Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7666 2023-10-17 10:09 dss.cmd  

2b31d5fbd2c8b2014e741757c44b3503


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.0 ZeroCERT

7667 2023-10-17 10:08 doc.bat  

5508b50b110acf7a152316d5352da364


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.6 ZeroCERT

7668 2023-10-17 10:07 at.hta  

b3a69d39ea2f074e520077721b475d51

VirusTotal Malware crashed
1.0 M 26 ZeroCERT

7669 2023-10-17 10:07 555.bat  

758138cf292edc7fc200b8853a34dce3


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process malicious URLs WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
2 3 4 2 11.6 M 1 ZeroCERT

7670 2023-10-17 10:04 1  

2a8cb72531364c728a5d258ae273f69e


Generic Malware UPX Downloader PE File PE32 VirusTotal Malware Check memory crashed
1.6 2 ZeroCERT

7671 2023-10-17 10:04 2  

aed1eb4ab37c9eac1b1108d9739f5903


ZIP Format VirusTotal Malware
0.6 12 ZeroCERT

7672 2023-10-17 10:02 bf85700e.exe  

49c3a1783950fa165b770f6cf5cc0619


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
2.0 35 ZeroCERT

7673 2023-10-17 10:01 uwp4072801.png.exe  

e0154733596f482f5feff0f3b5b5cadf


Malicious Library UPX .NET DLL PE File DLL PE32 OS Processor Check VirusTotal Malware PDB
1.4 22 ZeroCERT

7674 2023-10-17 09:44 j-16  

2d544a42a3a073438330c81607df6ca7


Malicious Library Downloader PE File DLL PE32 Malware download VirusTotal Malware Malicious Traffic Checks debugger Creates executable files unpack itself AppData folder AntiVM_Disk sandbox evasion VM Disk Size Check GameoverP2P Zeus Windows DNS Downloader
1 1 9 5.2 M 43 ZeroCERT

7675 2023-10-17 09:43 artwork.hta  

b3a69d39ea2f074e520077721b475d51


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
2 3 2 10.6 26 ZeroCERT

7676 2023-10-17 07:46 macwelter2.1.exe  

5dc9185191d639c955367a880101e252


NSIS Malicious Library UPX PE File PE32 FormBook Malware download Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself
4 8 1 3.4 ZeroCERT

7677 2023-10-17 07:46 HQR8391000.pdf.exe  

dc36e4d8f1c2b8447a5dfb31c6ec9330


Generic Malware Malicious Library UPX Malicious Packer .NET framework(MSIL) PE File PE32 OS Processor Check .NET EXE PNG Format PDB Check memory Checks debugger Creates executable files unpack itself AppData folder Remote Code Execution
3.2 ZeroCERT

7678 2023-10-17 07:44 pqAlGyUFhqdKYsx.exe  

991a0243b129e2086d31127247f0c630


LokiBot Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer powershell PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 12.0 ZeroCERT

7679 2023-10-17 07:44 ChromeSetup.exe  

8bada859ba3d8bb71df1e74e4e630b9f


Malicious Library UPX PE File PE32 OS Processor Check unpack itself
1.0 ZeroCERT

7680 2023-10-16 21:30 jazz pcto.pdf  

36399fff264f2e4ee3cfcd4f794ee9ce


PDF
guest