Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48406 2024-09-26 09:58 niceworkingskillmadeeveryoneha...  

7a9a05109dd848058fd327bc38459a3d


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Windows Exploit DNS crashed
1 3 8 4.8 M 40 ZeroCERT

48407 2024-09-26 09:59 dl  

d9d92da97544f0c2116d7375f2665110


Malicious Library UPX PE File PE32 OS Processor Check unpack itself
0.8 M ZeroCERT

48408 2024-09-26 10:00 vnobizxc.exe  

a4cd1ff60c7b69df5a061df3365e60c7


XWorm Generic Malware WebCam Malicious Library .NET framework(MSIL) Antivirus KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Telegram PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName DNS Cryptographic key keylogger
4 4 13.2 M 45 ZeroCERT

48409 2024-09-26 10:00 goodimageswithgoodfeatureshave...  

59e879eb2a3f5f54db609e47b0596813


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
1 3 1 4.6 M 38 ZeroCERT

48410 2024-09-26 10:02 nVvfLpoRTEWzzG.exe  

48977f1b641a9a3d88329ac470152381


Generic Malware Malicious Library Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 8 9 15.8 M 47 ZeroCERT

48411 2024-09-26 10:05 66f4247962974_vfdsgasd12.exe  

8b0b12811b60a92a72b636a46fadb0ba


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 37 ZeroCERT

48412 2024-09-26 10:08 3333.exe  

0336bc6e2759bd7b5c400a447a55756e


Generic Malware Malicious Library Malicious Packer UPX PE File DllRegisterServer dll PE32 MZP Format OS Processor Check JPEG Format DLL VirusTotal Malware AutoRuns suspicious privilege Creates executable files unpack itself AppData folder sandbox evasion Tofsee Windows Advertising Google ComputerName DNS DDNS crashed keylogger
3 9 2 8.4 M 66 ZeroCERT

48413 2024-09-26 10:10 1.exe  

814eede0c07f64e2ce4efbeede8928f4


Generic Malware Malicious Library Malicious Packer ASPack UPX PE File DllRegisterServer dll PE32 MZP Format OS Processor Check JPEG Format DLL VirusTotal Malware AutoRuns suspicious privilege Creates executable files unpack itself AppData folder sandbox evasion Tofsee Windows Advertising Google ComputerName DNS DDNS crashed keylogger
3 9 2 8.8 M 65 ZeroCERT

48414 2024-09-26 10:11 win11.exe  

613d958a64df2e883b11d994f57b1c80


Gen1 Generic Malware Malicious Library UPX PE File PE32 MZP Format JPEG Format DLL VirusTotal Malware AutoRuns Check memory Creates executable files RWX flags setting unpack itself Tofsee Windows Advertising Google ComputerName DNS DDNS crashed keylogger
3 10 2 10.4 M 66 ZeroCERT

48415 2024-09-26 10:22 Hkbsse.exe  

e4f3ed3daf21363918afbc91db6f775b


Amadey Generic Malware Malicious Library Malicious Packer UPX Antivirus PE File PE32 OS Processor Check DLL PE64 JPEG Format Browser Info Stealer Malware download Amadey FTP Client Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency powershell AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder sandbox evasion installed browsers check Windows Browser ComputerName Cryptographic key Software
4 2 3 12.0 51 guest

48416 2024-09-26 10:27 66f4186b24569_sfx_123_500.exe  

9aca15a320ce8fe7eabb268f7116cbcc


Malicious Library UPX PE File PE32 VirusTotal Malware Check memory
1.0 16 ZeroCERT

48417 2024-09-26 10:28 xBneIooWzQjjOOg.exe  

432644163e0aaa8a0269179e0e036eae


AgentTesla Formbook Generic Malware Malicious Library .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself suspicious process WriteConsoleW Windows Browser Email ComputerName Cryptographic key Software crashed
11.4 M 40 ZeroCERT

48418 2024-09-26 10:29 66f4247628ddf_vfdsgsfd15.exe  

38d89dee3e519cce0366a2ce70b7ec0d


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.8 M 34 ZeroCERT

48419 2024-09-26 10:29 66f424844286a_vfdhgsd16.exe  

77011ba24d1088a963898abc72c6e129


PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself WriteConsoleW ComputerName
2.6 M 28 ZeroCERT

48420 2024-09-26 10:32 VbcXXnmIwPPhh.exe  

70262b2a7d84c44a127705652cdb57dc


Formbook Generic Malware Malicious Library .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 6 9 16.8 M 24 ZeroCERT