Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47521 2024-08-25 18:46 xxxx.exe  

31fa485283c090077fb15a0831fd89f7


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 37 ZeroCERT

47522 2024-08-25 18:48 WindowsUI.exe  

616b51fce27e45ac6370a4eb0ac463f6


Malicious Packer PE File .NET EXE PE32 VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege Check memory Checks debugger buffers extracted RWX flags setting unpack itself AntiVM_Disk VM Disk Size Check Windows ComputerName Cryptographic key
6.6 M 47 ZeroCERT

47523 2024-08-25 18:50 tunnel.php  

bb8b2337887949183d8eeb8d0c204e93


AntiDebug AntiVM VirusTotal Email Client Info Stealer Malware suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
4.0 14 ZeroCERT

47524 2024-08-25 18:51 66c9d38385a86_crypto.exe#kiscr  

517723763103f23dcd3a692066db6aee


Stealc Client SW User Data Stealer North Korea ftp Client info stealer Generic Malware Malicious Library .NET framework(MSIL) UPX Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS Software crashed plugin
9 1 15 2 13.2 M 32 ZeroCERT

47525 2024-08-25 18:52 66c9d78d43c01_valensu.exe#spac...  

459061967c92b83083c24ed4963e7a18


Stealc Client SW User Data Stealer LokiBot North Korea ftp Client info stealer Generic Malware Malicious Library .NET framework(MSIL) UPX Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check FTP Client Info Stealer VirusTotal Malware Telegram PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 17.2 M 47 ZeroCERT

47526 2024-08-25 18:53 66c866840e631_Indentif.exe  

4dff7e34dcd2f430bf816ec4b25a9dbc


Emotet Malicious Library UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
2.2 M 27 ZeroCERT

47527 2024-08-25 18:55 66c9d3f5503cc_GIFT.exe  

58c6ec5a74a80def1f37f7956da11a26


Malicious Library Malicious Packer UPX PE File .NET EXE PE32 VirusTotal Malware Buffer PE PDB Check memory Checks debugger buffers extracted unpack itself ComputerName Remote Code Execution
4.2 M 40 ZeroCERT

47528 2024-08-25 18:56 5PHCENYBS068Y01  

7fffe8702479239234bce6013bcad409


Gen1 Generic Malware Malicious Library UPX Antivirus Malicious Packer Anti_VM PE File PE64 DLL OS Processor Check ftp wget VirusTotal Malware Check memory Creates executable files unpack itself
3.2 M 51 ZeroCERT

47529 2024-08-25 18:56 System-Repair.msi  

25243822b373e327d5b11bfbf35096fe


Generic Malware Malicious Library Antivirus MSOffice File OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger Creates shortcut unpack itself AntiVM_Disk VM Disk Size Check ComputerName
2.8 M 18 ZeroCERT

47530 2024-08-25 18:57 66ca560048cbe_sgrk.exe#space  

ec11395a4f9b30672b9392e14e684c24


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
3.0 M 41 ZeroCERT

47531 2024-08-25 18:59 66ca20a26df75_PastaCache.exe#i...  

377dcc031a12d3c0189afe684e4ad41e


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.4 M 15 ZeroCERT

47532 2024-08-25 19:01 runus.exe  

d3348d383a614ddf7405f189fcf10a4b


Stealc PE File PE32 Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare VMware anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 2 19 2 12.0 M 29 ZeroCERT

47533 2024-08-25 19:01 66c9dcdb986c5_crypted.exe#1  

724a304d92c8e4920afbc604d34ad74a


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
3.0 M 46 ZeroCERT

47534 2024-08-25 19:01 66ca11c91d783_vaelw.exe#space  

ad8a02a68b36bd0c78428d3552feacce


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 32 ZeroCERT

47535 2024-08-25 19:04 66ca11c555823_sewfe.exe#space  

0df1eb83d7ed49150b934fe7f68585af


Antivirus PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 32 ZeroCERT