Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48211 2024-09-21 13:48 66ed9885d9aee_Day2.exe  

1fedf314d7c5ed06ff6833c9c8fe5441


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName Remote Code Execution
2.6 12 ZeroCERT

48212 2024-09-21 13:49 66ecb44e7f1ca_vdfshd15.exe  

82661ca16a1713263f9a11beaf43efee


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.0 M 51 ZeroCERT

48213 2024-09-21 13:50 l6E.exe  

fac2188e4a28a0cf32bf4417d797b0f8


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows
9.0 M 55 ZeroCERT

48214 2024-09-21 13:52 66ed0c1bc99a0_setup333.exe#lyl...  

55cf0ba0a65d11eee638b11ba9e2f3a1


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.2 M 43 ZeroCERT

48215 2024-09-21 13:53 noode.exe  

38f41466d936e5e4edc1eaae88f698cd


Emotet Gen1 Malicious Library UPX PE File PE32 MZP Format DLL PE64 OS Processor Check VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder
2.4 M 18 ZeroCERT

48216 2024-09-21 13:54 66ed5659d6ee7_vcxhsdf12.exe  

9bcf6be0b4b8eff680b0d8539237a496


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 16.0 M 49 ZeroCERT

48217 2024-09-21 13:55 66ed8059174df_ConsiderMilfs.ex...  

12860c8f39570ea1a7256b7ed9dabccf


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
7.4 M 23 ZeroCERT

48218 2024-09-21 13:56 66ed337476b90_vfdshd.exe  

80a0a1a9bcd5080ade393da387e7cebb


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 16.4 M 32 ZeroCERT

48219 2024-09-21 13:58 66edcd212760d_set3.exe#lyla  

42924131895c18395ecebb6e49f10b5f


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
1.8 M 26 ZeroCERT

48220 2024-09-21 13:59 66ecb4509c214_vbfdsg12.exe  

7ee5fd9d304831f5c6862c705f3bc489


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 52 ZeroCERT

48221 2024-09-21 14:00 66ed7ef071886_crypted.exe#1  

72f7c1208efd829ad580e839494a681c


RedLine stealer Antivirus ScreenShot PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6 12.8 M 29 ZeroCERT

48222 2024-09-21 14:02 66ed336eac985_vdfhssfdg12.exe  

6b082832f014548bf1703ddaed1e16b9


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 15.4 M 48 ZeroCERT

48223 2024-09-21 14:02 random.exe  

e0bb28202965797f022195320f3287d5


Stealc Amadey Gen1 Themida Generic Malware Malicious Library UPX Malicious Packer Code injection Anti_VM AntiDebug AntiVM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Amadey FTP Client Info Stealer Vidar Email Client Info Stealer Malware c&c AutoRuns MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Checks Bios Collect installed applications Detects VMWare AppData folder malicious URLs sandbox evasion VMware anti-virtualization installed browsers check Ransomware Stealc Stealer Windows Exploit Browser Email ComputerName DNS Software crashed plugin
10 3 19 3 22.2 M ZeroCERT

48224 2024-09-21 14:03 66ed33717e4c1_vfdshfdag15.exe  

cd681a24c9d79c3af8caa1843296a062


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 16.0 M 47 ZeroCERT

48225 2024-09-21 14:05 66ebb3bf78bd6_Send.exe#111us30...  

098e15e88e5332253356c78badf8d479


UPX PE File PE32 OS Processor Check VirusTotal Malware Buffer PE AutoRuns PDB Code Injection Malicious Traffic buffers extracted Creates executable files unpack itself Windows Remote Code Execution DNS
1 1 1 9.0 M 36 ZeroCERT