Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
5146 2024-09-21 13:50 l6E.exe  

fac2188e4a28a0cf32bf4417d797b0f8


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows
9.0 M 55 ZeroCERT

5147 2024-09-21 13:49 66ecb44e7f1ca_vdfshd15.exe  

82661ca16a1713263f9a11beaf43efee


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.0 M 51 ZeroCERT

5148 2024-09-21 13:48 66ed9885d9aee_Day2.exe  

1fedf314d7c5ed06ff6833c9c8fe5441


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName RCE
2.6 12 ZeroCERT

5149 2024-09-21 09:26 vfdhfgw12.exe  

f9607a414c82ab166cf40801b17fa452


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 15.2 M 32 ZeroCERT

5150 2024-09-21 09:26 random.exe  

cb218d4896ba79bb9d4527b1a69602e0


Stealc Amadey Themida Generic Malware Code injection Anti_VM AntiDebug AntiVM PE File PE32 Malware download Amadey VirusTotal Malware c&c AutoRuns MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Checks Bios Detects VMWare malicious URLs VMware anti-virtualization installed browsers check Ransomware Stealc Windows Exploit Browser ComputerName DNS crashed
4 3 7 3 17.2 M 38 ZeroCERT

5151 2024-09-21 09:24 vfsdgdf.exe  

a463e516041f4bc84f03bc8fe2b643dd


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 15.6 M 29 ZeroCERT

5152 2024-09-21 09:21 CITROEN.msi  

b9134d2ca1cb72f262c362ba304b0d07


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) AntiDebug AntiVM MSOffice File CAB OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk VM Disk Size Check ComputerName crashed
3.8 4 ZeroCERT

5153 2024-09-21 09:18 wels.exe  

0568c4bcf6acda54e2251b1e35929608


RedLine stealer Generic Malware Malicious Library UPX Code injection Anti_VM AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Ransomware Exploit Browser crashed
9.2 51 ZeroCERT

5154 2024-09-21 09:18 random.exe  

d23aac5d0b47654754a6e6d79085c871


Generic Malware Malicious Library UPX Code injection AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Ransomware Exploit Browser crashed
8.8 23 ZeroCERT

5155 2024-09-21 09:16 random.exe  

a5b724154ef3434013666c4f5ab0ac17


Stealc Themida Anti_VM PE File PE32 Malware download VirusTotal Malware c&c Malicious Traffic Check memory Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Stealc Windows ComputerName DNS crashed
2 1 1 2 7.6 M 57 ZeroCERT

5156 2024-09-21 09:13 random.exe  

6daa440752eea065bbfd1f6c1cd37ed0


Stealc Gen1 Themida Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar Email Client Info Stealer Malware c&c Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare sandbox evasion VMware anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 1 15 2 11.4 M ZeroCERT

5157 2024-09-21 09:11 MPA.exe  

9e73edecc13d48a931257849c4036190


RedLine stealer Malicious Library PE File .NET EXE PE32 VirusTotal Malware MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 3.8 M 40 ZeroCERT

5158 2024-09-21 09:09 vdshgdf16.exe  

7c8c40571618f1dedabedb3c3db944ec


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 15.6 M 29 ZeroCERT

5159 2024-09-21 09:09 vsfdhgg15.exe  

92c66c140509b75bae23f055d427afb4


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 14.8 M 30 ZeroCERT

5160 2024-09-21 02:11 l6E.exe  

fac2188e4a28a0cf32bf4417d797b0f8


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows
8.0 53 guest