Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7516 2024-07-31 09:12 3.lnk  

0a68f0e0832154a0a4fbdc304392693f


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.6 8 ZeroCERT

7517 2024-07-31 09:12 2.lnk  

2ac86d33add8cc3fc0bacb12d028faff


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.8 16 ZeroCERT

7518 2024-07-31 07:38 sand.exe  

037f916ac94fcc198a7253a0daf62777


Amadey Gen1 RedLine stealer RedlineStealer Generic Malware EnigmaProtector UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer .NET framework(MSIL) Anti_VM PE File PE32 DLL PE64 OS Processor Check .NET EXE ZIP Format ftp Malware download Amadey Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself Checks Bios Detects VMWare AppData folder VMware anti-virtualization Tofsee Windows ComputerName DNS Cryptographic key crashed
8 5 10 6 15.8 M ZeroCERT

7519 2024-07-31 07:32 postbox.exe  

c53bb047b93851b66fead144d7c46ff3


Gen1 Generic Malware Malicious Library Malicious Packer UPX DllRegisterServer dll PE File PE64 MSOffice File OS Processor Check
M ZeroCERT

7520 2024-07-31 07:28 UXSNUWNZ.exe  

532d05ffeadbd71ebd3427d829a6759f


Generic Malware Malicious Library UPX Malicious Packer PE File PE32 DLL PE64 OS Processor Check PNG Format Check memory Checks debugger Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check ComputerName
3.2 ZeroCERT

7521 2024-07-31 07:28 random.exe  

9cccb9b47686e3ab460cbee74196ba25


EnigmaProtector PE File PE32 unpack itself ComputerName crashed
1.4 ZeroCERT

7522 2024-07-31 07:27 stealc_valenciga.exe  

3c18dac89d980c0102252ad706634952


Gen1 Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Antivirus UPX Malicious Packer PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Vidar Malware c&c Malicious Traffic Check memory Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 6.0 ZeroCERT

7523 2024-07-31 07:22 Major_0x00012BD4C3BDF0.exe  

c7ea74a05e864d4d67a2fba6be3bb667


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 OS Processor Check crashed
0.2 ZeroCERT

7524 2024-07-30 13:57 ms2.bin_dec.dll  

81e9262f4a1fb09caf782d12339c4b9d


Generic Malware task schedule Malicious Library Malicious Packer UPX ScreenShot PWS DNS KeyLogger AntiDebug AntiVM PE File DLL PE64 OS Processor Check VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows RCE
1 9.4 36 ZeroCERT

7525 2024-07-30 13:55 BITHUMB_20240729.docx.lnk  

2afb9ccd85ffcef656eefc18150741ab


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Java ComputerName Cryptographic key
7.2 14 ZeroCERT

7526 2024-07-30 13:40 Authenticator.exe  

dae181fa127103fdc4ee4bf67117ecfb


Emotet Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
1.6 35 ZeroCERT

7527 2024-07-30 13:38 HostelCurves.exe  

9512f65eed44bccd7da4ca3d8adb397d


Generic Malware Suspicious_Script_Bin Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P An VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
7.2 M 47 ZeroCERT

7528 2024-07-30 10:13 mobile_kadw.ps1  

563d96353e5b51fdb7fe7509967f9747


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 10 ZeroCERT

7529 2024-07-30 10:11 doc.exe  

8f92f52bffea35771a435d8d0ac04b0d


UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
0.8 M 14 ZeroCERT

7530 2024-07-30 10:11 ccxzse.ps1  

2c41269583d28c932670429c40247c3e


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 M 13 ZeroCERT