Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6001 2024-01-31 15:52 NeonRank.exe  

372894142599e37c16b10e893cc0f0b1


Gen1 Suspicious_Script_Bin Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug Ant VirusTotal Malware Buffer PE suspicious privilege Code Injection Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Windows ComputerName DNS crashed
2 9.8 M 22 ZeroCERT

6002 2024-01-31 15:52 1234pixxxx.exe  

e2695d45520fe4058a6df4dff94b51e9


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check ZIP Format PNG Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency MachineGuid Check memory buffers extracted Collect installed applications AntiVM_Disk anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Browser RisePro Email ComputerName DNS Software crashed
1 5 6 8.8 M 52 ZeroCERT

6003 2024-01-31 15:49 microsoftupdationgoingformicro...  

ca369817b8724db3c26b5d66f052ab0a


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
1 1 5 4.6 M 33 ZeroCERT

6004 2024-01-31 15:49 seidr_build.exe  

35f2d8f41310c52cada4d183fb60f555


PhysicalDrive Malicious Library Malicious Packer Antivirus UPX Anti_VM PE File PE64 ftp OS Processor Check VirusTotal Malware PDB Check memory anti-virtualization
2.4 M 41 ZeroCERT

6005 2024-01-31 15:47 mrk1234.exe  

bf2a3e48b0ea897e1cb01f8e2d37a995


RedLine Infostealer UltraVNC Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware PDB Check memory Checks debugger unpack itself Windows Cryptographic key crashed
3.0 M 47 ZeroCERT

6006 2024-01-31 15:47 bakcrypt.exe  

b370662ce4e04c96a0b2993c3099ca2f


UPX PE File PE64 OS Processor Check VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself
2.2 M 47 ZeroCERT

6007 2024-01-31 15:46 Multa.vbs  

3f53f2077d0bad96a99aebfbeac5ed1a


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key DoTNet
2 2 2 7.0 8 ZeroCERT

6008 2024-01-31 15:44 hclupdationprocessstartedrecen...  

e589afe701c8eb046a0aa6b1ab35e9eb


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 1 1 4.6 M 33 ZeroCERT

6009 2024-01-31 15:44 IInurhametov_crypted_LAB.exe  

c53b40a7f6ae33b3e318813db209e82e


RedLine Infostealer UltraVNC Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware PDB Check memory Checks debugger unpack itself Windows Cryptographic key crashed
2.8 M 39 ZeroCERT

6010 2024-01-31 15:42 rty49.exe  

0b941f1bb25e443be09efec27f807341


Malicious Packer UPX PE File PE64 VirusTotal Malware PDB MachineGuid unpack itself Check virtual network interfaces Tofsee Remote Code Execution
2 3 1 4.0 M 43 ZeroCERT

6011 2024-01-31 15:42 RagCrypt.exe  

f3ed43acd7d035e8c6035c7d65ec60bf


.NET framework(MSIL) UPX PE32 PE File .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.2 M 52 ZeroCERT

6012 2024-01-31 10:07 bizus.exe  

cc1924e912c7c31c5c9b18c9c62e9618


Malicious Packer .NET framework(MSIL) PE32 PE File .NET EXE Check memory Checks debugger unpack itself ComputerName
1.0 M ZeroCERT

6013 2024-01-31 10:05 tuc5.exe  

341edb9d58cd37043107d39849e09aba


Emotet Gen1 Malicious Library UPX Anti_VM PE32 PE File MZP Format DllRegisterServer dll OS Processor Check PE64 DLL ftp VirusTotal Malware Checks debugger Creates executable files unpack itself AppData folder Windows ComputerName crashed
4.2 M 17 ZeroCERT

6014 2024-01-31 10:05 12029.exe  

9217000741d062534aef0209b53ade51


Generic Malware Malicious Library UPX Malicious Packer PE32 PE File OS Processor Check DLL Lnk Format GIF Format VirusTotal Malware Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder ComputerName Firmware
4.2 M 21 ZeroCERT

6015 2024-01-31 10:04 conhost.exe  

0645eb9460ec8b21c95d1638794ef18f


AgentTesla Admin Tool (Sysinternals etc ...) UPX KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName Cryptographic key Software crashed
10.4 M ZeroCERT