Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7276 2023-11-04 10:53 1  

2dc7034a89baf7a87c7423ae0e685a7e


UPX Downloader PE File PE32 VirusTotal Malware Check memory crashed
1.6 6 ZeroCERT

7277 2023-11-04 10:53 TEST32.exe  

993c85b5b1c94bfa3b7f45117f567d09


Malicious Library UPX Malicious Packer PE File PE32 OS Processor Check Browser Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Check memory buffers extracted IP Check installed browsers check Tofsee Ransomware Browser Email ComputerName Trojan Banking DNS
3 5 12.0 56 ZeroCERT

7278 2023-11-04 10:52 build2.exe  

1199c88022b133b321ed8e9c5f4e6739


RedlineStealer RedLine Infostealer RedLine stealer UPX .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself Check virtual network interfaces Windows DNS Cryptographic key
1 4.2 62 ZeroCERT

7279 2023-11-04 10:44 Word_.doc  

75d7d706c41a6eb2d5a5161a24733999


VBA_macro Generic Malware MSOffice File VirusTotal Malware RWX flags setting exploit crash unpack itself Exploit DNS crashed
1 4.0 18 ZeroCERT

7280 2023-11-04 10:42 hn-1  

a04b173e5b0cb462684e646d91b14683


Malicious Library Downloader PE File DLL PE32 Malware download VirusTotal Malware Malicious Traffic Checks debugger Creates executable files unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check GameoverP2P Zeus Windows DNS Downloader
1 1 9 4.8 55 ZeroCERT

7281 2023-11-04 10:41 vah50.exe  

03f92deb14398467ee6f9ac147c5b97a


Amadey RedLine stealer Gen1 Emotet Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) PWS ScreenShot AntiDebug AntiVM PE File PE32 CAB OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Email Client Info Stealer Malware Microsoft AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealc Stealer Windows Update Browser Email ComputerName Remote Code Execution DNS Cryptographic key Software crashed
4 3 12 4 24.2 M ZeroCERT

7282 2023-11-04 10:38 d-6  

82eae0084a91983e3730b537982b0d82


Malicious Library UPX Downloader PE File DLL PE32 JPEG Format ZIP Format Malware download VirusTotal Malware Malicious Traffic Check memory Checks debugger Creates executable files RWX flags setting unpack itself AppData folder sandbox evasion Windows Browser ComputerName DNS Downloader
4 2 6 8.6 26 ZeroCERT

7283 2023-11-04 10:35 Wpqcpff.exe  

e533f71c253551d1be4ad5ffd52fb793


PE File PE32 .NET EXE VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.2 46 ZeroCERT

7284 2023-11-04 10:33 TrueCrypt_BcCqcw.exe  

bf85e5d13200077c89650c3c2fb48a84


Generic Malware Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check VirusTotal Malware crashed
1.2 16 ZeroCERT

7285 2023-11-04 10:33 ams.exe  

5d26beb8eae1bcf1ba1fc82359f06df2


Generic Malware Malicious Library UPX Malicious Packer PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger Creates executable files RWX flags setting unpack itself
4.2 54 ZeroCERT

7286 2023-11-04 10:30 주요도시 시장가격 조사2023.xlsx.lnk...  

d1dc2db2956803de7eef7a76a6ac5cb2


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format PowerShell ZIP Format Vulnerability VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
9.0 24 ZeroCERT

7287 2023-11-04 10:26 Kuteiisd.exe  

0bb98a8a1597245e3c0c37fbf2c0f94b


Hide_EXE PE File PE64 VirusTotal Malware Check memory Checks debugger unpack itself
2.0 41 ZeroCERT

7288 2023-11-03 18:29 Amadey.exe  

5d0310efbb0ea7ead8624b0335b21b7b


Amadey RedLine stealer Browser Login Data Stealer RedlineStealer RedLine Infostealer Gen1 Emotet Generic Malware Hide_EXE Malicious Library UPX Malicious Packer .NET framework(MSIL) ScreenShot PWS Anti_VM Javascript_B Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Microsoft AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Collect installed applications Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW IP Check VM Disk Size Check human activity check installed browsers check Kelihos Tofsee Stealc Stealer Windows Update Browser ComputerName Trojan DNS Cryptographic key Software crashed Downloader
65 41 26 8 25.8 M ZeroCERT

7289 2023-11-03 18:20 timeSync.exe  

c5413f26ad9d6a74ed7e649f8001da14


Malicious Library UPX PE File PE32 OS Processor Check unpack itself
0.8 ZeroCERT

7290 2023-11-03 18:18 macoptic2.1.exe  

d6c5df23371399eb60055b93d7b80ea7


NSIS Malicious Library UPX PE File PE32 OS Processor Check Check memory Creates executable files unpack itself AppData folder crashed
3.2 ZeroCERT