Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
6901 2023-11-29 11:21 kung.exe  

2b1319e5ae1ed2c33f766c482d2b68e2


Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware unpack itself Windows crashed
3.2 M 55 ZeroCERT

6902 2023-11-29 11:19 build.exe  

d013d961e6b71c1d844589c7efef0f36


Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware PDB unpack itself
2.0 M 30 ZeroCERT

6903 2023-11-29 00:11 .rels  

69984e911a8e36d7f6eab75bf36c6d01


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

6904 2023-11-29 00:10 .rels  

69984e911a8e36d7f6eab75bf36c6d01


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

6905 2023-11-29 00:10 [Content_Types].xml  

10720bd1e11273d47d78cc6f2d215894


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

6906 2023-11-29 00:09 [Content_Types].xml  

10720bd1e11273d47d78cc6f2d215894


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

6907 2023-11-28 14:51 보안메일.html.scr  

d0e8c1574fbd022e5723b85988c902a4


Eredel Stealer Extended NSIS Malicious Library UPX AntiDebug AntiVM PE32 PE File OS Processor Check .NET EXE PNG Format MSOffice File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces AppData folder Tofsee Windows Exploit DNS Cryptographic key crashed
9 2 1 9.6 11 ZeroCenter

6908 2023-11-28 14:17 hv.exe  

096406c4d94995f150e36fbb4f8fa05b


Admin Tool (Sysinternals etc ...) .NET framework(MSIL) Malicious Library UPX PWS AntiDebug AntiVM PE32 PE File .NET EXE PNG Format DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces AppData folder installed browsers check SectopRAT Windows Browser Backdoor ComputerName DNS Cryptographic key Software crashed
1 1 14.8 4 ZeroCERT

6909 2023-11-28 14:17 obizx.exe  

22033619d1075b112f8b58d657f536f8


Formbook .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 11.8 M 51 ZeroCERT

6910 2023-11-28 11:29 vbsss.jpg.exe  

db2ee1ea937d2e49bc3f237edde48cfb


Generic Malware Antivirus PE32 PE File DLL .NET DLL VirusTotal Malware Check memory unpack itself
1.2 14 ZeroCERT

6911 2023-11-28 11:20 hta.jpg.exe  

0f259f4cb66106371ece0128de84bfb2


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware Check memory unpack itself
1.6 38 ZeroCERT

6912 2023-11-28 10:44 server1.exe  

2390cfec047769ff220db8d9d5d5c78d


UPX Confuser .NET PE32 PE File .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself
2.2 M 35 ZeroCERT

6913 2023-11-28 10:20 hta.jpg.exe  

0f259f4cb66106371ece0128de84bfb2


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware
1.0 38 ZeroCERT

6914 2023-11-28 10:19 js.jpg.exe  

cb3540aebe2027f561ec83f5effae983


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware
1.2 42 ZeroCERT

6915 2023-11-28 10:09 3tuvq.js  

a758953be379c89a34398eb1fc1f233a


Generic Malware Antivirus ActiveXObject PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
4 5 2 9.0 8 ZeroCERT