Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7231 2023-11-07 07:42 My2.exe  

9873907d252dcecd6baea9a11ac4b0da


PE File PE64 Cryptocurrency Miner DNS CoinMiner
2 1 0.4 M ZeroCERT

7232 2023-11-07 07:42 Ads.exe  

5462d8767b051ba3fc66f78d9ded9f41


PE File PE32 .NET EXE Check memory Checks debugger unpack itself ComputerName
1.4 M ZeroCERT

7233 2023-11-06 18:26 nord.exe  

b3e87b107b029e8c0ab14b095119b263


AsyncRAT Malicious Library UPX Malicious Packer .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check DNS
1 2.2 M ZeroCERT

7234 2023-11-06 14:17 whesilozx.exe  

a117d7af8f85cacb310671b834482605


AgentTesla .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
3 2 11.4 r0d

7235 2023-11-06 14:10 defounderzx.exe  

2ed10c1ecb18c82e28180b08eb96fbc2


AgentTesla .NET framework(MSIL) PWS KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer Email Client Info Stealer Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Discord Browser Email ComputerName DNS crashed keylogger
2 3 3 1 11.4 r0d

7236 2023-11-06 14:07 MKiJjiii77.exe  

5aefabd29d2955e7c86c5c6a24f2502b


AgentTesla Confuser .NET PWS SMTP KeyLogger AntiDebug AntiVM PE File PE64 Browser Info Stealer Malware download FTP Client Info Stealer Email Client Info Stealer Malware AgentTesla suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName Software crashed keylogger
2 2 9.6 r0d

7237 2023-11-06 10:55 clips.exe  

c6ae3bd0ab0e78257468cdab2b867707


Themida Packer Downloader UPX VMProtect Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 AutoRuns Code Injection Check memory Creates executable files unpack itself Windows utilities Checks Bios Detects VirtualBox Detects VMWare suspicious process WriteConsoleW VMware anti-virtualization Windows ComputerName Firmware crashed
9.6 ZeroCERT

7238 2023-11-06 10:53 mnr.exe  

6584c57539dd7f05013ecd3806683fb4


UPX Malicious Packer PE File PE64 OS Processor Check suspicious privilege MachineGuid Check memory Checks debugger unpack itself anti-virtualization ComputerName
3.8 ZeroCERT

7239 2023-11-06 10:17 lq0bp.vbs  

ea41f9bee135305e27c09f8de3737b15


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 6.0 11 ZeroCERT

7240 2023-11-06 10:00 timeSync.exe  

cf5cb731825863750c4b86a3df164db7


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.0 32 ZeroCERT

7241 2023-11-06 09:59 1  

b6be80abf1b338d6b1b11462aa4b86b4


UPX Downloader PE File PE32 VirusTotal Malware crashed
1.6 10 ZeroCERT

7242 2023-11-06 09:57 mstsc.exe  

1ec8db165fd00337acf3097ce1105055


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself DNS
1 2.6 52 ZeroCERT

7243 2023-11-06 09:55 x-1  

d963ef1ca1c2ee60eaf77d1c394e9564


Malicious Library UPX Downloader PE File DLL PE32 JPEG Format ZIP Format Malware download VirusTotal Malware Malicious Traffic Check memory Checks debugger Creates executable files RWX flags setting unpack itself sandbox evasion Windows Browser ComputerName DNS Downloader
4 2 6 8.4 33 ZeroCERT

7244 2023-11-06 09:54 agodzx.exe  

c65810b74dedc88ca0256ecb11a927cb


UPX .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself DNS
1 6.0 51 ZeroCERT

7245 2023-11-06 09:52 MKiJjiii77.exe  

5aefabd29d2955e7c86c5c6a24f2502b


LokiBot Confuser .NET PWS SMTP KeyLogger AntiDebug AntiVM PE File PE64 Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AgentTesla suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName Software crashed keylogger
2 2 10.8 41 ZeroCERT