Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6166 2024-08-27 13:30 66cccdaf426d9_vnewe12.exe#d12  

659418612b1d12a71813f316fa0661e8


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 32 ZeroCERT

6167 2024-08-27 13:27 66ccae17b8329_ip360_dozen1_uns...  

e66d3c8d8751bbddf797b0f29cd82d07


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer UPX PE File PE32 MZP Format OS Processor Check PE64 VirusTotal Malware Check memory Checks debugger unpack itself AppData folder installed browsers check Tofsee Browser crashed
2 2 1 3.8 M 3 ZeroCERT

6168 2024-08-27 13:26 random.exe  

cd777558787347c317809674583f3c89


Amadey Stealc Gen1 Generic Malware Themida Packer Malicious Library UPX Malicious Packer AntiDebug AntiVM PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Amadey FTP Client Info Stealer Vidar VirusTotal Email Client Info Stealer Malware c&c AutoRuns MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Checks Bios Collect installed applications Detects VMWare suspicious process AppData folder AntiVM_Disk sandbox evasion VMware anti-virtualization VM Disk Size Check installed browsers check Stealc Stealer Windows Browser Email ComputerName DNS Software crashed plugin
10 3 20 3 17.8 M 42 ZeroCERT

6169 2024-08-27 13:25 crss.exe  

3ab61ee8a81099edddf87af587420a10


Malicious Library Antivirus UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself AntiVM_Disk VM Disk Size Check Windows ComputerName DNS Cryptographic key
1 1 4.6 M 63 ZeroCERT

6170 2024-08-27 13:25 66cd1d4315e2e_vokfw.exe#space  

2f6adedcacebcc4c1e68c75119e5d371


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 14.2 M 23 ZeroCERT

6171 2024-08-27 13:23 66cccdb20c31e_vewf.exe#space  

eef25382ccfa4a108cad7e43bc4b43ea


Stealc Client SW User Data Stealer LokiBot ftp Client info stealer Antivirus Malicious Library Http API PWS HTTP Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 FTP Client Info Stealer VirusTotal Malware Telegram PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities Collect installed applications suspicious process malicious URLs sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
1 5 3 1 15.4 M 30 ZeroCERT

6172 2024-08-27 13:14 5GInside终端生态认证合作申请表.lnk...  

511f1e0b4274bf0c1cf6d9e756b5002c


Generic Malware Socket DNS AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware Code Injection Check memory Creates shortcut WriteConsoleW
2.2 1 ZeroCERT

6173 2024-08-27 05:22 F-Secure-Safe-Network-Installe...  

9c15aac2f31dd9e1e8d64cf8f04ea5d6


Gen1 UPX PE File PE64 OS Processor Check VirusTotal Malware Tofsee RCE
4 1 1.2 11 guest

6174 2024-08-27 02:30 CPPFPS.exe  

80eeef64813e08184cc1102e86e690a2


Generic Malware Malicious Library UPX PE File PE64 OS Processor Check PDB Check memory crashed
1.2 guest

6175 2024-08-26 16:43 svchost.exe  

733996860531962f4c9998a1fbaa5ce4


Malicious Library PE File PE32 unpack itself ComputerName
1.4 guest

6176 2024-08-26 10:58 equitosnewwwMPDW-constraints.v...  

4ae7385704b5628d2281adfcdf6e0aa6


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 M 2 ZeroCERT

6177 2024-08-26 10:55 equitoxxMPDW-constraints.vbs  

9be5974d1b599b086815ef813ef176f0


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 M 2 ZeroCERT

6178 2024-08-26 10:53 66bdb58f78c9f_Vidar.exe  

a154607fdb9dc1990f91e19b7a983b5e


Generic Malware Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself
6.6 M 36 ZeroCERT

6179 2024-08-26 10:53 madamwebbbcMPDW-constraints.vb...  

45094c2c15fadb6d8f8dc8b01215f8db


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 M 6 ZeroCERT

6180 2024-08-26 10:52 66bf3574eb3f2_FocusesAttempted...  

635508b01c2a8f9ceb1ab024c149b020


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder sandbox evasion WriteConsoleW Windows ComputerName
5.8 M 13 ZeroCERT