Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7756 2021-04-30 09:24 5bef7b39fe02eabea2c02612758762...  

6f203feba292f1322dae52e76dbf4ce4


VBA_macro VirusTotal Malware Malicious Traffic unpack itself DNS
3 3.6 M 4 ZeroCERT

7757 2021-04-30 09:31 s68r0hZ49vns9tk.exe  

081bff782d62aebc69b61009e6000ab8


PWS .NET framework Malicious Packer SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName crashed
11.6 M 23 ZeroCERT

7758 2021-04-30 09:31 reg.dot  

d0c491b8eb3ea8f00a93af05ef1b8945


AntiDebug AntiVM Malware download VirusTotal Malware MachineGuid Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed Downloader
3 1 6 5.2 M 27 ZeroCERT

7759 2021-04-30 09:32 HBankers_Latest.hta  

4324831d87b2b6e82e60406c4d07b42c

VirusTotal Malware crashed
3 0.6 4 ZeroCERT

7760 2021-04-30 09:33 280421-z1z.exe  

2699077a996951eac7b369b6356ff296


PE File OS Processor Check PE32 VirusTotal Malware unpack itself Remote Code Execution
2 2.0 20 ZeroCERT

7761 2021-04-30 09:36 8BmVIdYzvSw7AD3.exe  

063f5233e489e4b13c2fcc62e1750705


PWS .NET framework AsyncRAT backdoor Malicious Library SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
12.0 M 27 ZeroCERT

7762 2021-04-30 09:38 HBankers_Latest.hta  

4324831d87b2b6e82e60406c4d07b42c


Antivirus AntiDebug AntiVM MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process Tofsee Windows Exploit ComputerName DNS Cryptographic key crashed
1 2 8.8 4 ZeroCERT

7763 2021-04-30 09:41 redbutton.png  

79f0f44a27a3d1bdc7cdd7e7c248fb29


PE File OS Processor Check PE32 Dridex TrickBot Malware suspicious privilege Malicious Traffic buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process Kovter ComputerName DNS crashed
1 4 2 7.0 ZeroCERT

7764 2021-04-30 09:47 Company Details.ppam  

c8e1760af8a65590d26315a4ff144b62


VBA_macro PNG Format VirusTotal Malware powershell AutoRuns Malicious Traffic Check memory buffers extracted Creates executable files ICMP traffic RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Interception Windows ComputerName DNS
15 16 1 8.6 15 ZeroCERT

7765 2021-04-30 09:48 cutscroll.png  

f5c29728fe1f4226a8dc603d788a0a6f


PE File OS Processor Check PE32 Dridex TrickBot Malware suspicious privilege Malicious Traffic buffers extracted unpack itself Check virtual network interfaces suspicious process Kovter ComputerName DNS crashed
1 2 3 4.6 ZeroCERT

7766 2021-04-30 09:48 divine11111.html  

2eeda876014265c8413ef0e565a96657


AntiDebug AntiVM PNG Format VBScript suspicious privilege MachineGuid Code Injection WMI wscript.exe payload download Creates executable files RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Windows ComputerName Dropper
33 19 1 1 10.0 M ZeroCERT

7767 2021-04-30 12:04 RaptoreumDigger.exe  

ddf9bb04a39bd8b450d6fb90a146df9c


AsyncRAT backdoor PE File OS Processor Check PE64 PDB MachineGuid Check memory Checks debugger unpack itself Windows Cryptographic key
1.4 guest

7768 2021-04-30 17:56 Project Korvus.exe  

e4cb6177f54802a8eb50817353622056


Ave Maria WARZONE RAT Antivirus OS Processor Check PE File PE32 VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName Remote Code Execution DNS Cryptographic key
2 1 10.8 52 r0d

7769 2021-04-30 17:58 s.dot  

f62c1d955d66e2f33ed7f3abe9a44690


Loki RTF File doc AntiDebug AntiVM LokiBot Malware download VirusTotal Malware c&c MachineGuid Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
2 3 12 1 5.0 M 25 ZeroCERT

7770 2021-04-30 17:59 kayx.exe  

129e1d37b93430b4bd894b16c53cd6bc


AsyncRAT backdoor AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows crashed
3 7 2 10.0 M 26 ZeroCERT