Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47551 2024-08-26 09:22 66cb3e08e7e87_install.exe#upus  

7586d565812943ae038f1a3957e14a65


Generic Malware Malicious Library Malicious Packer UPX PE File .NET EXE PE32 DLL OS Processor Check VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder crashed
3.0 M 21 ZeroCERT

47552 2024-08-26 09:23 도양기업 20240610 송장 갑지.bmp.lnk...  

09b1213c8a336541a4849d65b937293f


Antivirus AntiDebug AntiVM Lnk Format GIF Format wget VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 6.8 28 ZeroCERT

47553 2024-08-26 09:23 66cba4c565f5f_vief.exe#space  

75d0097acc881bb6bc4332bda07f16f1


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.8 M 26 ZeroCERT

47554 2024-08-26 09:25 66cb4f5c496b9_doz.exe  

4f43057798a7498e61de57cdc627d87c


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library .NET framework(MSIL) Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 1 15.2 M 18 ZeroCERT

47555 2024-08-26 09:27 9009.exe  

644a43fda332b29e94af26722ee4a836


UPX PE File PE32 VirusTotal Malware
1.0 M 38 ZeroCERT

47556 2024-08-26 09:28 66cba4c974f15_swej.exe#space  

05554101e30ffaf2f05439200060852f


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer ScreenShot Http API PWS Create Service Socket DGA Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
12 7 21 3 18.4 M 26 ZeroCERT

47557 2024-08-26 09:30 ven_protected.exe  

d0dd63b98bf3d7e52600b304cdf3c174


Generic Malware UPX Anti_VM PE File .NET EXE PE32 VirusTotal Malware DNS
1 3.6 28 ZeroCERT

47558 2024-08-26 09:30 win.exe  

48dfda3eff897f0a62f71bbac51ff237


UPX PE File PE32 VirusTotal Malware AutoRuns Creates executable files Check virtual network interfaces Windows DNS
1 2 1 6.4 M 44 ZeroCERT

47559 2024-08-26 09:32 Mswgoudnv.exe  

de64bb0f39113e48a8499d3401461cf8


.NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware Buffer PE Check memory Checks debugger buffers extracted unpack itself ComputerName
3.6 M 53 ZeroCERT

47560 2024-08-26 09:33 BaddStore.exe  

26d737343527707f7e4fbad11ef723ad


Generic Malware Malicious Library Malicious Packer UPX PE File .NET EXE PE32 DLL OS Processor Check VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder DNS crashed
1 4.0 M 45 ZeroCERT

47561 2024-08-26 09:34 PURLOG.exe  

457c9342db5fc82febdcf8a348123a0e


Malicious Library UPX PE File PE64 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 21 ZeroCERT

47562 2024-08-26 09:35 Identification-1.exe  

c7cd553e6da67a35d029070a475da837


Emotet Malicious Library UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
2.6 M 46 ZeroCERT

47563 2024-08-26 09:37 surfex.exe  

1f4b0637137572a1fb34aaa033149506


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 12.8 M 26 ZeroCERT

47564 2024-08-26 09:38 winn.exe  

5e7c5bff52e54cb9843c7324a574334b


Malicious Library PE File PE64 VirusTotal Malware Buffer PE Check memory Checks debugger buffers extracted unpack itself
3.4 40 ZeroCERT

47565 2024-08-26 09:39 gagagggagagag.exe  

7f20b668a7680f502780742c8dc28e83


AsyncRAT Malicious Packer .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check Malware download AsyncRAT NetWireRC VirusTotal Malware DNS
1 2 1.8 M 50 ZeroCERT