Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47626 2024-08-27 15:14 FuzeLoader.exe  

a6b65cfc697dbbdcde8f19d2ab7a61d9


ROMCOM RAT Downloader PE File PE64 VirusTotal Malware DNS
1 1.8 16 ZeroCERT

47627 2024-08-27 15:15 test.exe  

c04a91e68f4d54aac6959c0f8bfa38b7


Gen1 Browser Login Data Stealer Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE File PE64 OS Processor Check DLL ftp wget DllRegisterServer dll VirusTotal Malware Check memory Creates executable files unpack itself
3.4 M 61 ZeroCERT

47628 2024-08-27 15:15 discordnitrogen.exe  

2db515aa4c8ba2b4e6878e7e0b550c8f


Gen1 Generic Malware Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check DLL ZIP Format Check memory Checks debugger Creates executable files unpack itself
1.2 M ZeroCERT

47629 2024-08-27 15:16 66cc3862316e2_vaiwkl.exe#d15  

b487d459d6a3fe60ff7bb30aa3938370


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.6 M 41 ZeroCERT

47630 2024-08-27 15:17 leks.dll  

6034e37cba0561fc20d10700e5d9cc02


Generic Malware Malicious Library UPX PE File DLL PE64 OS Processor Check VirusTotal Malware unpack itself crashed
1.8 M 32 ZeroCERT

47631 2024-08-27 15:21 2.exe  

31fa727012b592325d876a801c0f1f83


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check PE64 VirusTotal Cryptocurrency Miner Malware Cryptocurrency AutoRuns PDB Creates executable files unpack itself AppData folder Tofsee Windows Remote Code Execution DNS crashed CoinMiner
1 4 3 4.0 M 35 ZeroCERT

47632 2024-08-27 15:21 Minecom.exe  

08147f2060315f23b4b5e6daeef11f66


UPX PE File .NET EXE PE32 OS Processor Check Malware suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces AntiVM_Disk VM Disk Size Check ComputerName
1 2 3.8 M ZeroCERT

47633 2024-08-27 15:22 csrss.exe  

a1c95767e2aae895bca002778203b26e


Generic Malware Suspicious_Script_Bin Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware AutoRuns Checks debugger Creates executable files unpack itself AppData folder Windows
3.8 M 37 ZeroCERT

47634 2024-08-27 15:23 penguin.exe  

bbb6c17b5412df1003825be613b20a38


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware PDB DNS
1 1.2 M 4 ZeroCERT

47635 2024-08-27 15:24 Aquarius.exe  

a18fe6fa6a9296ba8faf7e7dcfd5d0f8


Gen1 Generic Malware task schedule Downloader Malicious Library UPX Admin Tool (Sysinternals etc ...) .NET framework(MSIL) Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows Java
8.6 M 55 ZeroCERT

47636 2024-08-27 15:25 restart1.exe  

a53afb86a8787bf91dcb86a37dd4ba0b


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB
1.2 M 34 ZeroCERT

47637 2024-08-27 15:26 leto.exe  

a854823ade2ebde26f0869fdd05c5cce


Amadey Stealc Gen1 Themida Packer Generic Malware Downloader Malicious Library UPX Malicious Packer Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogg Browser Info Stealer Malware download Amadey FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c AutoRuns MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare suspicious process AppData folder sandbox evasion VMware anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
10 3 20 3 16.8 M 29 ZeroCERT

47638 2024-08-27 15:30 qqlive_kvdun_108411.exe  

7609af2419ddda223fa0685d13590303


Generic Malware PhysicalDrive Malicious Library Admin Tool (Sysinternals etc ...) UPX Downloader Malicious Packer Antivirus Anti_VM PE File PE32 OS Processor Check PNG Format BMP Format DLL VirusTotal Malware PDB Check memory Creates executable files unpack itself Windows utilities AppData folder sandbox evasion China Interception Windows Browser Remote Code Execution
4 5 8.0 M 29 ZeroCERT

47639 2024-08-27 15:32 66cc6466906a0_ww9.exe#kis9  

865adfa302bfc57219c6541aebbfa1c9


Stealc Client SW User Data Stealer Gen1 ftp Client info stealer Generic Malware Malicious Library UPX Malicious Packer Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Malware c&c PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications Check virtual network interfaces suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser ComputerName DNS Software plugin
10 5 17 2 16.4 M 40 ZeroCERT

47640 2024-08-27 19:35 msvci70.dll  

ca3a59d92f479a17e5ca6a0e13896846


UPX PE File DLL PE32 PDB Check memory
0.4 guest