Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45871 2024-07-08 09:52 my.exe  

6470b936622d9502880cae6452d1bb48


Generic Malware Malicious Library Malicious Packer Antivirus UPX PE File PE64 ftp OS Processor Check VirusTotal Malware WriteConsoleW DNS
2 4.0 27 ZeroCERT

45872 2024-07-08 09:54 Client.exe  

86108d3bcc19fe774cc81b71494d31f9


Generic Malware Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check PNG Format Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Browser Email ComputerName DNS Software crashed
1 4 3 7.8 M 61 ZeroCERT

45873 2024-07-08 10:04 Update.js  

affe7c07da3776a191c69b73e50d491a

VBScript wscript.exe payload download Tofsee crashed Dropper
1 2 2 10.0 guest

45874 2024-07-08 10:36 App.dll  

1afdf73c0d1ba126c63927b423c55205


Generic Malware Malicious Library ASPack UPX PE File DLL PE64 OS Processor Check PDB Checks debugger crashed
0.6 ZeroCERT

45875 2024-07-08 11:11 archive.rar  

2074be740d489e298715968ed68fd122


Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself IP Check Tofsee Windows Discord DNS
10 26 18 7 5.2 M ZeroCERT

45876 2024-07-08 13:29 node.js.exe  

9e6ba754b50c865d54a69075a65620ae


Gen1 RedLine stealer NSIS Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) Obsidium protector Antivirus Anti_VM Javascript_Blob PE File PE32 DLL PE64 OS Processor Check ftp VirusTotal Malware suspicious privilege Check memory Creates executable files unpack itself AppData folder Ransomware
4.2 1 ZeroCERT

45877 2024-07-08 14:09 INVESTIGATION_OF_SEXUAL_HARASS...  

9345d52abd5bab4320c1273eb2c90161


ZIP Format Word 2007 file format(docx) VirusTotal Malware unpack itself Tofsee
2 4 1 2.0 4 ZeroCERT

45878 2024-07-08 14:16 482c30dc5680e0c01b8a117ce969ae...  

482c30dc5680e0c01b8a117ce969aef0


MSOffice File VirusTotal Malware unpack itself suspicious TLD
1 2.0 3 ZeroCERT

45879 2024-07-08 14:24 INVESTIGATION_OF_SEXUAL_HARASS...  

9345d52abd5bab4320c1273eb2c90161


ZIP Format Word 2007 file format(docx) VirusTotal Malware exploit crash unpack itself Tofsee Exploit crashed
2 4 1 1 2.6 M 4 ZeroCERT

45880 2024-07-08 16:50 cp.exe  

a40cfc38fce8d0285fd1462bd2d7abd1


UPX PE File PE64 VirusTotal Malware suspicious privilege Windows utilities WriteConsoleW Windows DNS
1 3.8 M 20 ZeroCERT

45881 2024-07-08 16:50 Erlnb.exe  

9352ddda312eeb93823ee2e6cc9a83bc


Generic Malware Malicious Library .NET framework(MSIL) Antivirus AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process Windows ComputerName Cryptographic key
1 2 1 13.6 M 50 ZeroCERT

45882 2024-07-08 16:51 venture45.hta  

e17e0242e9fe3834c192513619013b92

VirusTotal Malware unpack itself crashed
1.4 23 ZeroCERT

45883 2024-07-08 16:52 svchost.exe  

cb146d2042ae0df2c95f3afde7256583


UPX PE File PE64 VirusTotal Malware suspicious privilege Windows utilities suspicious TLD WriteConsoleW Windows DNS
1 3 2 4.0 M 19 ZeroCERT

45884 2024-07-08 16:53 Uialn.exe  

4104370a4f4d897292560d55666cdb10


Generic Malware Malicious Library Antivirus AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process Windows ComputerName Cryptographic key crashed
1 5 1 15.0 M 52 ZeroCERT

45885 2024-07-08 16:53 2019년 졸업자 취업통계조사 붙임.chm...  

972be4aec6506e8bf4dc8d72491099f6


AntiDebug AntiVM CHM Format VirusTotal Malware Code Injection Check memory unpack itself crashed
2.6 28 ZeroCERT