Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6121 2024-09-02 10:44 c64.exe  

d94524a8793610d5291f4748981e9916


Emotet Generic Malware Suspicious_Script_Bin Suspicious_Script Malicious Library ASPack UPX Downloader VMProtect Malicious Packer PE File DllRegisterServer dll PE32 OS Processor Check PNG Format DLL PE64 ZIP Format MZP Format BMP Format icon ftp MSOffice VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger Creates executable files ICMP traffic unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Ransomware Windows ComputerName RCE
12.2 M 58 ZeroCERT

6122 2024-09-02 10:38 66d1eb58f2491_stealc_cry.exe#k...  

a2d6bc4c76921e184d0a81e79c40ede1


Stealc Client SW User Data Stealer ftp Client info stealer Malicious Library Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Malware download FTP Client Info Stealer VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Collect installed applications suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS Software plugin
3 1 8 2 13.6 M 23 ZeroCERT

6123 2024-09-02 10:36 66d17d49c93d8_main.exe  

01a3155b62c88c17d864f9fd78745902


Malicious Library Malicious Packer UPX Anti_VM PE File PE64 OS Processor Check VirusTotal Malware
1.6 M 35 ZeroCERT

6124 2024-09-02 10:34 66d1b7f7f3765_Front.exe  

ef210f3d8e05ecafd8d41a98b5806218


Generic Malware Malicious Library Malicious Packer UPX PE File DllRegisterServer dll PE32 OS Processor Check VirusTotal Malware
1.6 M 34 ZeroCERT

6125 2024-09-02 10:31 US+ONLY1.exe  

eafad63994d7226e68bb54d7a9396e91


Malicious Library .NET framework(MSIL) PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee Windows Cryptographic key
2 1 3.2 M 56 ZeroCERT

6126 2024-09-02 10:30 66d1b41544279_build.exe  

084e0e9053875ee1c7eb25799b4f2a55


Malicious Library UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
2.2 M 23 ZeroCERT

6127 2024-09-02 10:29 madamwebwin7fileMPDW-constrain...  

e4d40675c1dce3dd82443d9e0975d399


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 M 4 ZeroCERT

6128 2024-09-02 10:28 66d1e3c3c7dc6_vregs.exe#space  

744dad327f45b0839b0150d45e6b1f9f


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Malicious Library Antivirus Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications malicious URLs sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
8 1 10 1 17.0 M 45 ZeroCERT

6129 2024-09-02 10:28 masrshal.exe  

a5a3902eda13fdecf1320b900d2e5395


PE File .NET EXE PE32 Malware download VirusTotal Malware Buffer PE AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows ComputerName DNS Cryptographic key crashed
1 1 4 7.6 M 54 ZeroCERT

6130 2024-09-02 10:24 66d1ee505e71e_Build.exe  

a7b783146953de955a829962edd77767


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 53 ZeroCERT

6131 2024-09-02 10:24 66cef067bb8bb_CoinAccording.ex...  

6cd2eb2553ba19d387c45537a16547f4


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS
1 7.2 M 17 ZeroCERT

6132 2024-09-02 10:23 66d1e3d63bd13_sbgdwf.exe#space  

bde7cb83c1fa62b052a3b255a79dfc1e


Stealc Client SW User Data Stealer ftp Client info stealer Malicious Library Antivirus Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer Malware download Vidar VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 2 12.0 M 24 ZeroCERT

6133 2024-09-02 10:22 jhg.exe  

b21e324a39b4279504b10fee217239d3


Browser Login Data Stealer Generic Malware Malicious Library Downloader Malicious Packer UPX PE File PE32 OS Processor Check VirusTotal Malware AutoRuns Windows DNS
1 4.6 M 61 ZeroCERT

6134 2024-09-02 10:21 MeMpEng.exe  

2de33a20655435a626ae19973654e95c


Formbook Generic Malware Malicious Library UPX PE File PE32 OS Processor Check DLL Browser Info Stealer VirusTotal Malware Checks debugger buffers extracted Creates executable files unpack itself AppData folder suspicious TLD Java Browser DNS
19 21 6 16 7.6 M 48 ZeroCERT

6135 2024-09-02 10:20 %E6%94%BE%E5%81%87%E5%80%BC%E7...  

07898838cbb961a9c4a61b180b6b48da


CoinMiner Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE64 OS Processor Check MSOffice File PNG Format VirusTotal Malware suspicious privilege Code Injection Check memory buffers extracted RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces suspicious process Windows Exploit ComputerName RCE DNS crashed
1 8.2 M 18 ZeroCERT