Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47071 2020-07-29 15:01 ff.exe  

da5e879220ffd4bc732fa76e25265fc1


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Checks debugger unpack itself malicious URLs Windows Browser Email ComputerName Software crashed
6.2 M 49

47072 2020-07-29 14:49 9fc542be9b40ee6ce1bdf777140fcc...  

b4d654755e5fb496138ed0e9c4121e84


Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk VM Disk Size Check human activity check Windows ComputerName DNS keylogger
3 2 7.4

47073 2020-07-29 14:47 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic exploit crash unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk sandbox evasion Firewall state off VM Disk Size Check human activity check installed browsers check Ransomware Interception Windows Exploit Browser ComputerName crashed
8 7 13.4

47074 2020-07-29 14:04 winruntime.exe  

532524e6b61b197d92f3bd4ed3331d3d


VirusTotal Malware AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger WMI unpack itself Windows utilities Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Windows ComputerName DNS crashed
6 2 10.6 M 43

47075 2020-07-29 13:47 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


Code Injection Creates executable files exploit crash unpack itself Windows utilities AppData folder Windows Exploit DNS crashed
1 1 4.2

47076 2020-07-29 13:28 jiz.exe  

7eb55ba7c9b9c5529b81aa64d315cd64


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself malicious URLs Windows Browser Email ComputerName Cryptographic key Software crashed
6.6 M 45

47077 2020-07-29 13:20 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


Code Injection Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit crashed
3 5 4.0

47078 2020-07-29 13:14 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


Code Injection Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit crashed
3 5 4.0

47079 2020-07-29 13:09 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit crashed
3 5 4.4

47080 2020-07-29 13:04 http://www.nalara1220.o-r.kr/m...  

543d9bb195c2df50e3dc076b6fdf95ef


Code Injection Creates executable files RWX flags setting unpack itself Windows utilities Windows
5 4 3.0

47081 2020-07-29 13:02 KISA자료1.xlsx  

d95ae922fa3e71e6b5a37d418643f791


unpack itself
1.2

47082 2020-07-29 13:01 excel.xlsx  

d95ae922fa3e71e6b5a37d418643f791


unpack itself
1.2

47083 2020-07-29 11:52 excel.xlsx  

d95ae922fa3e71e6b5a37d418643f791


unpack itself
1.2

47084 2020-07-29 11:50 excel.xlsx  

d95ae922fa3e71e6b5a37d418643f791


unpack itself
1.2

47085 2020-07-29 11:48 excel.xlsx  

d95ae922fa3e71e6b5a37d418643f791


unpack itself
1.2