Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
46126 2024-07-19 13:10 #2. 금융당국 요청에 따른 프로젝트 정보 확인 요청의...  

05545d71b8afcc697faf751f81cf66fd


PDF
ZeroCERT

46127 2024-07-19 13:16 #1. 프로젝트 정보 업데이트 요청사항.xlsx.lnk...  

717c204b2e1443bf9a985ab39f16ac1f


Lnk Format GIF Format
9 ZeroCERT

46128 2024-07-19 13:30 Adobe-PDF-Viewer.js  

916b1bf69fdabd368c719a14726fda61


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 2 7.0 5 ZeroCERT

46129 2024-07-19 13:34 Sleflistuiq.exe  

41dd4767d8c5f340b52cbc7258d45c08


Malicious Library UPX PE File .NET EXE PE32 VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.4 45 ZeroCERT

46130 2024-07-19 19:18 Final Draft.exe  

00537f781b10d766813b9d5987edde1a


Emotet Generic Malware Malicious Library UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Remote Code Execution
1.2 7 guest

46131 2024-07-20 17:41 codemirror.min.js  

0a522d4424efac7e86495e4359e90d16


wget crashed
0.2 guest

46132 2024-07-20 19:58 psi.ps1  

ff9703bcf189e4144bb277789540e1fa


Generic Malware Antivirus VirusTotal Malware powershell Malicious Traffic Check memory buffers extracted unpack itself Check virtual network interfaces WriteConsoleW Windows ComputerName Cryptographic key
1 2 2 4.6 5 ZeroCERT

46133 2024-07-20 19:59 IEnetcache.hta  

f56f02858f071b420ca3e54922f00ccf


Generic Malware Antivirus AntiDebug AntiVM PowerShell MSOffice File PE File DLL PE32 .NET DLL VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder Tofsee Windows Exploit ComputerName DNS Cryptographic key crashed
1 1 5 12.2 M 26 ZeroCERT

46134 2024-07-20 19:59 mimidrv.sys  

0818699d065afcb1f397d578d3708dc2


Antivirus PE File PE32 VirusTotal Malware PDB
1.6 M 61 ZeroCERT

46135 2024-07-20 20:01 mimispool.dll  

dab7a18b02399053ba3ff1e568789fce


PE File DLL PE32 VirusTotal Malware Check memory Checks debugger unpack itself crashed
2.2 M 58 ZeroCERT

46136 2024-07-20 20:01 mimilib.dll  

46e598798bdde4c72e796edcf2317b52


Malicious Packer PE File DLL PE32 VirusTotal Malware Checks debugger unpack itself crashed
2.0 M 63 ZeroCERT

46137 2024-07-20 20:04 669a08aa861a2_filemanager.exe#...  

71be3c01c7064efaa019e6259ccb0602


Vidar Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library .NET framework(MSIL) UPX ASPack Http API PWS HTTP Code injection Internet API Anti_VM AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 1 16.2 M 43 ZeroCERT

46138 2024-07-20 20:04 newwork.exe  

3764897fd08b8427b978fb099c091f71


Generic Malware Malicious Library Malicious Packer UPX PE File PE32 OS Processor Check Malware download Amadey VirusTotal Malware AutoRuns Malicious Traffic ICMP traffic unpack itself AppData folder Tofsee Windows DNS
1 5 6 7.0 63 ZeroCERT

46139 2024-07-20 20:05 Files.exe  

90b3832d4da1a85d18c9c515cb01780e


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 58 ZeroCERT

46140 2024-07-20 20:06 we.we.we.we.wewewewe.doc  

6f2f933c81549f01eb55e42a0d85535e


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash IP Check Tofsee Windows Exploit DNS crashed
2 3 8 5.2 M 40 ZeroCERT