Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48376 2024-09-25 10:57 vdshd16.exe  

477f0641023c28b462ea3d1b0a62151d


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName DNS
1 3.2 M 27 ZeroCERT

48377 2024-09-25 10:57 Golove.exe  

e9dc029457e9d23c8db988c4c0585bfa


UPX PE File PE64 OS Processor Check Emotet VirusTotal Malware PDB Code Injection sandbox evasion DNS crashed
1 7.6 M 47 ZeroCERT

48378 2024-09-25 10:59 66f2c6e0e5c2a_crypted.exe#1  

79903fe5b1c05b1283fd784af19a43e0


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.6 M 28 ZeroCERT

48379 2024-09-25 11:00 66f25393e0294_STcryotr.exe#ste...  

e457e6ce6ea00506eec98fab4ab49f74


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
7.4 M 23 ZeroCERT

48380 2024-09-25 11:02 veqfy15.exe  

a2fc88996b2fe412ad287321f6a18591


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 34 ZeroCERT

48381 2024-09-25 11:02 66f31d151f82e_lyla34.exe  

6ea7e8d78f2c13dd21e646f0c84a6f55


Malicious Library PE File PE32 VirusTotal Malware unpack itself Remote Code Execution
2.2 M 25 ZeroCERT

48382 2024-09-25 11:03 66f3128883969_crypted.exe#1  

a1c72950a28756d4f53171395e10af13


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.6 M 22 ZeroCERT

48383 2024-09-25 11:04 vfdshh12.exe  

55a5f2beec3dd4e2e81bd8c88b231ede


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 39 ZeroCERT

48384 2024-09-25 11:12 66f32080436ad_deepweb.exe#deep  

14bd964c6e45ac40d474f56d03cb98ce


RedLine Infostealer RedLine stealer RedlineStealer Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 5 7.4 M 58 ZeroCERT

48385 2024-09-25 11:12 stories.exe  

d95075fa0cc023415833d7569d65adc0


Emotet Gen1 Generic Malware Malicious Library UPX PE File PE32 MZP Format DLL OS Processor Check PE64 VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder ComputerName crashed
4.0 M 23 ZeroCERT

48386 2024-09-25 11:12 dl  

376af2756c19e59540331f6056b5c321


Malicious Library UPX PE File PE32 OS Processor Check unpack itself Remote Code Execution
1.4 M ZeroCERT

48387 2024-09-25 11:14 getlab.exe  

78701f8bedb23d81e15ee0c8b7cb826f


Emotet Gen1 Generic Malware Malicious Library UPX PE File PE32 MZP Format DLL OS Processor Check PE64 VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder ComputerName crashed
3.2 M 14 ZeroCERT

48388 2024-09-25 11:14 66f0297e9c3eb_15.exe  

38ef48a2e156067f1770497335e92066


RedLine Infostealer RedLine stealer Malicious Library .NET framework(MSIL) UPX PWS AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Browser Info Stealer Malware download Malware Buffer PE PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself malicious URLs IP Check Tofsee Windows Browser ComputerName Remote Code Execution DNS Downloader
11 20 17 5 12.8 M ZeroCERT

48389 2024-09-25 11:16 66ed8969a40d8_15_2024092017363...  

f48cbe7b6a8dc2ec21b01f117913b603


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself ComputerName Remote Code Execution
3.6 M 40 ZeroCERT

48390 2024-09-25 11:18 66f2966e903c0_AntiLogger.exe  

93848befe2685e3de677ef88df8081d7


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 DllRegisterServer dll OS Processor Check VirusTotal Malware
0.6 M 13 ZeroCERT