Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
47911 2024-09-10 10:12 66df4cfda9a79_software.exe  

2e4c46fcdaaaa624bd6f37075077b972


Malicious Library Malicious Packer UPX Anti_VM PE File PE64 OS Processor Check VirusTotal Malware
1.0 M 8 ZeroCERT

47912 2024-09-10 10:14 66dd9b20d75ea_otr.exe#kisotrme...  

805c6dfa454dc8a5538514cc30608f17


RedLine stealer Malicious Library .NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself
2.2 M 48 ZeroCERT

47913 2024-09-10 10:14 ScreenDataSync.exe  

66f4c467d6f87afe16daafb012f27e76


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.4 M 16 ZeroCERT

47914 2024-09-10 10:16 66db373332432_def.exe#kisotr  

6bed76e79419acb6cc20bcacf67dec0a


Stealc Client SW User Data Stealer ftp Client info stealer Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Malware download VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Stealc ComputerName DNS
2 1 1 2 10.4 M 50 ZeroCERT

47915 2024-09-10 10:16 66df167d4ce6b_v.exe#space  

84354d3c9965d9a0878596e347a34f39


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.2 M 33 ZeroCERT

47916 2024-09-10 10:19 66df0aabad68a_crypted.exe#1  

db1fbaf680dc245b486db86fa852f655


RedLine stealer Antivirus Malicious Library .NET framework(MSIL) ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft Buffer PE PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 5 6 1 17.2 M 40 ZeroCERT

47917 2024-09-10 10:21 66dda11e4dbe5_crystealc.exe#ki...  

bd34c12dc1eb99f17fd0cbd581dfce9f


Stealc Client SW User Data Stealer ftp Client info stealer Generic Malware Malicious Library .NET framework(MSIL) UPX Http API PWS KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Malware download VirusTotal Malware c&c PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Stealc ComputerName DNS
2 1 1 2 10.0 M 46 ZeroCERT

47918 2024-09-10 10:22 66df168687411_s.exe#space  

46a221059a8fae9bbbc96fdf1f794884


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer Http API PWS Create Service Socket DGA ScreenShot Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
12 7 21 3 19.0 M 32 ZeroCERT

47919 2024-09-10 10:23 66daf6d8ac980_PeakSports.exe#p...  

bdefc54e5fe6f091f968a28aa63783ba


Generic Malware Suspicious_Script_Bin Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder sandbox evasion WriteConsoleW Windows ComputerName
6.6 M 35 ZeroCERT

47920 2024-09-10 10:25 burda.exe  

fb715bbfab832a6a7b4e05fc94a74b88


Amadey Themida Generic Malware Malicious Library UPX PE File PE32 OS Processor Check Browser Info Stealer Malware download Amadey VirusTotal Malware AutoRuns Malicious Traffic Checks debugger Creates executable files exploit crash unpack itself Checks Bios Detects VMWare AppData folder VMware anti-virtualization installed browsers check Windows Exploit Browser DNS crashed
3 3 7 2 12.6 M 44 ZeroCERT

47921 2024-09-10 10:26 66dd9b656c6a0_cry.exe#kiscrmet...  

3879291a4c9563f65101294045b3b427


RedLine stealer Malicious Library .NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 45 ZeroCERT

47922 2024-09-10 10:27 66ded92c118ad_svvfdd.exe#space  

69f26c9e7dfc93644c1c9ebaeff84128


Stealc Client SW User Data Stealer ftp Client info stealer Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
10 2 18 2 13.8 M 41 ZeroCERT

47923 2024-09-10 10:28 66ded92ea2a29_vffdg.exe#space  

b525b80d2056db699ed31d53b5955588


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 42 ZeroCERT

47924 2024-09-10 10:29 66ddde9c4d56a_crypted.exe#1  

5ac3358abe03a6faa36599fe785b85b2


RedLine stealer Suspicious_Script_Bin Antivirus Malicious Library .NET framework(MSIL) ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft Telegram Buffer PE AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder WriteConsoleW installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
3 9 9 1 20.6 M 41 ZeroCERT

47925 2024-09-10 10:30 v.exe  

65208d6a2c36c758bab95b17fb22e19e


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 1 15.4 M 43 ZeroCERT