Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7051 2021-04-08 09:33 ya.exe  

68e2ff114060c1bfc6d2398b860e70b0


Malicious Library Browser Info Stealer VirusTotal Malware Buffer PE AutoRuns Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs AntiVM_Disk suspicious TLD WriteConsoleW VM Disk Size Check Windows Browser ComputerName DNS crashed
2 3 13.4 14 ZeroCERT

7052 2021-04-08 09:33 cv76.exe  

c41188e4415567a1465712a6c85331a6

VirusTotal Malware Code Injection Check memory Creates executable files ICMP traffic unpack itself Windows utilities sandbox evasion Windows ComputerName DNS
1 6.8 M 18 ZeroCERT

7053 2021-04-08 09:36 lv.exe  

eee8b6b36e877d7294ca94dc10d7f53a


Malicious Library Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
1 6.4 M ZeroCERT

7054 2021-04-08 09:38 sd3672.exe  

3478322eeb8ae0134a8bbea54b6e1c7c

VirusTotal Malware Check memory Creates shortcut Creates executable files unpack itself Windows utilities AppData folder AntiVM_Disk sandbox evasion VM Disk Size Check installed browsers check Windows Browser ComputerName
1 2 6.0 M 24 ZeroCERT

7055 2021-04-08 09:39 tett.exe  

2939f396d5b175b2e1f28b05c09e812b

VirusTotal Malware PDB suspicious privilege MachineGuid Code Injection Malicious Traffic buffers extracted RWX flags setting unpack itself Check virtual network interfaces suspicious process IP Check ComputerName DNS crashed
16 19 11.2 M 20 ZeroCERT

7056 2021-04-08 09:40 fter.exe  

cfb0292715c8260295e34dfd0080879b


Emotet VirusTotal Malware Code Injection buffers extracted RWX flags setting unpack itself AntiVM_Disk VM Disk Size Check crashed
5.4 M 12 ZeroCERT

7057 2021-04-08 09:42 rtr3.exe  

a062400119a4a2b81e8465cd91c145d7

VirusTotal Malware
1.2 M 12 ZeroCERT

7058 2021-04-08 09:50 ooo.exe  

9a0848614ef4a9cccffd1ec54c35d04d


Azorult .NET framework Emotet Gen1 Gen2 AsyncRAT backdoor Browser Info Stealer VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder installed browsers check Windows Browser ComputerName DNS crashed
12.0 M 58 ZeroCERT

7059 2021-04-08 11:15 install.exe  

433f8ca64803e4678febbca7902909bb

VirusTotal Malware MachineGuid Check memory Checks debugger Creates executable files unpack itself AppData folder ComputerName crashed
3.6 51 ZeroCERT

7060 2021-04-08 11:39 ooo.exe  

9a0848614ef4a9cccffd1ec54c35d04d


Azorult .NET framework Emotet Gen1 Gen2 AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder installed browsers check Windows Browser Email ComputerName Cryptographic key Software crashed
12.8 M 58 ZeroCERT

7061 2021-04-08 12:20 Practical3.ex_  

8819d7f8069d35e71902025d801b44dd


Antivirus VirusTotal Malware PDB suspicious privilege Check memory WMI Windows utilities WriteConsoleW Windows ComputerName
5.0 50 guest

7062 2021-04-08 13:20 clip-per.exe  

90639ca4a2ccbc468b4b00d0fbce51e4


Azorult .NET framework AsyncRAT backdoor Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName DNS
9.6 ZeroCERT

7063 2021-04-08 13:29 코로나바이러스 대응.doc  

a9dac36efd7c99dc5ef8e1bf24c2d747

Vulnerability VirusTotal Malware Check memory unpack itself suspicious process Interception
2 7.0 M 40 ZeroCERT

7064 2021-04-08 17:24 vbc.exe  

fe05aad3216165a28d139640ae3fcb40

VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself AppData folder
28 28 4.4 6 ZeroCERT

7065 2021-04-08 18:08 origg.exe  

01158bfc4ce6cb2c5a3cdbf661f13f8b


Azorult .NET framework VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
10.6 M 21 ZeroCERT