Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
5176 2024-09-20 10:51 Desktop_Explorer.exe  

acccb5d6308487da88b2f05b2f4f6234


Generic Malware Malicious Library Malicious Packer UPX Anti_VM PE File DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware
0.8 M 11 ZeroCERT

5177 2024-09-20 10:47 66ec3528901bb_winupdate11.exe#...  

4fe072b888cd64ff01d73d8b80bfcf3e


Malicious Library .NET framework(MSIL) PE File .NET EXE MSOffice File PE32 VirusTotal Malware Buffer PE suspicious privilege Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
3.6 M 28 ZeroCERT

5178 2024-09-20 10:47 Inquiry-Dubai.js  

b54f5c7cb5ac3d69127941e40966ab0c


Generic Malware Antivirus ActiveXObject VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.8 12 ZeroCERT

5179 2024-09-20 10:47 66ebf725efe38_lyla.exe  

117cd56896073eaa680d408fe7fb51c8


Generic Malware Admin Tool (Sysinternals etc ...) UPX PE File PE32 DLL Malware download VirusTotal Malware Malicious Traffic AppData folder suspicious TLD CryptBot DNS
1 2 3 3.6 M 52 ZeroCERT

5180 2024-09-20 10:46 ldfnsa.exe  

731a25a9b1f2c31056f7bd75c71deac4


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows
8.0 M 44 ZeroCERT

5181 2024-09-20 10:45 AntonioIssn.exe  

6e75f9fb3b72d60fd52dbdfff338f33f


Generic Malware Suspicious_Script_Bin Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
6.6 M 26 ZeroCERT

5182 2024-09-20 10:44 in.ps1  

04441f657f719cbac9be106030c5af9c


Generic Malware Antivirus unpack itself WriteConsoleW Windows Cryptographic key
1 0.8 ZeroCERT

5183 2024-09-20 10:43 shhds.exe  

3c01f02d55374baace8ac5b33fe49f0e


Stealc Client SW User Data Stealer ftp Client info stealer Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 2 14.0 M 49 ZeroCERT

5184 2024-09-20 10:42 66ec71a8dd7f7_setup33.exe#lyla  

56e3db9291d886a337ba3d4a12828bca


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.0 M 31 ZeroCERT

5185 2024-09-20 10:39 66ec34ea3a1b3_app3454636138226...  

826eb90d730bf03e39d78daa585364bc


RedLine stealer RedLine Infostealer Generic Malware UltraVNC Malicious Library UPX Antivirus ScreenShot PWS AntiDebug AntiVM PE File PE32 OS Processor Check .NET EXE Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName RCE DNS Cryptographic key Software crashed
2 6 15.0 46 ZeroCERT

5186 2024-09-20 10:39 vfdshf.exe  

6d1999f1096cee3f06507e0d896d7c4a


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 47 ZeroCERT

5187 2024-09-20 10:37 vejsfs16.exe  

6a94e9f1450b205023e275c69b8688dc


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 16.4 M 45 ZeroCERT

5188 2024-09-20 10:37 66ebe621bc80b_ffile.exe#xin  

9dfbc6519520d53606f41e8532747b42


RedLine stealer Malicious Library UPX PWS AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself RCE DNS
1 9.2 ZeroCERT

5189 2024-09-20 10:37 PO-LIST.exe  

e21b8ab721253a904d148587bb256be4


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check Remcos VirusTotal Malware AutoRuns Malicious Traffic Check memory Checks debugger Creates executable files unpack itself AppData folder Windows DNS DDNS keylogger
1 4 2 7.4 46 ZeroCERT

5190 2024-09-20 10:36 66ec0e61998bf_setup30.exe  

6171efb98ce36e0d0f9e6a416c15afb8


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.0 M 37 ZeroCERT