Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
46486 2024-07-31 23:06 InstallAAAwave.exe  

47781e2f67d75de26c08227ef50a1da5


Emotet Gen1 Generic Malware UPX Antivirus Malicious Library PE File PE32 MZP Format Lnk Format GIF Format DllRegisterServer dll DLL BMP Format OS Processor Check VirusTotal Malware Check memory Creates shortcut Creates executable files RWX flags setting unpack itself AntiVM_Disk VM Disk Size Check ComputerName crashed
4.2 1 guest

46487 2024-07-31 23:18 azmid170.exe  

8a7e8d21f7790b63abb22853ccb0178c


Emotet Malicious Library UPX ScreenShot KeyLogger AntiDebug AntiVM PE File PE32 Lnk Format GIF Format OS Processor Check DllRegisterServer dll suspicious privilege Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself AntiVM_Disk VM Disk Size Check ComputerName
4.0 guest

46488 2024-08-01 02:05 141532.php  

e25219536e1f96b52b090a9e8a05620f

crashed
0.2 guest

46489 2024-08-01 02:05 141532.php  

e25219536e1f96b52b090a9e8a05620f

unpack itself crashed
0.6 guest

46490 2024-08-01 08:37 ber.exe  

40b5cfe2ff96cd0f16a0af393ac8b039


Lumma Stealer UPX PE File PE32
ZeroCERT

46491 2024-08-01 08:37 1.exe  

d94cf1913f3dbee17014f7a765c09d4e


Generic Malware Themida Packer Malicious Library WinRAR UPX Admin Tool (Sysinternals etc ...) PE File PE32 OS Processor Check .NET EXE PDB suspicious privilege Check memory Checks debugger Creates executable files unpack itself Checks Bios Detects VMWare AppData folder AntiVM_Disk VMware anti-virtualization VM Disk Size Check Windows ComputerName Remote Code Execution Firmware crashed
6.8 ZeroCERT

46492 2024-08-01 08:39 1.exe  

be951641ba5b2620a2d4e9b9e9568e76


Generic Malware Malicious Library ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 Malware download Malware PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows DNS Downloader
1 1 6 8.8 ZeroCERT

46493 2024-08-01 08:41 random.exe  

ad1dde8691f26ca55a64c3a8d1adaa7f


RedLine stealer EnigmaProtector Generic Malware UPX Code injection Anti_VM AntiDebug AntiVM PE File PE32 OS Processor Check MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Tofsee Ransomware Exploit Browser ComputerName crashed
2 1 9.2 M ZeroCERT

46494 2024-08-01 08:45 stealc_valenciga.exe  

cb24cc9c184d8416a66b78d9af3c06a2


Gen1 Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Antivirus UPX Malicious Packer PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar Email Client Info Stealer Malware c&c Malicious Traffic Check memory Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
9 1 16 9 7.2 M ZeroCERT

46495 2024-08-01 08:47 PwHnaA.exe  

19f436930646f3e8f283fa71f2a4cbcb


Generic Malware Malicious Library Malicious Packer .NET framework(MSIL) UPX Anti_VM PE File .NET EXE PE32 OS Processor Check JPEG Format Malware Telegram Malicious Traffic Windows utilities IP Check Tofsee Windows DNS
2 6 7 1.6 ZeroCERT

46496 2024-08-01 08:47 winiti.exe  

002c833ff6ecaac50c4ef23b36189bbc


Formbook Generic Malware Malicious Library .NET framework(MSIL) UPX ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 DLL FormBook Browser Info Stealer Malware download Malware PDB Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder suspicious TLD Browser DNS crashed
3 3 3 2 9.4 M ZeroCERT

46497 2024-08-01 08:50 NO.exe  

8f307a5db76ea7573f1824d852178c0c


Gen1 Generic Malware Malicious Library WinRAR UPX Malicious Packer PE File PE64 OS Processor Check DLL PDB Creates executable files unpack itself Remote Code Execution
3.0 ZeroCERT

46498 2024-08-01 08:51 schuste.exe  

115988cec15bcf0adc3b6a4f100b1b24


Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE File PE64 OS Processor Check DLL ZIP Format Check memory Creates executable files
1.0 ZeroCERT

46499 2024-08-01 10:13 886535bbe925890a01f49f49f49fee...  

886535bbe925890a01f49f49f49fee40


Generic Malware HWP PS PostScript Antivirus AntiDebug AntiVM MSOffice File Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 7.8 27 ZeroCERT

46500 2024-08-01 10:29 vhcrvdh iobv.exe  

da2331ac3e073164d54bcc5323cf0250


Malicious Library .NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.4 48 ZeroCERT