Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6061 2024-09-04 10:17 payload.exe  

ca6ae34bf2b35aacb25a27f94fb1f7d5


Metasploit Generic Malware PE File PE64 VirusTotal Malware DNS crashed
1 3.6 M 62 ZeroCERT

6062 2024-09-04 10:17 66d707705967b_12.exe#d12  

d72251694d71a89fab057f9976ec1827


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications malicious URLs sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
8 1 10 1 15.8 M 43 ZeroCERT

6063 2024-09-04 10:16 tqh64.exe  

2d8bfa12ffd53e578028edae844e7611


UPX PE File PE32 VirusTotal Malware
1.2 M 57 ZeroCERT

6064 2024-09-04 10:15 66d6af212bad3_kbdturme.exe  

b2ceff540f1fb7234b424a5702e989ba


Gen1 Generic Malware NSIS Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer UPX Javascript_Blob AntiDebug AntiVM PE File PE32 MZP Format OS Processor Check DLL PE64 PNG Format DllRegisterServer dll VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder Windows ComputerName crashed
7.0 M 6 ZeroCERT

6065 2024-09-04 10:14 66d5e39de168d_cry.exe#kiscrypt...  

c4863f9cb3f845ccd4ebd260d532928e


Client SW User Data Stealer ftp Client info stealer Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 16 12.4 M 47 ZeroCERT

6066 2024-09-04 10:11 rev.exe  

c457b64b8faf93fb23adb3d3b6a6cb78


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware crashed
1.6 M 63 ZeroCERT

6067 2024-09-04 10:09 1_encoded.exe  

6c098287139a5808d04237dd4cdaec3f


PE File PE64 VirusTotal Malware crashed
1.6 M 62 ZeroCERT

6068 2024-09-04 10:09 chrome.exe  

67407557dfbdd3d71436f89d6d47897a


Malicious Packer UPX PE File PE64 VirusTotal Malware buffers extracted RWX flags setting DNS
1 4.6 M 55 ZeroCERT

6069 2024-09-04 10:08 lamp.exe  

54dd56c2c79350de18dc0be27360520d


Stealc Gen1 Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare sandbox evasion VMware anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
9 1 16 2 12.4 M 36 ZeroCERT

6070 2024-09-04 10:07 66d58b1858bcb_crypted.exe#xin  

d8ecb462d3046a0ee172551c5d505c8e


RedLine stealer Antivirus PWS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself DNS
1 9.0 M 56 ZeroCERT

6071 2024-09-04 10:03 66d707730e9bf_s.exe#space  

998f7fb6068e4377618bcdb2138bc6f0


Stealc Client SW User Data Stealer LokiBot Gen1 ftp Client info stealer Generic Malware Downloader Antivirus Malicious Library UPX Malicious Packer Http API PWS Create Service Socket DGA ScreenShot Escalate priviledges Steal credential Sniff Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software plugin
19 3 19 3 16.6 M 44 ZeroCERT

6072 2024-09-04 09:40 2.exe  

727d942e4c26b713b9498e8997fabf38


Malicious Packer UPX PE File PE64 VirusTotal Malware RWX flags setting DNS crashed
1 3.8 M 55 ZeroCERT

6073 2024-09-04 09:40 1388.exe  

7109c985bd8a553012ea843d05737794


Malicious Library PE File PE64 VirusTotal Malware RWX flags setting unpack itself ComputerName DNS
1 5.2 M 65 ZeroCERT

6074 2024-09-04 09:35 66d7540419a3a_installer.exe  

9a0770b61e54640630a3c8542c5bc7ac


Malicious Library UPX PE File PE64 VirusTotal Malware Checks debugger Creates executable files unpack itself crashed
2.2 M 12 ZeroCERT

6075 2024-09-03 12:00 WORDICON.EXE  

068918a65830b7e7671056f125412757


ASPack UPX PE File DLL PE64
guest