Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6196 2024-01-22 14:59 index.php  

cfb1c1dc1927543d3ba7d2776a425e57


Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware unpack itself
1.6 M 29 ZeroCERT

6197 2024-01-22 14:55 wefhrf.exe  

2ca4bd5f5fece4e6def53720f2a7a9bb


Generic Malware Antivirus PE32 PE File .NET EXE VirusTotal Malware PDB suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Disables Windows Security suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 7.0 M 51 ZeroCERT

6198 2024-01-22 14:53 Eszop.exe  

9379b6e19fb3154d809f8ad97ff03699


PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself
3.0 M 52 ZeroCERT

6199 2024-01-22 14:53 payment_Receipt.jar  

519c10d7ec21b5ed36b6a6a6da1a33f8


Generic Malware Antivirus Malicious Library UPX ZIP Format PowerShell PE32 PE File DLL OS Processor Check JPEG Format Browser Info Stealer Malware download NetWireRC VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger buffers extracted WMI heapspray Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW IP Check Windows Java Browser Email ComputerName DNS Cryptographic key crashed
1 9 3 11.4 M 23 ZeroCERT

6200 2024-01-22 12:45 RisePro_1.4_oCtFry7ogY0hng063r...  

1c8918482b9cd613ba75ab7a16463e18


Generic Malware Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check ZIP Format PNG Format Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency AutoRuns MachineGuid Check memory buffers extracted Windows utilities Disables Windows Security Collect installed applications suspicious process AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser RisePro Email ComputerName DNS Software crashed
1 5 7 13.2 M 14 ZeroCERT

6201 2024-01-22 12:42 client.exe  

25b6389bbaa746df85d53714d4a6d477


Malicious Library Malicious Packer Antivirus .NET framework(MSIL) UPX PE32 PE File .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 52 ZeroCERT

6202 2024-01-22 12:40 nika.exe  

add34134b9398dd5429301d0d5646be6


PE32 PE File .NET EXE PDB suspicious privilege Check memory Checks debugger unpack itself Disables Windows Security Windows Update
3.6 M ZeroCERT

6203 2024-01-22 12:39 build.exe  

57935225dcb95b6ed9894d5d5e8b46a8


RedlineStealer RedLine Infostealer RedLine stealer .NET framework(MSIL) UPX Malicious Library Malicious Packer Antivirus PE32 PE File .NET EXE OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
3 3 9 9.2 62 ZeroCERT

6204 2024-01-22 12:38 defgrabber.exe  

ced2b6106c76edfe1ce2aedacbdba99b


Emotet Gen1 Generic Malware Malicious Library ASPack UPX Malicious Packer Admin Tool (Sysinternals etc ...) Anti_VM PE File PE64 OS Processor Check DLL DllRegisterServer dll ZIP Format VirusTotal Malware Check memory Creates executable files Ransomware crashed
2.6 37 ZeroCERT

6205 2024-01-22 12:35 Aixnslkoum.exe  

1c38258e33ab23bead674c34db28e23d


Hide_EXE PE File PE64 VirusTotal Malware Check memory Checks debugger unpack itself
2.4 44 ZeroCERT

6206 2024-01-22 12:35 rty27.exe  

90ab18d69c8c28f797acf90b61d656df


Malicious Packer UPX PE File PE64 PDB MachineGuid unpack itself Check virtual network interfaces Tofsee Remote Code Execution
1 3 1 1.8 ZeroCERT

6207 2024-01-22 12:32 rty45.exe  

c5431ed88227d6f2e201da982db63f38


Malicious Packer UPX PE File PE64 VirusTotal Malware PDB MachineGuid unpack itself Check virtual network interfaces Tofsee Remote Code Execution
1 3 1 3.0 46 ZeroCERT

6208 2024-01-22 12:32 890f46f4-23a3-4020-bf35-0d1f89...  

ba700214afe24b7926ec8b4d0fa64cb9


Emotet Suspicious_Script_Bin Downloader Malicious Library UPX Malicious Packer .NET framework(MSIL) Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP Ke VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
6.4 10 ZeroCERT

6209 2024-01-22 12:29 networ.exe  

f573785b121c6dbca1b536cfc58c4279


Malicious Library UPX PE32 PE File OS Processor Check Checks debugger
0.2 ZeroCERT

6210 2024-01-22 12:27 Zzbifmr.exe  

14f7c4b98e2c837e555d030bfbe740c4


.NET framework(MSIL) PE32 PE File .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.4 M 37 ZeroCERT