Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6016 2024-01-31 10:02 tuc6.exe  

da1e2ce1604d43e048144d51a9395962


Emotet Gen1 Malicious Library UPX Anti_VM PE32 PE File MZP Format OS Processor Check DllRegisterServer dll PE64 DLL ftp VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself AppData folder Windows ComputerName crashed
3.8 14 ZeroCERT

6017 2024-01-31 10:00 dwarga.exe  

88a277bbba1ac0ed88ce7e8df73614ea


Malicious Library VMProtect PE32 PE File VirusTotal Malware unpack itself crashed
2.4 M 28 ZeroCERT

6018 2024-01-31 10:00 288c47bbc1871b439df19ff4df68f0...  

2ab09b6ebda5c4fde187a8a91ac25f64


NPKI HermeticWiper Generic Malware Suspicious_Script NSIS Malicious Library UPX Antivirus Admin Tool (Sysinternals etc ...) Malicious Packer Anti_VM Javascript_Blob PE32 PE File .NET EXE PNG Format JPEG Format OS Processor Check ZIP Format MZP Format ic VirusTotal Malware AutoRuns Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Ransomware Windows ComputerName DNS crashed
2 3 4 2 12.8 M 48 ZeroCERT

6019 2024-01-31 09:58 MONTHRDX.exe  

9aa8737202bac7dcc71ef4c77939f82b


RedlineStealer RedLine stealer .NET framework(MSIL) UPX PE32 PE File .NET EXE OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 7.8 M 48 ZeroCERT

6020 2024-01-31 09:58 Ogovckrrq.exe  

e320a03e4df01230ddd097fa1b0642e2


Generic Malware Antivirus PE32 PE File .NET EXE VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key DDNS
2 2 6.8 M 46 ZeroCERT

6021 2024-01-31 09:56 goldprimesupp.exe  

e192ed56e9f5156b30ac5b5764f1eea1


PE32 PE File .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.4 M 39 ZeroCERT

6022 2024-01-31 09:56 rockrunn.exe  

df35f19c7d7e1539ca17e4d839b20a04


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check VirusTotal Malware AutoRuns unpack itself AppData folder Windows
2.4 M 36 ZeroCERT

6023 2024-01-31 09:53 Apple.exe  

82659385a3faa68194726148a3654109


Malicious Library UPX PE File PE64 OS Processor Check VirusTotal Malware crashed
0.8 M 7 ZeroCERT

6024 2024-01-31 09:51 Cwjgfe.exe  

96f646a4b18898abc40f56ecfa685aaa


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 M 44 ZeroCERT

6025 2024-01-31 09:51 obizx.exe  

da7f9653755cb1f6bc22984cfc3a37d0


.NET framework(MSIL) PE32 PE File .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.2 M 25 ZeroCERT

6026 2024-01-30 16:22 Booking.hta  

fc44bc846156354fa99f4f483a360bd0


Generic Malware Antivirus AntiDebug AntiVM PowerShell MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Tofsee Windows Exploit ComputerName DNS Cryptographic key crashed
2 9.4 22 guest

6027 2024-01-30 09:39 uwp4246971.png.exe  

0a0576ad29a833a32e09e018df0cb445


Generic Malware Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware Remote Code Execution
0.6 4 ZeroCERT

6028 2024-01-30 09:39 microsoftupdationgoingformicro...  

cf0eac9717475dc8279979d5297d43aa


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
1 1 5 4.6 M 33 ZeroCERT

6029 2024-01-30 09:33 NService_youngji057.chm  

717d7c2ee8e97b512cbcecde3aa300c3


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM CHM Format VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory RWX flags setting unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows ComputerName
1 5.2 24 ZeroCERT

6030 2024-01-30 09:26 Decrd.js  

6468ec2c43b826c943bbb0c79e219d77


Qakbot Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut RWX flags setting unpack itself Check virtual network interfaces suspicious process WriteConsoleW Interception Windows ComputerName DNS Cryptographic key
4 3 3 10.8 M 22 ZeroCERT