Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7156 2021-04-12 10:59 kch.com  

712696c784185d9eaa3c7dccf54a5f68


Antivirus Gen1 VirusTotal Malware powershell AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities Auto service Check virtual network interfaces suspicious process AppData folder sandbox evasion WriteConsoleW Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key crashed Downloader
3 10.0 M 36 ZeroCERT

7157 2021-04-12 11:01 zabax.exe  

ee0290febc47fec50c639fa4eb13d594


Azorult .NET framework AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key
1 8.4 M 47 ZeroCERT

7158 2021-04-12 11:02 win.com  

73e9a221cc6f41c56c6664e9d0ca0ced


Antivirus Gen1 VirusTotal Malware PDB Creates executable files unpack itself
1.8 M 19 ZeroCERT

7159 2021-04-12 11:03 .................................  

5608fd8f35d6ba85c260b794cee500ad

VirusTotal Malware Malicious Traffic exploit crash unpack itself Exploit DNS crashed
2 4.2 M 32 ZeroCERT

7160 2021-04-12 11:04 updatewin2.exe  

996ba35165bb62473d2a6743a5200d45

VirusTotal Malware unpack itself Windows Remote Code Execution
3.2 M 61 ZeroCERT

7161 2021-04-12 11:13 IE.exe  

89239d803d0a9f3cfce0cd45e9b78b61


AsyncRAT backdoor njRAT Antivirus Gen1 VirusTotal Cryptocurrency Miner Malware VBScript Cryptocurrency powershell AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI wscript.exe payload download Creates shortcut Creates executable files unpack itself Windows utilities Auto service Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key DDNS crashed Downloader Dropper
10 15 10.0 M 53 ZeroCERT

7162 2021-04-12 11:17 uko.exe  

40367f496f45ba45b8545f90065b6940

VirusTotal Malware
1.4 M 19 ZeroCERT

7163 2021-04-12 11:17 x64.com  

f0411337b3218b145f6b4ea19d67c5e2


Antivirus VirusTotal Malware AutoRuns PDB Check memory Creates executable files unpack itself Auto service Check virtual network interfaces sandbox evasion Windows Browser ComputerName Remote Code Execution Firmware DNS
2 8.0 M 32 ZeroCERT

7164 2021-04-12 14:35 filename.exe  

7b8cec428653a5a825830748cd6426a7

VirusTotal Malware unpack itself Remote Code Execution DNS
2.6 23 ZeroCERT

7165 2021-04-12 14:44 http://13.114.247.134/winhace/...  

127ae40009368fb03554057f1bf860a0


Azorult .NET framework AsyncRAT backdoor VirusTotal Malware Code Injection Malicious Traffic Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit DNS crashed
1 6.0 M 17 guest

7166 2021-04-12 14:58 uko.exe  

40367f496f45ba45b8545f90065b6940

VirusTotal Malware
1.4 M 19 guest

7167 2021-04-12 15:40 loki.exe  

a3cbeb3e732b11954572b3ee6755242c

VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS
1 14.6 M 21 ZeroCERT

7168 2021-04-12 15:42 loki%20old.exe  

3fef6985af0d52ab6701df170096b504

VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself AppData folder DNS
24 27 5.2 M 14 ZeroCERT

7169 2021-04-13 07:38 vbc.exe  

e34880f77348bec259761a86d2e12ec6


Azorult .NET framework AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key crashed
10.2 30 ZeroCERT

7170 2021-04-13 07:40 vbc.exe  

e34880f77348bec259761a86d2e12ec6


Azorult .NET framework AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows DNS Cryptographic key
1 6.0 30 ZeroCERT