Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7396 2023-10-30 17:35 build.exe  

ebf343196e0bbc5310da9150fcb5cc5f


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
1.8 M 35 ZeroCERT

7397 2023-10-30 09:53 File.7z  

af9d7f78e54912ec053e221309ce9288


PrivateLoader Stealc Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Malware c&c Microsoft suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader
57 105 48 27 7.0 M ZeroCERT

7398 2023-10-30 07:52 123.exe  

e374462a741bd8b228f22b33bb62f83f


Emotet Gen1 Generic Malware NSIS Malicious Library UPX Malicious Packer Antivirus Admin Tool (Sysinternals etc ...) Anti_VM AntiDebug AntiVM PE File PE64 OS Processor Check PNG Format PE32 DLL MZP Format ZIP Format JPEG Format DllRegisterServer dll BMP Malware download Cryptocurrency Miner Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk suspicious TLD WriteConsoleW VM Disk Size Check Tofsee Ransomware Windows ComputerName DNS crashed Downloader CoinMiner
9 29 15 3 19.4 M ZeroCERT

7399 2023-10-28 19:08 xlaexpoittt.vbs  

08c5dddd1b41a03887c72314ea20d249


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
4 5 2 9.6 7 ZeroCERT

7400 2023-10-28 19:04 cincocicnnc.vbs  

13f5fea2cf9c8eab90170dfda8194c09

VirusTotal Malware buffers extracted wscript.exe payload download Tofsee
1 2 2 3.0 8 ZeroCERT

7401 2023-10-28 19:04 ngfor.vbs  

974b499ef10e95adc829e98ec09d6565

VirusTotal Malware buffers extracted wscript.exe payload download Tofsee
1 2 2 3.0 8 ZeroCERT

7402 2023-10-28 18:57 HTMLIEBrowserhistory.doc  

f7b8200be0d768ab8fdc7ef3203267e8


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic exploit crash Tofsee Exploit DNS crashed
4 6 3 1 3.6 M 29 ZeroCERT

7403 2023-10-28 18:53 HTMLDesginBrowserInternet.dOC  

c6f17e9d8c72950b1100f1ab9c3ab77d


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware exploit crash Tofsee Exploit crashed
2 3 2.2 M 26 ZeroCERT

7404 2023-10-28 18:50 HTMLIEbrowserHistoryClean.doc  

5ad1dfb31daa5015f4fdc8af08b50ae9


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware exploit crash Tofsee Exploit crashed
2 3 2.4 M 30 ZeroCERT

7405 2023-10-28 13:00 KLV.txt.exe  

ad0080738beb0f1c978ebd471e918ffe


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
2 4 5.2 42 ZeroCERT

7406 2023-10-28 12:58 HDV.txt.exe  

cb9088db397e3a4cc261a65902056464


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
4 6 5.2 42 ZeroCERT

7407 2023-10-28 12:58 HCR.txt.exe  

910000304ded0b7d71f772a41e697d72


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Browser Email ComputerName crashed
3.8 45 ZeroCERT

7408 2023-10-28 12:58 GSW.txt.exe  

584252105f5f7f2ab0bad8d1cc9a1bd4


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
2 4 5.2 48 ZeroCERT

7409 2023-10-28 12:54 HTMLIEbrowserhistory.vbs  

a32dfa1497c07d6c81f1c0ca839cbf03


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
4 5 2 9.6 M 5 ZeroCERT

7410 2023-10-28 12:51 HTMLIEBrowserHistorycleaner.dO...  

1276da2350d722faf931038319ea6613


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware RWX flags setting exploit crash Tofsee Exploit crashed
2 3 2.8 M 30 ZeroCERT