Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
46156 2024-07-20 20:20 669a659129ee2_crypted.exe#1  

a6e3a44c463433ecb473af3f761923db


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself WriteConsoleW crashed
2.4 M 51 ZeroCERT

46157 2024-07-20 20:21 lummnew.exe  

cf8dc800af1373e2e48b68f126ab4123


Lumma Stealer UPX PE File PE32 VirusTotal Malware
1.2 M 59 ZeroCERT

46158 2024-07-20 20:23 1x212.exe  

5ce0b51dc000aef2803892a6c87aea26


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 59 ZeroCERT

46159 2024-07-20 20:23 winiti.exe  

6298475c0e4860db7568c5b231e3cca9


Generic Malware Malicious Library UPX Antivirus PE File PE32 DLL VirusTotal Malware powershell suspicious privilege Check memory Checks debugger WMI Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process AppData folder WriteConsoleW Windows ComputerName Cryptographic key crashed
7.4 M 53 ZeroCERT

46160 2024-07-20 20:25 svchost.exe  

4ebd63449193b8fdbd0c0315f8e33e10


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 54 ZeroCERT

46161 2024-07-20 20:25 669b5b78252ea_googlesoft.exe  

8ac8aa90462b3181025ca80e26af7848


Vidar Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library .NET framework(MSIL) UPX ASPack Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 17.0 M 18 ZeroCERT

46162 2024-07-20 20:27 LummaC2.exe  

3d2133fcf75f684b0b8d0152c8304c9b


Lumma Stealer UPX PE File PE32 VirusTotal Malware
1.2 M 54 ZeroCERT

46163 2024-07-20 20:27 appdrivesound.exe  

0f798c42cf4a3724aab608409cdb0426


North Korea Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger buffers extracted unpack itself ComputerName
3.0 M 42 ZeroCERT

46164 2024-07-20 20:28 crowdstrike-hotfix.zip  

1e84736efce206dc973acbc16540d3e5


ZIP Format Remcos VirusTotal Malware DNS
2 1 1.0 6 ZeroCERT

46165 2024-07-20 20:29 gold.exe  

3828babaa69c01aa31609e67ac8c1f71


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 59 ZeroCERT

46166 2024-07-20 20:32 92584v.exe  

0d0b2d2e8e757e66ae44a0e3aeed2512


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself crashed
2.2 M 55 ZeroCERT

46167 2024-07-20 20:34 AppGate018ver1.exe  

8f8f6a36a8b827ceaae1228fd2669002


Vidar Client SW User Data Stealer LokiBot Gen1 Emotet ftp Client info stealer Generic Malware Themida Packer Malicious Library UPX ASPack .NET framework(MSIL) Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File PE64 OS Processor Che Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Cryptocurrency Miner Malware Telegram AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security Checks Bios Collect installed applications Detects VirtualBox Detects VMWare Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk sandbox evasion WriteConsoleW VMware Firewall state off anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Interception Windows Discord Browser RisePro ComputerName Firmware DNS Software crashed CoinMiner
10 28 26 5 28.4 M 15 ZeroCERT

46168 2024-07-20 20:44 info.zip  

cbcb58ffe45c202c11bcf2070496aed6


ZIP Format VirusTotal Malware suspicious TLD DNS
2 2.2 M 56 ZeroCERT

46169 2024-07-21 09:34 billi_e58d74e455634dc695ed8a7b...  

c781ee8c2429c44cda2d6d2ab3830991


Malicious Packer UPX PE File PE32 VirusTotal Malware unpack itself DNS
1 3.6 M 56 ZeroCERT

46170 2024-07-21 09:34 billi_e58d74e455634dc695ed8a7b...  

b9edf01e4f7bcefb95dfb9f653344569


Malicious Packer UPX PE File PE32 VirusTotal Malware unpack itself DNS
1 3.6 M 56 ZeroCERT