Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47641 2024-08-27 22:14 66cd1d485d44c_lsfjf3n.exe  

50d8852654d517f75977552d4a606941


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.0 M 22 ZeroCERT

47642 2024-08-27 22:18 360.exe  

7645db87b80a529917917a893dce7cc8


Generic Malware Malicious Library UPX PE File PE32 Malware download VirusTotal Malware AutoRuns Creates executable files ICMP traffic RWX flags setting unpack itself AppData folder Windows DNS crashed
7 2 7.6 66 ZeroCERT

47643 2024-08-28 03:04 r57.exe  

6b9ea327b920218c777a34b3193826a2


UPX PE File PE32 VirusTotal Malware
1.2 M 54 guest

47644 2024-08-28 10:13 vsfdki.exe  

1004e31f8b0d72820d77e16371794c0e


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.0 M ZeroCERT

47645 2024-08-28 10:14 66ce162f61921_crypted.exe#1  

fc980ed1da175090e176c4c4b9b1fd01


Client SW User Data Stealer Gen1 ftp Client info stealer Generic Malware Antivirus Malicious Library UPX Malicious Packer Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
9 1 17 14.2 27 ZeroCERT

47646 2024-08-28 10:15 66ce1115726ee_vjweiq15.exe#d15  

4aecaf0aad3b9c42ea948554a7cae1a7


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 27 ZeroCERT

47647 2024-08-28 10:15 66ce237125ba7_vjrew2ge.exe#spa...  

985591b59446fcf5dadd314fdbda90e4


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.8 M 39 ZeroCERT

47648 2024-08-28 10:17 66ce1679b8344_Main.exe  

eb0830efaf21e7e426eb602118f70c62


Emotet Generic Malware Suspicious_Script_Bin Downloader Malicious Library UPX Malicious Packer Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persiste VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger Creates executable files Windows utilities malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
5.2 M 10 ZeroCERT

47649 2024-08-28 10:18 66ce0aa740197_1112.exe  

861faba8e780fc1f323eb46f390fb6ca


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
1.8 M 29 ZeroCERT

47650 2024-08-28 10:19 Underldighedens.vbs  

9f920797b154f49ea9e2bcaea7e8607f


Generic Malware Antivirus powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 3 7.0 ZeroCERT

47651 2024-08-28 10:21 66cdfc485c6f9_instruction.exe#...  

0a7f5d0b4dab9c77dc68db0ea99b0058


Emotet Malicious Library UPX PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName Remote Code Execution
3.2 M 25 ZeroCERT

47652 2024-08-28 10:22 saofewk.exe  

a0a71a13e2ea5c606f46ced827fdc156


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer ScreenShot Http API PWS Create Service Socket DGA Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
12 7 21 3 18.0 M 26 ZeroCERT

47653 2024-08-28 10:24 66ce111830a90_vrn12.exe#d12  

25629d287f7defb4e86755910b5926bf


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.0 M 38 ZeroCERT

47654 2024-08-28 10:27 66ce056ac07c2_crypted.exe#1  

b79ed7b267159f2b1497de63786e6f6d


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 10.0 M 37 ZeroCERT

47655 2024-08-28 12:25 seethedifferentofcupcakewhichm...  

603f3fc7d36b263a35aebc03ca35ee34


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 3 1 5.0 M 35 ZeroCERT