Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47731 2024-09-02 09:57 yr68.exe  

ea321922de9babb9a9b8e25bed931ff6


UPX PE File PE32 VirusTotal Malware
1.2 M 55 ZeroCERT

47732 2024-09-02 09:59 goldenballonhourstokissherlips...  

cd3b14daed16ebb53330abb3b7f41797


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
1 3 1 4.8 M 40 ZeroCERT

47733 2024-09-02 10:01 66d2b5c78630c_crypted.exe#1  

ae9de1093d87672c550524299e8df649


RedLine stealer Malicious Library Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6 12.0 M ZeroCERT

47734 2024-09-02 10:02 joffer2.exe  

4386df2790a9752e9cf0424dca91ad15


Generic Malware Admin Tool (Sysinternals etc ...) UPX PE File PE32 DLL Malware download VirusTotal Malware Malicious Traffic AppData folder suspicious TLD CryptBot DNS
1 2 3 3.4 M 30 ZeroCERT

47735 2024-09-02 10:14 66d1ec0485e55_stealc_default.e...  

0ce7687b9cd4c4acb89247fb9aef7c4c


Stealc Client SW User Data Stealer ftp Client info stealer Malicious Library Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Malware download FTP Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Collect installed applications suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS Software plugin
3 1 8 2 14.4 M ZeroCERT

47736 2024-09-02 10:16 feishu_update.exe  

1b8f93f22f2aee44c16f9886b44549b8


PE File PE64 VirusTotal Malware
1.2 M 56 ZeroCERT

47737 2024-09-02 10:16 66d1ee217b021_1202156955.exe#1...  

f63c0bf42b8e72dc1cad0cad0b08ce62


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 54 ZeroCERT

47738 2024-09-02 10:16 66d1e3d3208e9_vfdw12.exe#d12  

b01121b9f9a1e48a7737d6b43e8a7fe5


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Malicious Library Antivirus UPX Malicious Packer Http API PWS HTTP Code injection Internet API ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
10 2 13 1 16.8 M 54 ZeroCERT

47739 2024-09-02 10:18 66d1b31955f50_SunshineSolving....  

0a34380175bb4da2cce136e0cb3d3e04


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check ftp VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.8 M 14 ZeroCERT

47740 2024-09-02 10:20 %E6%94%BE%E5%81%87%E5%80%BC%E7...  

07898838cbb961a9c4a61b180b6b48da


CoinMiner Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE64 OS Processor Check MSOffice File PNG Format VirusTotal Malware suspicious privilege Code Injection Check memory buffers extracted RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces suspicious process Windows Exploit ComputerName Remote Code Execution DNS crashed
1 8.2 M 18 ZeroCERT

47741 2024-09-02 10:21 MeMpEng.exe  

2de33a20655435a626ae19973654e95c


Formbook Generic Malware Malicious Library UPX PE File PE32 OS Processor Check DLL Browser Info Stealer VirusTotal Malware Checks debugger buffers extracted Creates executable files unpack itself AppData folder suspicious TLD Java Browser DNS
19 21 6 16 7.6 M 48 ZeroCERT

47742 2024-09-02 10:22 jhg.exe  

b21e324a39b4279504b10fee217239d3


Browser Login Data Stealer Generic Malware Malicious Library Downloader Malicious Packer UPX PE File PE32 OS Processor Check VirusTotal Malware AutoRuns Windows DNS
1 4.6 M 61 ZeroCERT

47743 2024-09-02 10:23 66d1e3d63bd13_sbgdwf.exe#space  

bde7cb83c1fa62b052a3b255a79dfc1e


Stealc Client SW User Data Stealer ftp Client info stealer Malicious Library Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 2 12.0 M 24 ZeroCERT

47744 2024-09-02 10:24 66cef067bb8bb_CoinAccording.ex...  

6cd2eb2553ba19d387c45537a16547f4


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS
1 7.2 M 17 ZeroCERT

47745 2024-09-02 10:24 66d1ee505e71e_Build.exe  

a7b783146953de955a829962edd77767


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 53 ZeroCERT