Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7651 2023-10-17 16:44 smss.exe  

73f54afbcdc80fdb3c3dd8a0e9fa1c32


Formbook UPX .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
1 4 1 9.6 M 15 ZeroCERT

7652 2023-10-17 16:42 bQGy.exe  

a60c2e8459387329e1dbe2d3625ee2c8


PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee crashed
1 3 1 3.8 55 ZeroCERT

7653 2023-10-17 16:42 owenzx.exe  

944cbd3720565dd3132d42deaaf25cb3


Formbook AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious TLD DNS
2 5 2 2 8.6 M 21 ZeroCERT

7654 2023-10-17 16:40 Ermnnolfu.exe  

7ba214f8174004943d83942dda0f9731


Downloader UPX PWS KeyLogger Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential Sniff Audio HTTP DNS Code injection Internet API FTP P2P AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 4 1 14.4 48 ZeroCERT

7655 2023-10-17 16:28 Archive.7z  

14cf80a7fd8a77c3eaed98b8ec615eb4


Stealc PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Kelihos Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS plugin
56 80 54 21 6.4 M ZeroCERT

7656 2023-10-17 10:52 at.hta  

b3a69d39ea2f074e520077721b475d51


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
1 3 2 1 12.4 M 26 ZeroCERT

7657 2023-10-17 10:42 uwp4072801.png.exe  

e0154733596f482f5feff0f3b5b5cadf


Malicious Library UPX .NET DLL PE File DLL PE32 OS Processor Check VirusTotal Malware PDB
1.4 22 ZeroCERT

7658 2023-10-17 10:38 opt-63.js  

27677b638817a290b98a867a960e28a1


AntiDebug AntiVM Malware Code Injection Malicious Traffic wscript.exe payload download unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows DNS crashed
2 3 2 8.4 guest

7659 2023-10-17 10:38 opt-66.js  

a8715ee933ba762489a918d77d89030d


AntiDebug AntiVM Malware Code Injection Malicious Traffic Check memory wscript.exe payload download unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows DNS crashed
2 3 2 8.0 guest

7660 2023-10-17 10:38 opt-71.js  

a5de8594f885a3ba4d8fdad1c9122c33


AntiDebug AntiVM Malware Code Injection Malicious Traffic wscript.exe payload download Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows DNS
2 3 2 7.2 guest

7661 2023-10-17 10:19 HJGHJGHJJGFile.vbs  

5ccfeb1c2b9afa98577b2d633b4b1166


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 1 ZeroCERT

7662 2023-10-17 10:18 xxx.vbs  

8565f26c1e4435a5645fee07d989e418


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 1 ZeroCERT

7663 2023-10-17 10:12 test.hta  

db2fde02752a7a3ddcbf39589acdf815


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 1 1 10.2 M 25 ZeroCERT

7664 2023-10-17 10:12 test.pdf.url  

ff6018379580a0f672c47e2051e514fa


AntiDebug AntiVM Malware download VirusTotal Malware powershell Code Injection Malicious Traffic RWX flags setting exploit crash unpack itself Windows utilities Tofsee RedCurl Windows Exploit DNS crashed
1 1 4 1 4.6 M 4 ZeroCERT

7665 2023-10-17 10:10 main.bat  

5508b50b110acf7a152316d5352da364


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.6 ZeroCERT