Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6721 2023-12-11 15:28 ma.exe  

c1ca2440bbc8d8e5928e7d28eb4d24ca


UPX PE File PE64 .NET EXE VirusTotal Malware unpack itself Windows Remote Code Execution crashed
2.8 M 25 ZeroCERT

6722 2023-12-11 15:25 Pfvtwoys.exe  

eeca722283938a812fd6670b34ec5e29


Hide_EXE .NET framework(MSIL) UPX PWS AntiDebug AntiVM PE File PE64 .NET EXE OS Processor Check VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key
8.6 M 46 ZeroCERT

6723 2023-12-11 15:24 Nnyphhamc.exe  

7f5108b2158d537f11fd88886c1c047c


Hide_EXE UPX PE File PE64 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows DNS Cryptographic key
1 5.8 M 47 ZeroCERT

6724 2023-12-11 15:23 Zocymkpxeu.exe  

b9922787936c8e2ed028b5bd652d7ee9


Create Service Socket Escalate priviledges PWS DNS persistence AntiDebug AntiVM PE File PE64 URL Format VirusTotal Malware AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself malicious URLs Windows Cryptographic key
1 7 1 12.4 M 49 ZeroCERT

6725 2023-12-11 15:23 Edbwgnrp.exe  

27b354807eeeeacddfeab9532165a5d8


Hide_EXE .NET framework(MSIL) UPX PWS AntiDebug AntiVM PE File PE64 .NET EXE OS Processor Check VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
8.0 M 48 ZeroCERT

6726 2023-12-11 14:24 release_ver9.rar  

a64249c49fd7686653154060beaa68dc


Stealc Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware download Vidar Open Directory Malware c&c suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Exploit Browser RisePro DNS Downloader plugin
15 28 36 2 5.6 M ZeroCERT

6727 2023-12-11 14:18 release_ver9.rar  

a64249c49fd7686653154060beaa68dc


Escalate priviledges PWS KeyLogger AntiDebug AntiVM suspicious privilege Check memory Checks debugger unpack itself
1.6 ZeroCERT

6728 2023-12-11 14:17 tuc5.exe  

e6a2e949c740c3e5c4763b6ab7e13d7c


Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) PE32 PE File MZP Format DLL OS Processor Check DllRegisterServer dll PE64 wget ZIP Format Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName crashed
4.0 M ZeroCERT

6729 2023-12-11 14:14 Vbewgil.exe  

752d19f58c4bcb8ced90460032b693e4


Hide_EXE .NET framework(MSIL) PE File PE64 .NET EXE MachineGuid Check memory Checks debugger unpack itself
1.4 M ZeroCERT

6730 2023-12-11 13:24 hv.exe  

59d1fa3b93c1cbbe665017060c8140aa


Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX Malicious Library PWS AntiDebug AntiVM PE32 PE File .NET EXE PNG Format DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces AppData folder installed browsers check SectopRAT Windows Browser Backdoor ComputerName DNS Cryptographic key Software crashed
1 1 15.2 9 ZeroCERT

6731 2023-12-11 11:08 pdf.exe  

e7ff90c3f9326d57e42e276d0afb4c48


UPX Malicious Library AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications AppData folder installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 3 14.6 M 50 ZeroCERT

6732 2023-12-08 18:40 microsoftdecidedtodeleteentire...  

49ad634e1dfd465013beb3ce092015de


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit DNS crashed
2 4 2 4.6 M 33 ZeroCERT

6733 2023-12-08 18:38 Microsoftdecidedtodeleteentire...  

684c997cc1b2dc1290b00576e884f425


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Tofsee Windows Exploit DNS crashed
3 7 4.2 M 36 ZeroCERT

6734 2023-12-08 18:38 index.php  

8801830b87729b1843ff56584d9f34a0


Malicious Library PE32 PE File PDB unpack itself Remote Code Execution
1.2 M ZeroCERT

6735 2023-12-08 18:36 chrome.exe  

c0af31044fcaa756f32f13007d50724f


Gen1 Generic Malware Malicious Library UPX Antivirus Malicious Packer PE32 PE File MZP Format URL Format DLL PE64 Remcos VirusTotal Malware Malicious Traffic Check memory Creates executable files unpack itself Windows utilities suspicious process WriteConsoleW Windows DNS keylogger
2 4 1 6.4 M 41 ZeroCERT