Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
46426 2024-07-30 10:05 SRV.txt.vbs  

558ec1566a5e96df14e34f69c20423f1


Browser Login Data Stealer Generic Malware Downloader Malicious Library Malicious Packer UPX PE File PE32 OS Processor Check Remcos VirusTotal Malware Malicious Traffic Check memory DNS DDNS
1 4 3 2.8 59 ZeroCERT

46427 2024-07-30 10:05 HRD.txt.exe  

437b017eb2cc7db4677091a38116e7bb


Browser Login Data Stealer Generic Malware Downloader Malicious Library Malicious Packer UPX ScreenShot AntiDebug AntiVM PE File PE32 OS Processor Check Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS DDNS keylogger
1 4 3 12.4 64 ZeroCERT

46428 2024-07-30 10:06 Medical.doc  

a5cc3d6c626628f934384cf95dddfc09


MSOffice File RWX flags setting exploit crash unpack itself Exploit DNS crashed
1 2.8 ZeroCERT

46429 2024-07-30 10:06 weareinonlinewithnewthingsalwa...  

dd84171b3002f6733fdc2800ac93f09f


Generic Malware Antivirus PowerShell Malware download VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 2 2 1 8.8 M 4 ZeroCERT

46430 2024-07-30 10:11 weseethesimplethingsalwaystoge...  

c7f6cf5da3192c2cae7d911ee67f6620


Generic Malware Antivirus PowerShell Malware download VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 2 1 8.8 M 4 ZeroCERT

46431 2024-07-30 10:11 ccxzse.ps1  

2c41269583d28c932670429c40247c3e


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 M 13 ZeroCERT

46432 2024-07-30 10:11 doc.exe  

8f92f52bffea35771a435d8d0ac04b0d


UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
0.8 M 14 ZeroCERT

46433 2024-07-30 10:13 mobile_kadw.ps1  

563d96353e5b51fdb7fe7509967f9747


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 10 ZeroCERT

46434 2024-07-30 13:38 HostelCurves.exe  

9512f65eed44bccd7da4ca3d8adb397d


Generic Malware Suspicious_Script_Bin Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P An VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
7.2 M 47 ZeroCERT

46435 2024-07-30 13:40 Authenticator.exe  

dae181fa127103fdc4ee4bf67117ecfb


Emotet Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
1.6 35 ZeroCERT

46436 2024-07-30 13:55 BITHUMB_20240729.docx.lnk  

2afb9ccd85ffcef656eefc18150741ab


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Java ComputerName Cryptographic key
7.2 14 ZeroCERT

46437 2024-07-30 13:57 ms2.bin_dec.dll  

81e9262f4a1fb09caf782d12339c4b9d


Generic Malware task schedule Malicious Library Malicious Packer UPX ScreenShot PWS DNS KeyLogger AntiDebug AntiVM PE File DLL PE64 OS Processor Check VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows Remote Code Execution
1 9.4 36 ZeroCERT

46438 2024-07-31 07:22 Major_0x00012BD4C3BDF0.exe  

c7ea74a05e864d4d67a2fba6be3bb667


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 OS Processor Check crashed
0.2 ZeroCERT

46439 2024-07-31 07:27 stealc_valenciga.exe  

3c18dac89d980c0102252ad706634952


Gen1 Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Antivirus UPX Malicious Packer PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Vidar Malware c&c Malicious Traffic Check memory Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 6.0 ZeroCERT

46440 2024-07-31 07:28 random.exe  

9cccb9b47686e3ab460cbee74196ba25


EnigmaProtector PE File PE32 unpack itself ComputerName crashed
1.4 ZeroCERT