Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47821 2024-09-04 10:26 66d70e8640404_trics.exe  

b5887a19fe50bfa32b524aaad0a453bc


Malicious Library .NET framework(MSIL) UPX Socket PWS DNS AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Lnk Format GIF Format Malware download VirusTotal Malware AutoRuns PDB Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows RisePro ComputerName Remote Code Execution DNS
1 3 12.4 M 44 ZeroCERT

47822 2024-09-04 10:27 66d70775c548d_v.exe#space  

6f99968cc27d2d6a07a921ab703a5d5d


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications malicious URLs sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
2 1 5 1 13.6 M 43 ZeroCERT

47823 2024-09-04 10:27 66d72df86b9f3_crypted.exe#1  

6b19e5c100db0812ffb7813a1503c05d


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6 14.2 M 49 ZeroCERT

47824 2024-09-04 10:30 66d753b13350c_cry.exe#kiscrypt...  

7935a87d35721d1697e50bebcbec125b


Client SW User Data Stealer ftp Client info stealer Malicious Library .NET framework(MSIL) UPX Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Malware download VirusTotal Malware c&c PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Stealc ComputerName DNS
2 1 1 9.8 M 34 ZeroCERT

47825 2024-09-04 10:32 prompt.exe  

26ea34638c9aab0fb5411b9944f50404


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware crashed
1.6 M 65 ZeroCERT

47826 2024-09-04 10:34 BitLockerToGo.exe  

0c349af12bacc3cda19ae8a9a4acb428


Generic Malware Malicious Library Malicious Packer UPX PE File DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware
1.4 M 41 ZeroCERT

47827 2024-09-04 10:43 tmk.scr  

f257d37c05d29e725071a900ef49f1c9


Generic Malware Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself
2.2 56 guest

47828 2024-09-04 10:58 66d5ddcbb9f86_vyre.exe  

9d1e5520a634731ed9747be9e9af7c5d


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 1 17.0 M 52 ZeroCERT

47829 2024-09-04 11:00 66d5ddc254656_lfem.exe  

24b1ff1f8ba8c5e20613a652b7ddcafb


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
8.4 M 49 ZeroCERT

47830 2024-09-04 11:02 66d7077a2064d_l.exe  

5cdada1cda3c68a8ca61405458e1e587


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 40 ZeroCERT

47831 2024-09-04 11:16 huna.exe  

8424ecf2f95410ceed693e7d1011d26f


Themida PE File PE32 VirusTotal Malware
1.4 M 24 r0d

47832 2024-09-04 17:48 pc.ps1  

8a319fa42e7c7432318f28a990f15696


Generic Malware Antivirus VirusTotal Malware unpack itself
1.6 41 ZeroCERT

47833 2024-09-04 17:48 shell.bat  

978e36e12abdfb849745a694eca47fc6


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 7.2 28 ZeroCERT

47834 2024-09-04 18:03 강연의뢰서.docx  

108180eaed0fe88ebb3cbc783fce110a


Word 2007 file format(docx) ZIP Format unpack itself
1.2 ZeroCERT

47835 2024-09-05 08:33 IAEA.doc.lnk  

1d2b9a986461e97edfff9b91e64e1e5b


Generic Malware AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware Code Injection Check memory Creates shortcut unpack itself suspicious process Interception
1 2 4.6 18 ZeroCERT