Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48826 2024-10-14 11:13 DocuSign.exe  

4a1e0a1302e5143652b8cdc7d29847a2


Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE File PE64 OS Processor Check DLL icon JPEG Format ZIP Format VirusTotal Malware Check memory Creates executable files Ransomware
2.4 8 ZeroCERT

48827 2024-10-14 11:17 241007.lnk  

7eb7d0133965022ad362132782da9d15


Generic Malware task schedule Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6.0 23 ZeroCERT

48828 2024-10-14 11:22 670a8ccf0c6f9_LofiseNose.exe  

400af20bb680795b1a047b588d8f1b26


Gen1 Generic Malware Malicious Library UPX ScreenShot AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware PDB Code Injection buffers extracted unpack itself
8.0 47 ZeroCERT

48829 2024-10-14 11:26 nicefornewthingstogetmebackwit...  

904af9fb7e5bee74577f430af1080585


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
1 2 5 5.6 38 ZeroCERT

48830 2024-10-14 11:27 utility-inst.exe  

0d43698dffc5ee744f805a699df25c00


Generic Malware Malicious Library UPX Antivirus PE File PE32 MZP Format OS Processor Check DLL PE64 VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName Cryptographic key crashed
1 2 1 7.6 46 ZeroCERT

48831 2024-10-14 11:27 7f3c2473d1e6.exe  

de2af610c33df4386b17ddc9b532bfd1


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Generic Malware Malicious Library UPX Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File PE32 OS Processor Check FTP Client Info Stealer Malware Telegram MachineGuid Code Injection Malicious Traffic Check memory buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process AppData folder malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software crashed
3 5 3 1 15.4 ZeroCERT

48832 2024-10-15 14:18 Telltalely.chm  

19a2f85327b3bca4544ea2a0880a5c5f


Suspicious_Script_Bin AntiDebug AntiVM Code Injection Check memory crashed
1.4 ZeroCERT

48833 2024-10-15 14:18 artifact.exe  

cecc2b6b3bd5983b991fd86a185952b6


Malicious Library PE File PE64 Malware download Cobalt Strike Cobalt VirusTotal Malware RWX flags setting unpack itself ComputerName DNS
2 1 2 3.8 M 63 ZeroCERT

48834 2024-10-15 14:20 test.exe  

e15c800e9c74967984dfd1f7fb68ec99


Malicious Library Admin Tool (Sysinternals etc ...) PE File .NET EXE PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself
1.4 3 ZeroCERT

48835 2024-10-15 14:20 neofetch.exe  

d6b10fe0f03dc8bdf3cd5ec9e4e3d305


Generic Malware UPX Antivirus PE File PE64 PowerShell VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName DNS Cryptographic key
1 1 5 8.4 M 53 ZeroCERT

48836 2024-10-15 14:24 swf.exe  

c02569d1105aa9135737cf3c1052e9dc


Emotet Gen1 Generic Malware Malicious Library Confuser .NET UPX Admin Tool (Sysinternals etc ...) PE File PE32 MZP Format OS Processor Check DLL PE64 DllRegisterServer dll VirusTotal Malware Checks debugger Creates executable files unpack itself AppData folder ComputerName crashed
3.6 M 18 ZeroCERT

48837 2024-10-15 14:24 stail.exe  

c098830ac7a7e0ea481dba5c2d7e4f92


Emotet Gen1 Generic Malware Malicious Library Confuser .NET UPX Admin Tool (Sysinternals etc ...) PE File PE32 MZP Format OS Processor Check DLL DllRegisterServer dll PE64 Check memory Checks debugger Creates executable files unpack itself AppData folder ComputerName crashed
2.6 M ZeroCERT

48838 2024-10-15 14:25 RRFCCE.txt.exe  

57d3d8dd95d86ac35f4b428da9cc1e30


Browser Login Data Stealer Generic Malware Malicious Library Downloader Malicious Packer UPX PE File PE32 OS Processor Check ICMP traffic Windows DNS DDNS keylogger
2 2 3.4 ZeroCERT

48839 2024-10-15 14:26 CrazyCoach.exe  

05894e6439e626412c11b1c23eac073f


Gen1 Generic Malware Malicious Library Malicious Packer UPX PE File PE32 OS Processor Check DLL ftp VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself AppData folder Windows Update Remote Code Execution
4 4 4 6.0 54 ZeroCERT

48840 2024-10-15 14:27 builder.exe  

c2bc344f6dde0573ea9acdfb6698bf4c


BlackMatter Ransomware Malicious Packer UPX PE File PE32
0.4 M ZeroCERT