Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7591 2023-10-19 10:49 himeffectivelyproress.exe  

fa9494dcb5bd42e61e89231dfc8eb0da


Gen1 Emotet Malicious Library UPX AntiDebug AntiVM PE File PE64 CAB PE32 .NET EXE OS Processor Check PNG Format MSOffice File JPEG Format VirusTotal Malware AutoRuns PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces AppData folder Tofsee Windows Exploit Remote Code Execution DNS crashed
1 3 4 1 10.2 M 22 ZeroCERT

7592 2023-10-19 10:47 setup.exe  

3111f8d446efd3c0a0e2c91cbf303998


Malicious Library PE File PE32 VirusTotal Malware WMI Creates executable files RWX flags setting Checks Bios anti-virtualization ComputerName
4.2 M 41 ZeroCERT

7593 2023-10-19 10:47 build.exe  

a8f8c8c13cfd0aa9b11430b98485b6e5


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
1.6 M 30 ZeroCERT

7594 2023-10-19 10:35 toolspub1.exe  

d29b29f543a8e7145d225a7a81818308


Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware Code Injection Checks debugger buffers extracted unpack itself
6.4 M 30 ZeroCERT

7595 2023-10-19 10:35 build.exe  

fb822de297dc253056e7538748d43a3a


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
1.6 M 31 ZeroCERT

7596 2023-10-19 10:29 Setup.7z  

7549293a5a8c4e9e8ded3ee62551db42


PrivateLoader Amadey Vidar Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c powershell Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Discord Browser RisePro Trojan DNS Downloader
76 138 57 30 8.4 M ZeroCERT

7597 2023-10-19 10:21 EngineChromium.exe  

2f943946efaa3e446ee3cbd43a540f5b


Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) PE File PE64 ftp OS Processor Check VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces
3.0 31 ZeroCERT

7598 2023-10-19 09:58 EngineChromium.exe  

2f943946efaa3e446ee3cbd43a540f5b


Emotet Gen1 Generic Malware Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) PE File PE64 ftp OS Processor Check VirusTotal Malware PDB crashed
1.6 30 ZeroCERT

7599 2023-10-19 09:56 bQJU.exe  

bf88f41d1be46f0855345b4b74beb44f


UPX Malicious Packer .NET framework(MSIL) PE File PE32 .NET EXE Malware download NetWireRC VirusTotal Malware IP Check RAT DNS DDNS
1 4 4 2.4 54 ZeroCERT

7600 2023-10-19 09:56 oneone.js.exe  

7099a939fa30d939ccceb2f0597b19ed


PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself ComputerName
2.6 M 56 ZeroCERT

7601 2023-10-19 09:55 0.txt.ps1  

3651e42acbe56a42676d14fc00d3e824


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.4 3 ZeroCERT

7602 2023-10-19 09:36 oneone.js  

8d38022aafef200f061a873cad79fe61


WSHRAT LokiBot Formbook Hide_EXE Generic Malware Suspicious_Script_Bin Antivirus .NET framework(MSIL) Escalate priviledges PWS KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer Malware download FTP Client Info Stealer Wshrat NetWireRC VirusTotal Email Client Info Stealer Malware VBScript powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI wscript.exe payload download Creates shortcut Creates executable files ICMP traffic unpack itself Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW IP Check VM Disk Size Check Windows Houdini Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger Dropper
2 6 6 1 10.0 M 34 ZeroCERT

7603 2023-10-19 08:05 smss.exe  

89e7a2a15d1a8eaff2f2570f39532c1c


Formbook .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself DNS
2 5 1 9.6 M 31 ZeroCERT

7604 2023-10-19 08:02 987123.exe  

1d14fe082ca22877edbcea8f33401b18


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself DNS
1 2.2 M 31 ZeroCERT

7605 2023-10-19 08:00 ch.exe  

443ebfe5300c79fd559324c757aab369


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware
1.2 M 45 ZeroCERT