Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7726 2023-10-16 11:01 x9.x9.x9.x0.x0.x0.doc  

4263e519252b6b43dd6901b64f05133d


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware RWX flags setting exploit crash Exploit crashed
2.8 35 ZeroCERT

7727 2023-10-16 11:00 pablozx.exe  

be5084e351dfbf93ca2cc522907e4cc6


Formbook .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
3 6 2 8.6 54 ZeroCERT

7728 2023-10-16 10:58 rc2.jpg  

9727340e36156ec7295b019317a9c5d5


PE File DLL PE32 VirusTotal Malware crashed
2.2 44 ZeroCERT

7729 2023-10-16 10:57 sihost.exe  

12e015f7ce3f2092a290eccf26de6889


Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 12.6 53 ZeroCERT

7730 2023-10-16 09:56 foto2552.exe  

c7523bca22d87a152b8c10c02736a335


Amadey RedLine stealer Gen1 Emotet Generic Malware Malicious Library UPX Antivirus Admin Tool (Sysinternals etc ...) Malicious Packer ScreenShot PWS AntiDebug AntiVM PE File PE32 CAB PNG Format MSOffice File OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell Microsoft AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Collect installed applications powershell.exe wrote suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Stealc Stealer Windows Exploit Browser Email ComputerName Remote Code Execution DNS Cryptographic key Software crashed Downloader
49 26 19 3 26.4 M 45 ZeroCERT

7731 2023-10-16 09:47 newrock.exe  

5678c3a93dafcd5ba94fd33528c62276


Amadey Malicious Library UPX Malicious Packer AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check PE64 Malware download Amadey VirusTotal Cryptocurrency Miner Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW human activity check Kelihos Windows ComputerName Trojan DNS crashed CoinMiner
5 10 14 4 14.6 M 49 ZeroCERT

7732 2023-10-16 09:45 sihost.exe  

7d53ef9b324f31e4258e85abff6b3024


Malicious Library UPX PE File PE32 OS Processor Check unpack itself
0.6 M ZeroCERT

7733 2023-10-14 12:59 AppaltQD.exe  

1a687a4c22bfcb3fcf4c19a05d6da9e5


Malicious Library UPX Malicious Packer Antivirus PE File PE32 OS Processor Check VirusTotal Malware PDB Tofsee Remote Code Execution
2 2 1.8 M 13 ZeroCERT

7734 2023-10-14 12:58 file.exe  

fac282b834711d71edb59aa5fcfa3466


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.0 M 39 ZeroCERT

7735 2023-10-14 12:56 file.exe  

fac282b834711d71edb59aa5fcfa3466


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.0 39 ZeroCERT

7736 2023-10-14 12:55 ratherplan.exe  

2244407bb2d42d5f4eac695f41b6fb5f


Gen1 Emotet Generic Malware Malicious Library UPX ScreenShot AntiDebug AntiVM PE File PE64 CAB OS Processor Check PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files RWX flags setting unpack itself Check virtual network interfaces AppData folder Windows ComputerName Remote Code Execution DNS Cryptographic key crashed
1 1 1 15.4 M 44 ZeroCERT

7737 2023-10-14 12:53 windviewcikon2.1.exe  

898a7d62ce8f67a4bf58a4d697ee65da


NSIS Malicious Library UPX PE File PE32 FormBook Malware download Cobalt Strike Cobalt VirusTotal Malware c&c suspicious privilege Malicious Traffic Check memory Creates executable files ICMP traffic unpack itself
4 9 2 4.8 38 ZeroCERT

7738 2023-10-14 12:53 audiodgse.exe  

9a2273d43305150b70e4cfa69bff2231


LokiBot Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 12.2 44 ZeroCERT

7739 2023-10-14 08:13 inCFxdZ2eOW7KAW.exe  

709e4bfe015ece74ba2f90752f1c1164


task schedule Malicious Packer .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS Cryptographic key
1 12.4 M 54 guest

7740 2023-10-13 09:22 191.exe  

4c321e07bba6c01aab73acdaa9c28b52


Cutwail Malic Malware download VirusTotal Malware Buffer PE MachineGuid Code Injection Malicious Traffic Check memory buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process suspicious TLD sandbox evasion Tofsee Interception Windows Backdoor ComputerName DNS Cryptographic key DoTNet
261 1912 9 17.0 M 34 ZeroCERT