Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
5161 2024-09-21 09:18 wels.exe  

0568c4bcf6acda54e2251b1e35929608


RedLine stealer Generic Malware Malicious Library UPX Code injection Anti_VM AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Ransomware Exploit Browser crashed
9.2 51 ZeroCERT

5162 2024-09-21 09:18 random.exe  

d23aac5d0b47654754a6e6d79085c871


Generic Malware Malicious Library UPX Code injection AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware MachineGuid Code Injection Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself malicious URLs installed browsers check Ransomware Exploit Browser crashed
8.8 23 ZeroCERT

5163 2024-09-21 09:16 random.exe  

a5b724154ef3434013666c4f5ab0ac17


Stealc Themida Anti_VM PE File PE32 Malware download VirusTotal Malware c&c Malicious Traffic Check memory Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Stealc Windows ComputerName DNS crashed
2 1 1 2 7.6 M 57 ZeroCERT

5164 2024-09-21 09:13 random.exe  

6daa440752eea065bbfd1f6c1cd37ed0


Stealc Gen1 Themida Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar Email Client Info Stealer Malware c&c Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare sandbox evasion VMware anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 1 15 2 11.4 M ZeroCERT

5165 2024-09-21 09:11 MPA.exe  

9e73edecc13d48a931257849c4036190


RedLine stealer Malicious Library PE File .NET EXE PE32 VirusTotal Malware MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 3.8 M 40 ZeroCERT

5166 2024-09-21 09:09 vdshgdf16.exe  

7c8c40571618f1dedabedb3c3db944ec


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 15.6 M 29 ZeroCERT

5167 2024-09-21 09:09 vsfdhgg15.exe  

92c66c140509b75bae23f055d427afb4


Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 14.8 M 30 ZeroCERT

5168 2024-09-21 02:11 l6E.exe  

fac2188e4a28a0cf32bf4417d797b0f8


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows
8.0 53 guest

5169 2024-09-20 13:24 setup.exe  

6fde335dc08a9c976dcad8647e5ecb47


Emotet Gen1 Generic Malware Malicious Library UPX PE File PE32 MZP Format OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself AppData folder crashed
2.6 1 guest

5170 2024-09-20 11:02 3uTools.exe  

3d2cb4c07b03ebffec42584ba3bc788f


Generic Malware Malicious Library Malicious Packer UPX PE File DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware
1.6 M 32 ZeroCERT

5171 2024-09-20 11:00 66ecb4573225b_vsbhfdg16.exe  

0c4b826cab211945649ac4bbb0c48c6b


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.8 M 30 ZeroCERT

5172 2024-09-20 10:58 66ecb452ba19c_sfbdsgfd.exe  

242293154c0caabd9953b0b1804926a7


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer Http API PWS HTTP Code injection Internet API Create Service Socket DGA ScreenShot Escalate p Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
11 7 21 3 17.8 M 29 ZeroCERT

5173 2024-09-20 10:57 66ecb44c35444_vfdhsgdf.exe  

4a8a0ccfecc930091116324c79c1006e


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.8 M 30 ZeroCERT

5174 2024-09-20 10:53 66ec0e61998bf_setup30.exe  

6171efb98ce36e0d0f9e6a416c15afb8


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.0 M 37 ZeroCERT

5175 2024-09-20 10:51 66ebf725efe38_lyla.exe  

117cd56896073eaa680d408fe7fb51c8


Generic Malware Admin Tool (Sysinternals etc ...) UPX PE File PE32 DLL Malware download VirusTotal Malware Malicious Traffic AppData folder CryptBot DNS
1 2 3 3.2 M 52 ZeroCERT