Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6541 2023-12-18 09:56 tuc3.exe  

e8bb391ee1c0c060b906750b07e2ac5f


Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) PE32 PE File MZP Format DLL OS Processor Check DllRegisterServer dll PE64 wget ZIP Format Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName crashed
4.0 ZeroCERT

6542 2023-12-18 09:55 Microsoftupgradedtechnologytoe...  

27447785fd8cb3c3f48f90e09a0c15c2


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Exploit DNS crashed
3 6 3 4.6 M 33 ZeroCERT

6543 2023-12-18 09:53 updater.exe  

eba1a3fb09c1fc6b8d987d176ab9575e


Gen1 RedLine stealer NSIS Downloader Generic Malware Malicious Library UPX Malicious Packer Javascript_Blob Anti_VM PE32 PE File ftp DLL OS Processor Check PE64 MSOffice File VirusTotal Malware suspicious privilege Check memory Checks debugger Creates executable files RWX flags setting unpack itself AppData folder Ransomware
3.8 M 10 ZeroCERT

6544 2023-12-18 09:53 rise.exe  

b5d5c6670a9986cba2e170ef7ad519b6


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check DNS
1 1.6 M ZeroCERT

6545 2023-12-18 09:50 film.exe  

fe9d5f33dabac2b6601cd86f4519f5bc


PE32 PE File .NET EXE VirusTotal Malware Buffer PE PDB Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces DNS
2 2 4.8 39 ZeroCERT

6546 2023-12-18 09:48 qwe.exe  

9f497e5418aaf7b8f15b92535de3c0d9


PE32 PE File VirusTotal Malware DNS crashed
1 1.6 M 27 ZeroCERT

6547 2023-12-18 09:48 microsoftprofilehandledbycooki...  

d268713168844021d6ef5d210a9eb234


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
1 1 5 4.6 M 31 ZeroCERT

6548 2023-12-18 09:46 v2.exe  

cf8a20b11ce9cf757bfaf49bd93ac524


RedLine stealer Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX Malicious Library ScreenShot PWS AntiDebug AntiVM PE32 PE File .NET EXE OS Processor Check DLL Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications AppData folder installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 12.8 46 ZeroCERT

6549 2023-12-18 09:46 microsoftdecidedtodeleteentire...  

066232099ba8df43942395e4ebfa39a2


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Tofsee Windows Exploit DNS crashed
1 3 7 4.6 M 34 ZeroCERT

6550 2023-12-18 08:00 rise.exe  

4e4e4a779e9e0e970184db551ec00e5a


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check DNS
2 1.6 M ZeroCERT

6551 2023-12-18 07:59 wlanext.exe  

91e0e276bfd12c96de9bf398f410bfb3


Browser Login Data Stealer Generic Malware Malicious Library Malicious Packer Downloader UPX ScreenShot AntiDebug AntiVM PE32 PE File OS Processor Check Browser Info Stealer Remcos Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check human activity check Browser Email ComputerName DNS DDNS
1 4 3 10.0 M ZeroCERT

6552 2023-12-18 07:56 marcopack2.1.exe  

f525808e3a1d0040b3c60e5940f250fe


NSIS Malicious Library UPX Downloader PE32 PE File OS Processor Check AutoRuns Check memory Creates executable files unpack itself AppData folder Windows DNS DDNS
3 2 5.2 ZeroCERT

6553 2023-12-18 07:56 3535.exe  

138b15b9fcd21533b3ca0193893053cf


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 5.2 M ZeroCERT

6554 2023-12-18 07:55 updater.exe  

6f0e94c80d8b9c98ea75bff456eff5a2


Gen1 Generic Malware UPX Antivirus Malicious Library PE32 PE File ftp DLL PE64 OS Processor Check ZIP Format Cryptocurrency Miner Malware Cryptocurrency powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key CoinMiner
1 7 3 1 6.6 M ZeroCERT

6555 2023-12-18 07:54 konordbox2.1.exe  

a458d02487805c29b7e6b7ee09d1bee9


NSIS Malicious Library UPX Downloader PE32 PE File OS Processor Check Malware download AveMaria NetWireRC Malware AutoRuns MachineGuid Check memory Creates executable files ICMP traffic unpack itself AppData folder Windows RAT ComputerName DNS DDNS keylogger
2 4 5.4 M ZeroCERT