Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47671 2024-08-29 09:13 66cf75d3791d7_vrewqgq.exe#spac...  

1ef9bbed957bcd2df5a639e04a67f8bb


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.8 M 22 ZeroCERT

47672 2024-08-29 09:15 66cf769b69d70_crypted.exe#1  

6d90f5899ff47cd3519ee0f53b8900f6


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6 12.8 M 23 ZeroCERT

47673 2024-08-29 09:15 66cf81753addd_vsldqfs15.exe#d1...  

8ae4605ae214af3ba375ad58263ca707


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 17.0 M 32 ZeroCERT

47674 2024-08-29 09:20 66cf8177d72f6_sdgkos.exe#space  

8e41d2107579afb2911dccffeab97f1c


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer Http API PWS Create Service Socket DGA ScreenShot Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
12 7 21 3 18.2 M 30 ZeroCERT

47675 2024-08-29 09:23 66cf5fb9ac3ce_xin.exe  

62abfe8a7ad3a99ea4d57734689952ef


RedLine stealer Antivirus PWS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself DNS
1 8.4 34 ZeroCERT

47676 2024-08-29 09:23 cred64.dll  

4a4527a3ecf33ac8dc86e12681abf97b


Generic Malware Malicious Library UPX Antivirus PE File DLL PE64 OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency powershell PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process sandbox evasion installed browsers check Windows Browser ComputerName DNS Cryptographic key Software
1 1 9.8 M 41 ZeroCERT

47677 2024-08-29 09:25 66cf54ea92102_ddd.exe#1  

171eeb8ca5c439e8af9e180a5f6a09f8


Malicious Library UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName Remote Code Execution
3.0 14 ZeroCERT

47678 2024-08-29 09:26 66cf56ae6e345_ColeusesWalkatho...  

afed25699b68eb6b0d7fa7fa382c55b7


RedLine Infostealer UltraVNC Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key crashed
6.2 M 34 ZeroCERT

47679 2024-08-29 09:28 66cf32a057fdd_vnre.exe#space  

99fc8aa825d1814814de66088bdb9787


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 37 ZeroCERT

47680 2024-08-29 09:31 exbuild.exe  

f5d7b79ee6b6da6b50e536030bcc3b59


Generic Malware Malicious Library Malicious Packer UPX PE File PE32 OS Processor Check Malware download Amadey VirusTotal Malware AutoRuns Malicious Traffic Creates executable files unpack itself AppData folder human activity check Windows DNS
2 3 5 1 7.6 M 56 ZeroCERT

47681 2024-08-29 09:31 random.exe  

0dbbf22c79d18bda3b9b753159f91fc7


Amadey Stealc Gen1 Generic Malware Themida Packer Malicious Library UPX Malicious Packer Anti_VM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Amadey FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c AutoRuns MachineGuid Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare AppData folder AntiVM_Disk sandbox evasion VMware anti-virtualization VM Disk Size Check installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
10 3 20 3 16.4 M 42 ZeroCERT

47682 2024-08-29 09:31 66cf32a438fcf_vwj12.exe#d12  

5c0f5d0e4e61f2ac03fc8115ad4d3a8f


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.0 M 35 ZeroCERT

47683 2024-08-29 09:33 66cf567bc9ba6_NEWCR.exe#1123  

e3a08541070dcb1f4fe7d82af869c3bc


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Windows
2.8 M 33 ZeroCERT

47684 2024-08-29 09:33 clip64.dll  

babfda6375b07d76f6a46af11bdc3787


Amadey Generic Malware Malicious Library UPX PE File DLL PE32 OS Processor Check VirusTotal Malware Malicious Traffic Checks debugger unpack itself DNS
1 1 3.4 M 39 ZeroCERT

47685 2024-08-29 09:38 66cf32a69f7f4_sgren.exe#space  

2fbc696f6e87a76007164c4fb93e979c


Stealc Client SW User Data Stealer Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer Http API PWS Create Service Socket DGA ScreenShot Escalate priviledges Steal credential Sniff Audio HTTP DNS Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications suspicious process sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
11 2 18 2 14.6 M 37 ZeroCERT