Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48226 2024-09-21 14:07 game.exe  

b5466eeb2b35e47ffc7230ec00d6d4c6


Stealc CryptBot Themida PE File PE32 Malware download VirusTotal Malware c&c Malicious Traffic Check memory Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Stealc Windows ComputerName DNS crashed
2 1 1 2 7.4 M 36 ZeroCERT

48227 2024-09-21 14:09 66ed33772bbe7_vdfhsjf16.exe  

5f1ea69f876e6c0b3f52c49cb56a5933


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 17.6 M 44 ZeroCERT

48228 2024-09-21 14:11 66edb89bc4073_crypted.exe#xin  

d687af3b103399aa245807bb719878b7


RedLine stealer Antivirus PWS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself DNS
1 8.6 M 48 ZeroCERT

48229 2024-09-21 14:15 sdhsfd.exe  

ea754070163f8eca914b259096d834f0


Stealc Client SW User Data Stealer Gen1 ftp Client info stealer Generic Malware Antivirus Malicious Library UPX Malicious Packer Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
9 3 17 2 14.6 M 45 ZeroCERT

48230 2024-09-21 14:18 random.exe  

9b638c429ac9e4c032d7e6852b464dbd


Generic Malware Malicious Library UPX Code injection AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Ransomware Exploit Browser crashed
9.0 M 14 ZeroCERT