Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6676 2023-12-11 19:55 deluxe_crypted.exe  

d7f80ac5e408c10c0f6d953a08b8db74


Malicious Library UPX PE32 PE File OS Processor Check Browser Info Stealer Malware download VirusTotal Malware Cryptocurrency wallets Cryptocurrency Malicious Traffic Check memory buffers extracted Collect installed applications suspicious TLD sandbox evasion installed browsers check Ransomware Lumma Stealer Browser ComputerName Firmware DNS
1 3 4 8.8 M 53 ZeroCERT

6677 2023-12-11 19:54 MedicinesViews.exe  

d0b882c07526d97ef91eccf153e31a4b


Suspicious_Script_Bin Hide_EXE Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug VirusTotal Malware Buffer PE suspicious privilege Code Injection Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities AppData folder malicious URLs sandbox evasion WriteConsoleW Windows ComputerName DNS
3 9.0 M 45 ZeroCERT

6678 2023-12-11 19:53 autorun.exe  

5d5ec23ea161feec9ef9e619dfe2d2d4


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check Check memory Checks debugger unpack itself Windows DNS Cryptographic key
1 2.8 M ZeroCERT

6679 2023-12-11 19:52 SoftwareMeetup.exe  

cbf9b27a8f0e0694c727f4365776b745


Raccoon Gen1 Suspicious_Script_Bin Downloader Malicious Library UPX Malicious Packer Http API ScreenShot Escalate priviledges PWS HTTP Code injection Internet API KeyLogger Create Service Socket DGA Steal credential Hijack Network Sniff Audio DNS persiste Browser Info Stealer Malware download Malware RecordBreaker Buffer PE suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications AppData folder malicious URLs sandbox evasion WriteConsoleW installed browsers check Stealer Windows Browser ComputerName DNS crashed
9 2 11 1 14.6 M 44 ZeroCERT

6680 2023-12-11 19:52 tuc5.exe  

63b2f4831b7af85aea9e507f772a8e11


Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) PE32 PE File MZP Format DLL OS Processor Check DllRegisterServer dll PE64 wget ZIP Format Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName crashed
4.2 M ZeroCERT

6681 2023-12-11 19:51 updHost.exe  

f635abf65a40a5de7cebafcc57a562da


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 M 49 ZeroCERT

6682 2023-12-11 19:51 clip64.dll  

c06513af505f65393b4ebcd2a11a2ee4


Amadey Malicious Library UPX PE32 PE File DLL OS Processor Check VirusTotal Malware Malicious Traffic Checks debugger unpack itself DNS
1 1 3.6 M 58 ZeroCERT

6683 2023-12-11 19:50 wlanext.exe  

f8dd68662d873c903364ab250ca25e7d


Generic Malware Malicious Library UPX Antivirus PE32 PE File powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key crashed
6.0 M ZeroCERT

6684 2023-12-11 19:49 setup294.exe  

3c3a0dc705cffd3f56b4315750c18e37


Malicious Library AntiDebug AntiVM PE32 PE File DLL VirusTotal Malware Code Injection Check memory Checks debugger Creates executable files unpack itself AppData folder
5.2 M 52 ZeroCERT

6685 2023-12-11 19:44 xyoriginzx.exe  

410f943c02ead92432bccafe75f3617a


PE32 PE File .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself
5.6 M 42 ZeroCERT

6686 2023-12-11 19:44 microsoftdecidedtodeleteentire...  

c0e36e7962911cb2865904a96323da33


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware buffers extracted exploit crash unpack itself Exploit DNS crashed
1 4.8 M 30 ZeroCERT

6687 2023-12-11 19:42 Cerber.exe  

c7aa2871e40be6337beaf13e1e07576a


PE32 PE File .NET EXE VirusTotal Malware Buffer PE suspicious privilege Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
3.6 M 48 ZeroCERT

6688 2023-12-11 19:42 31.exe  

c24fb9e28286976460a9f0d29f68e634


UPX PE32 PE File .NET EXE OS Processor Check VirusTotal Malware AutoRuns suspicious privilege MachineGuid Check memory Checks debugger unpack itself Windows DNS
1 5.8 M 63 ZeroCERT

6689 2023-12-11 19:40 cleaneruop.exe  

c8360d1235aa3bf925228bfe6a1c8a62


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows Cryptographic key
3.2 M 52 ZeroCERT

6690 2023-12-11 19:40 Microsoftdecidedtodeleteentire...  

2163e4abe634b604518567a27c2b57cd


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 2 1 4.6 M 36 ZeroCERT