Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7576 2021-04-24 20:55 info-33549970.xlsm  

effeb6845cee0ab05c452d39f9e5382d


VirusTotal Malware Check memory unpack itself Tofsee crashed
4 2 3.2 5 ZeroCERT

7577 2021-04-24 21:02 http://107.172.130.145/.-........  

e5d0475ba492d39bb533e3014c866d68


AgentTesla Malware download VirusTotal Malware MachineGuid Code Injection Malicious Traffic Checks debugger exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
2 1 6 7.6 ZeroCERT

7578 2021-04-24 21:09 http.exe  

53b0e38d2219a3ecbc04c80ec1faec1d


AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows DNS Cryptographic key
5.8 M 23 ZeroCERT

7579 2021-04-26 09:21 local.exe  

9820b61c2ef614e025f986fafa130e39

0.6 ZeroCERT

7580 2021-04-26 09:24 apps.exe  

cd155fbcc108d054d747ab4514f3cfd6

VirusTotal Malware Code Injection buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities suspicious TLD Tofsee Windows Exploit DNS crashed
46 16 1 6.4 14 ZeroCERT

7581 2021-04-26 09:29 6eb374b32f94435381bd3f41b0ab76...  

feb36e29ac649a1adec4fbcd1662bb42

VirusTotal Malware DNS
1.8 M 51 ZeroCERT

7582 2021-04-26 09:36 "http://5.79.75.210/0beU0RimJU...  

Malware Code Injection Malicious Traffic RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 2 4.2 M guest

7583 2021-04-26 15:16 mg20201223-1.exe  

0a13d106fa3997a0c911edd5aa0e147a


Ranumbot VirusTotal Malware WriteConsoleW DNS
896 1 3.2 M 57 r0d

7584 2021-04-26 15:29 regasm3.exe  

92ac3623e3748c80f1e1ea0db2fa60e6

Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Check memory Checks debugger Creates executable files unpack itself AppData folder installed browsers check Browser Email ComputerName DNS Software
1 1 1 7.8 M 44 r0d

7585 2021-04-26 15:35 regasm3.exe  

92ac3623e3748c80f1e1ea0db2fa60e6

Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Check memory Checks debugger Creates executable files unpack itself AppData folder installed browsers check Browser Email ComputerName DNS Software
1 1 1 7.8 M 44 r0d

7586 2021-04-26 17:59 winlog.exe  

4b233f24f3a1a17bb7e23f49e7589806


PWS .NET framework Malicious Library AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities AppData folder Windows Cryptographic key
9.6 M 24 ZeroCERT

7587 2021-04-26 18:00 file  

45a0cfbd6749929ebd451bd5a04120e4

Code Injection Creates executable files ICMP traffic RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
9 17 2 6.6 ZeroCERT

7588 2021-04-26 18:02 svchost.exe  

33293b91e0212a207697a9248bc10ed5


PWS .NET framework Malicious Library AsyncRAT backdoor VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Checks Bios Detects VirtualBox suspicious process VMware anti-virtualization Windows ComputerName Cryptographic key Software
11.2 M 18 ZeroCERT

7589 2021-04-26 18:02 regasm.exe  

8228bdbc0be3433aa24927fda1903650


PWS Loki Malicious Library AsyncRAT backdoor Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key Software
1 1 16.0 14 ZeroCERT

7590 2021-04-26 18:04 winlog.exe  

b49746e926f5e9398910a1c72f5c8aa6


PWS .NET framework Loki Malicious Library AsyncRAT backdoor Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs suspicious TLD installed browsers check Windows Browser Email ComputerName Cryptographic key Software
1 2 7 13.0 15 ZeroCERT