Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
5416 2021-02-25 09:18 crypt_sert.exe  

bc584a3be92cfdfda79446372fffa46d


Browser Info Stealer FTP Client Info Stealer VirusTotal Cryptocurrency Miner Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare Check virtual network interfaces suspicious process AppData folder malicious URLs WriteConsoleW VMware anti-virtualization installed browsers check Tofsee Ransomware Windows Browser ComputerName Firmware DNS Cryptographic key Software crashed
10 24 3 20.2 M 51 ZeroCERT

5417 2021-02-25 09:26 fux.exe  

5b60d41bd93869e36d90775be1ae7830


VirusTotal Malware PDB MachineGuid Code Injection Malicious Traffic Checks debugger buffers extracted unpack itself malicious URLs suspicious TLD sandbox evasion Tofsee Browser Remote Code Execution DNS crashed
2 4 2 10.0 M 51 ZeroCERT

5418 2021-02-25 09:30 IMG_0352_Scanned.jpg.exe  

6a4ce9c2b60181dad5c2ae6f01a21d65


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process malicious URLs VMware IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 17.2 M 27 ZeroCERT

5419 2021-02-25 09:34 IMG_57109_Scanned.jpg.exe  

e880bfe979296c1fb516d0f90cd5fb16


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 16.0 M 26 ZeroCERT

5420 2021-02-25 12:26 ipfile.exe  

42c148811400c4e8eff02746f7a7d02b


VirusTotal Malware unpack itself
2.8 M 57 ZeroCERT

5421 2021-02-25 12:26 Install_x86.exe  

e5d9d3e54ad6de4914eb6616193422c2


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs Windows DNS Cryptographic key
1 11.6 M 55 ZeroCERT

5422 2021-02-25 13:12 klfile.exe  

9dc97eaed4e61901afc327ce9f122262


VirusTotal Malware unpack itself
2.4 M 54 ZeroCERT

5423 2021-02-25 13:15 nefile.exe  

f1db5dec529b190c6bf41cba87c68238


VirusTotal Malware unpack itself
2.4 46 ZeroCERT

5424 2021-02-25 13:15 mofile.exe  

ca35b660415defe96fe6af4eb3a45d86


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows Cryptographic key
8.2 M 50 ZeroCERT

5425 2021-02-25 13:19 safile.exe  

fb29c68fcd5e475cb99fa351c4fe2b2a


VirusTotal Malware unpack itself
2.4 M 55 ZeroCERT

5426 2021-02-25 13:20 sav.exe  

b8d5cdc69c2c1e3a9e3b3c4199afa00f


VirusTotal Malware unpack itself DNS
3.0 M 56 ZeroCERT

5427 2021-02-25 13:47 svchost.exe  

4f903d491720ed347758030fb7bd3158


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Checks Bios Detects VirtualBox suspicious process VMware anti-virtualization Windows ComputerName DNS Cryptographic key Software
9.6 M 34 ZeroCERT

5428 2021-02-25 13:48 Showpieces.exe  

a6602f490e70a0c9846906944c01b1ba


Browser Info Stealer FTP Client Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency PDB suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications Check virtual network interfaces malicious URLs installed browsers check Tofsee Ransomware Windows Browser ComputerName DNS Cryptographic key Software crashed
2 7 2 11.6 M 57 ZeroCERT

5429 2021-02-25 13:56 tolkio.php.exe  

884dab96c679194fc5140322d5ce9e9d


Dridex TrickBot VirusTotal Malware suspicious privilege Malicious Traffic Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Kovter ComputerName DNS
6 7 4 6.2 M 41 ZeroCERT

5430 2021-02-25 14:06 vbc.exe  

2201881c6cc2de12c71f906e43178ef9


VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs
1 4 8.4 M 49 ZeroCERT