Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47701 2024-08-30 11:07 XClient.exe  

36a1ae0555b5c56da0d72fc78864f11e


Malicious Library Antivirus UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself AntiVM_Disk VM Disk Size Check Windows ComputerName Cryptographic key
4.0 M 52 ZeroCERT

47702 2024-08-30 11:08 12.exe  

a26e3c5047080c42ff5ef9279c17d41e


PE File PE64 VirusTotal Malware crashed
1.8 M 36 ZeroCERT

47703 2024-08-30 11:09 66d0cd9755a01_sbwd.exe#space  

7fee72ea1dd13c340355baa7fe9c574a


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer ScreenShot Http API PWS Create Service Socket DGA Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications suspicious process malicious URLs sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
13 3 19 3 17.2 M 26 ZeroCERT

47704 2024-08-30 11:09 66d0cd8fb6f7b_lgjfd.exe#space  

087f21847d13d50158683c834471728c


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.0 M 25 ZeroCERT

47705 2024-08-30 11:10 u888.exe  

f4d6d6ea62cb666b6fee9d00bdb77350


UPX PE File PE32 VirusTotal Malware
1.2 M 55 ZeroCERT

47706 2024-08-30 11:12 66d08591035ef_AttachmentDaught...  

abb713cf90e8345c0b6b79345cbdc9d6


Generic Malware Suspicious_Script_Bin Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.4 M 13 ZeroCERT

47707 2024-08-30 11:14 66d0cd9a65b5d_vqwergf.exe#spac...  

70567fae269796bf407322d0a4435054


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications malicious URLs sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
2 1 5 1 13.4 M 26 ZeroCERT

47708 2024-08-30 11:16 mapp.exe  

cb466c26bb103105b293f2c6c9eecac8


Gen1 Generic Malware Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
1.4 M 53 ZeroCERT

47709 2024-08-30 11:20 MEmpEng.exe  

3412e23523a0f4f6da613485bd7fdb38


Formbook Generic Malware Malicious Library UPX PE File PE32 OS Processor Check DLL Browser Info Stealer VirusTotal Malware Checks debugger buffers extracted Creates executable files unpack itself AppData folder Java Browser DNS
15 17 6 14 6.2 M 28 ZeroCERT

47710 2024-08-30 11:21 54.exe  

0b1d213e54d820dd3fefa386aa3e1f43


Generic Malware Downloader UPX PE File ftp PE64 OS Processor Check VirusTotal Malware PDB
1.4 M 46 ZeroCERT

47711 2024-08-30 11:23 nvidia.exe  

4b3659cdd58a9f5cda08278568d65da1


Malicious Library VMProtect PE File PE64 VirusTotal Malware DNS
1 2.4 M 21 ZeroCERT

47712 2024-08-30 16:37 7fda1e50488896f329561b30ea0c3f...  

8d2b522ca500a1fe0745223e1578ebae


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

47713 2024-08-30 16:38 fd78ad3be58e5d0cbac1242ccdcbd1...  

874858781e07cb3c3ce013b9e11dd7bc


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

47714 2024-08-30 16:38 f5c9ee003dc4f1dd578a393102938f...  

a1a12d64ae5e98d717e4a31fac953a8d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

47715 2024-08-30 16:39 374b481f704c5ac8d04e4d92f2df5e...  

6a5868425d6a234f502cc93da9013df2


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest