Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6451 2023-12-26 08:02 Recorder.exe  

a16c3e4711c591850a5fcc3f3ae8c4ea


Malicious Packer PE32 PE File unpack itself DNS
1 2.8 M ZeroCERT

6452 2023-12-26 07:59 Journal.exe  

9b82c2db03852974a14558c6fd9f0025


Malicious Library Malicious Packer PE32 PE File unpack itself DNS
1 3.0 M ZeroCERT

6453 2023-12-26 07:58 rundll64.exe  

f682862c3c888c7dcaf9d61aefe26675


Malicious Packer PE32 PE File unpack itself DNS
1 2.8 ZeroCERT

6454 2023-12-26 07:56 B13zx.exe  

65ece0fb49567a607d9459e992851006


Loki LokiBot Socket PWS DNS AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key Software
1 2 7 1 12.2 M ZeroCERT

6455 2023-12-26 07:54 setup294.exe  

5883c6a721eb3ba71923df4491d1a734


Malicious Library UPX AntiDebug AntiVM PE32 PE File OS Processor Check DLL PDB Code Injection Checks debugger Creates executable files unpack itself AppData folder Remote Code Execution
3.4 M ZeroCERT

6456 2023-12-26 07:54 WinScp.exe  

1cff16414073e9bee180d323736ce07f


Generic Malware .NET framework(MSIL) UPX Antivirus PE32 PE File .NET EXE Malware powershell AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 1 7.2 ZeroCERT

6457 2023-12-26 07:52 473892748329d.exe  

5c8c4357da5f3293b60e805e947e25d2


PE File PE64 crashed
0.2 M ZeroCERT

6458 2023-12-26 07:52 timeSync.exe  

e3ded33168c7758f7f04792b755ff57a


Malicious Library UPX PE32 PE File OS Processor Check PDB unpack itself
1.0 M ZeroCERT

6459 2023-12-25 23:49 IMG_7005_21603pdf.exe  

733a47d0689018b00e9017be3a92b4de


AgentTesla .NET framework(MSIL) UPX PWS SMTP KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
1 6 6 15.4 55 guest

6460 2023-12-24 16:17 DisplayDriverExt.dll  

1d509cbad17fe9bc39563956aadf5d3f


Generic Malware Malicious Library UPX PE32 PE File DLL DllRegisterServer dll OS Processor Check PDB Checks debugger unpack itself Remote Code Execution
1.0 guest

6461 2023-12-24 12:54 twty.exe  

c7207f25a68d4179e9a07969de719eda


Emotet Generic Malware Malicious Library UPX PE32 PE File PNG Format BMP Format DLL OS Processor Check Lnk Format GIF Format Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder ComputerName Firmware
3.4 M ZeroCERT

6462 2023-12-24 12:53 Testing.dot  

3dfddb91261f5565596e3f014f9c495a


VBA_macro Generic Malware MSOffice File VirusTotal Malware exploit crash unpack itself Exploit crashed
2.2 M 22 ZeroCERT

6463 2023-12-24 12:50 launcher  

c6a1ab972148e30f1da590a43b107411


PE File PE64 Remote Code Execution crashed
1.0 M ZeroCERT

6464 2023-12-24 12:48 a01.exe  

faf0d1a297e74fed509e1c473b3d2a06


Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 44 ZeroCERT

6465 2023-12-23 18:31 Rby1.exe  

e0bc2140d5a10035fb6d3b4e1b46cdfe


Emotet NSIS Generic Malware UPX Malicious Library Antivirus Admin Tool (Sysinternals etc ...) Malicious Packer Anti_VM AntiDebug AntiVM PE File PE64 PNG Format PE32 OS Processor Check BMP Format MZP Format ZIP Format JPEG Format CHM Format DLL icon C VirusTotal Malware Buffer PE AutoRuns Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Check virtual network interfaces AppData folder malicious URLs AntiVM_Disk suspicious TLD IP Check VM Disk Size Check Tofsee Ransomware Windows ComputerName Firmware DNS
17 35 12 5 16.8 M 29 ZeroCERT