Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7546 2021-04-23 18:21 watchdog.exe  

6512ae7c9f36206f6433f78296102419


VirusTotal Malware Creates executable files Trojan DNS
1 4.8 M 55 ZeroCERT

7547 2021-04-23 18:36 http://armyscheme.sytes.net/wi...  

fdd0b9ab0a8d70288ddef6337b62d151


Malware Code Injection unpack itself Windows utilities Tofsee Windows DNS DDNS
1 4 7 3.6 M ZeroCERT

7548 2021-04-23 18:37 update.exe  

7806508028c78ff39211cdfe01a070ef


Library Malware Gen2 Malware download Amadey ENERGETIC BEAR Malware Malicious Traffic Check memory Creates executable files unpack itself AppData folder Tofsee Windows ComputerName DNS
2 4 9 5.2 M ZeroCERT

7549 2021-04-23 18:38 sskiper.exe  

8062355a111a77ec5e83711bb635b60b


Process Kill FindFirstVolume PWS .NET framework CryptGenKey AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder suspicious TLD WriteConsoleW installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
11 12 6 16.0 M 16 ZeroCERT

7550 2021-04-23 18:38 a.dot  

fdd0b9ab0a8d70288ddef6337b62d151

VirusTotal Malware ICMP traffic exploit crash unpack itself Windows Exploit DNS DDNS crashed
4 2 2 1 3.8 M 24 ZeroCERT

7551 2021-04-23 18:39 xles.exe  

adcb63b06c30c27be703f0f4eb5b5392


PWS .NET framework AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key crashed
3 8.0 M 10 ZeroCERT

7552 2021-04-23 18:39 invoice_533767.doc  

551fc4e6c0a593d0b04b055531d1fc4e


RTF File doc VirusTotal Malware ICMP traffic exploit crash unpack itself Tofsee Exploit crashed
5 2 1 4.4 M 30 ZeroCERT

7553 2021-04-23 18:40 ugopoundx.exe  

b0ea02e59dcda980a26781b9a7a450c6


AsyncRAT backdoor VirusTotal Malware Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces Windows ComputerName DNS Cryptographic key
2 2 1 3.6 M 13 ZeroCERT

7554 2021-04-23 18:41 getfp.exe  

941b755a404a616a55ea57ff4dbfe184

VirusTotal Malware WriteConsoleW
3.0 M 49 ZeroCERT

7555 2021-04-23 18:43 bro.exe  

dec0c4ab66a84964be201aa8a0404962


PWS .NET framework AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName DNS Cryptographic key crashed
10.4 M 17 ZeroCERT

7556 2021-04-23 18:43 regasm.exe  

1c3957cf92e315b9e04dde81cc66d525


PWS .NET framework Loki AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName Cryptographic key Software
1 1 11.4 M 18 ZeroCERT

7557 2021-04-23 18:46 xUiuQ.txt  

b47160d5d81de4c8094c324ea1b524f9


PWS .NET framework AsyncRAT backdoor VirusTotal Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces suspicious process Tofsee Windows ComputerName DNS crashed
1 4 1 13.0 M 21 ZeroCERT

7558 2021-04-23 18:47 build.exe  

6635fb0d8619a28254c14f16c8f52bc3


Library Malware unpack itself
1.0 ZeroCERT

7559 2021-04-23 18:59 mg20201223-1.exe  

0a13d106fa3997a0c911edd5aa0e147a

VirusTotal Malware DNS
896 1 3.0 M 58 ZeroCERT

7560 2021-04-24 17:56 Wire receipt.pdf.exe  

a7c92e0db9c03095364c2c1ccdfcf704


PWS .NET framework Antivirus AsyncRAT backdoor VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
10.0 27 ZeroCERT