ff8c07c0


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM VirusTotal Malware powershell AutoRuns suspicious privilege Check memory Checks debugger heapspray Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
8 5.8 12 ZeroCERT

45431 2024-06-19 09:36 bbc.doc  

c37e66ac7c43e79fd1c771892d457314


MS_RTF_Obfuscation_Objects RTF File doc Vulnerability VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit DNS crashed
3 5 5 4.6 M 36 ZeroCERT

45432 2024-06-19 09:36 lamda.cmd  

7aad5e78aa5e3c4c1fd5da339379185e


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM VirusTotal Malware suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
3.8 20 ZeroCERT

45433 2024-06-19 09:37 AntiVirus2.exe  

571878c5dbb5200509fddc36d7c01643


Malicious Packer Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger ICMP traffic unpack itself
2.8 M 60 ZeroCERT

45434 2024-06-19 09:41 AntiVirus.exe  

06b81c8edd7f620513a06e3a5cc11483


PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 1 5.0 M 53 ZeroCERT

45435 2024-06-19 09:41 1.exe  

7b099cafaf5dada250f611dfef156cdb


PE File .NET EXE PE32 VirusTotal Malware MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 1 5.6 M 50 ZeroCERT