Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6676 2024-08-16 18:36 Mnemonic.chm  

55c6005f361c9011182379ba8f7a875f


Gen1 Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM CHM Format PE Fil VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory Creates executable files RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Windows
5.4 42 ZeroCERT

6677 2024-08-16 18:35 님.jse  

7756b4230adfa16e18142d1dbe6934af


ROMCOM RAT Generic Malware Suspicious_Script_Bin Hide_EXE Antivirus Malicious Library UPX Anti_VM PDF AntiDebug AntiVM PowerShell ZIP Format PE File DLL PE64 DllRegisterServer dll OS Processor Check MSOffice File VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Tofsee Ransomware Interception Windows Exploit ComputerName DNS Cryptographic key crashed
1 7 1 15.8 26 ZeroCERT

6678 2024-08-16 18:31 베트남 녹지원 상춘재 행사 견적서.hwp .exe...  

35d60d2723c649c97b414b3cb701df1c


Generic Malware Malicious Library UPX HWP PE File DllRegisterServer dll MSOffice File PE32 OS Processor Check DLL VirusTotal Malware PDB Check memory Checks debugger Creates executable files unpack itself suspicious process AppData folder WriteConsoleW RCE crashed
2 3 1 5.6 55 ZeroCERT

6679 2024-08-16 18:20 Doc1.docm  

0fee354732496cdbdb4e78ecb218a81a


VBA_macro Word 2007 file format(docx) ZIP Format VirusTotal Malware unpack itself Windows utilities Windows
1 2 4.8 17 ZeroCERT

6680 2024-08-16 18:16 bb.jpg.ps1  

35cc87966b1583d624d2be67dd4c5a91


Client SW User Data Stealer browser info stealer Generic Malware Google Chrome User Data Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection BitCoin Internet API Browser Info Stealer VirusTotal Malware powershell MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files exploit crash unpack itself powershell.exe wrote malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Exploit Browser ComputerName Cryptographic key crashed
1 9.2 8 ZeroCERT

6681 2024-08-16 18:04 new_image.jpg.exe  

9bc67a353e3056bac82436a1667350ab


Malicious Library UPX PE File DLL PE32 .NET DLL OS Processor Check VirusTotal Malware PDB
1.4 43 ZeroCERT

6682 2024-08-16 17:56 ChaveBB-2024.exe  

d46fbf03a71245869dc5c89805e6d8f1


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
0.6 8 ZeroCERT

6683 2024-08-16 17:49 adob024.msi  

acd50da7436621368061abc2ca6193fe


Generic Malware Malicious Library MSOffice File CAB OS Processor Check VirusTotal Malware Buffer PE suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk VM Disk Size Check Tofsee ComputerName
15 9 1 4.8 M 12 ZeroCERT

6684 2024-08-16 17:45 atualizarchavebb.exe  

5f6ed924c5fc2a7134acad39c491e426


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
0.6 2 ZeroCERT

6685 2024-08-16 17:43 451e981f-3416-484b-ba8a-6c3aae...  

6d29f4896892c91765c447a1987a4dbf


Malicious Library Malicious Packer Antivirus .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
1.8 39 ZeroCERT

6686 2024-08-16 15:18 unrootkit.dll  

56561903fd1e9dedfe029dd8c9172e7c


Generic Malware Malicious Library Malicious Packer UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself
2.6 M 62 ZeroCERT

6687 2024-08-16 15:16 feelfreethingstogetmebackwithe...  

c1a7bf262d7bad7fc46411c0996fc50c


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 3 1 4.6 M 37 ZeroCERT

6688 2024-08-16 15:16 rootkit.dll  

d72fea64a05b3f7dce725352d7c1d032


Generic Malware Malicious Library Malicious Packer PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself
3.0 M 63 ZeroCERT

6689 2024-08-16 15:10 robotic.exe  

6b1bbe4e391cdfd775780d8502ccbc41


RedLine stealer ILProtector Packer Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check RedLine Malware download VirusTotal Malware Microsoft suspicious privilege MachineGuid Check memory Checks debugger buffers extracted unpack itself Stealer Windows ComputerName DNS Cryptographic key
1 3 4.0 M 49 ZeroCERT

6690 2024-08-15 16:39 CodeResources  

b3449813343cf03f6050a0a4d79c2ee6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest