Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7861 2021-05-04 18:29 redbutton.png  

13643c7875dd8e1a32b657651029e321


OS Processor Check PE File PE32 Dridex TrickBot Malware suspicious privilege Malicious Traffic buffers extracted unpack itself Check virtual network interfaces suspicious process Kovter ComputerName DNS crashed
1 3 2 4.8 ZeroCERT

7862 2021-05-04 18:31 taskhost.exe  

7f6b8e103f0a42615d90a2b7ad862135


HTTP Http API Internet API ScreenShot AntiDebug AntiVM PE File PE32 VirusTotal Malware Buffer PE Code Injection buffers extracted RWX flags setting unpack itself crashed
7.6 M 29 ZeroCERT

7863 2021-05-05 10:10 flexing.exe  

3530084c6c504b18052f430a5d2a35c3


AsyncRAT backdoor PWS .NET framework Malicious Library DNS AntiDebug AntiVM .NET EXE PE File PE32 Malware download Nanocore VirusTotal Malware c&c Buffer PE PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key
1 1 12.8 17 ZeroCERT

7864 2021-05-05 10:10 ashleyx.exe  

34d4452c1b344685e3f5fd7d0e9640a1


PWS .NET framework Malicious Packer SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
8.8 M 21 ZeroCERT

7865 2021-05-05 10:12 Rina.Client.exe  

83f9bc0db9a3e0a33ffe239592be398a


UltraVNC OS Processor Check PE File PE32 VirusTotal Malware PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI unpack itself Check virtual network interfaces Windows ComputerName DNS Cryptographic key crashed
3 1 6.0 M 31 ZeroCERT

7866 2021-05-05 10:12 CShield.dll  

db5198ea4d04bad9c91dc04ba2033579


DLL PE File PE32 VirusTotal Malware Check memory crashed
1.6 M 19 ZeroCERT

7867 2021-05-05 10:14 teret.exe  

43de3367faeffa04f28ad1e3e1f154eb


PE64 PE File VirusTotal Malware unpack itself DNS crashed
1.8 8 ZeroCERT

7868 2021-05-05 10:14 krerb.exe  

1c74d51a1d7177bf9b23f6a567adc047


PE64 OS Processor Check PE File VirusTotal Malware unpack itself ComputerName
2.0 7 ZeroCERT

7869 2021-05-05 10:16 Ll2LxWOagynlSgJ.exe  

9dfaa6afc47f0bf01155b7f8253f719b


AsyncRAT backdoor PWS .NET framework Malicious Library SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
12.4 M 25 ZeroCERT

7870 2021-05-05 10:17 cNkVYRf1ANyFE70.exe  

2a2a8564ad128b54843a01cd01f71ebb


AsyncRAT backdoor PWS .NET framework Malicious Library .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself Windows Cryptographic key crashed
2.0 M 19 ZeroCERT

7871 2021-05-05 10:19 Pdipucce.exe  

d96b7886c4e00e171709fd82c54ec891


AsyncRAT backdoor PWS .NET framework AgentTesla SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces malicious URLs IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 8.6 M 20 ZeroCERT

7872 2021-05-05 10:19 mad.exe  

d96f52fc8733d2f4a127bdc44d4ceb25


Antivirus SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Disables Windows Security powershell.exe wrote suspicious process WriteConsoleW Windows Browser Email ComputerName DNS Cryptographic key Software crashed keylogger
16.4 M 29 ZeroCERT

7873 2021-05-05 10:21 rT7jHQCXKaUEaEs.exe  

682e89458bc1329479029352bafef781


AsyncRAT backdoor PWS .NET framework Malicious Library .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself Windows DNS Cryptographic key crashed
2.8 M 21 ZeroCERT

7874 2021-05-05 10:21 vbc.exe  

40b7776a47fc1062ec85c3e31c91eb81


AsyncRAT backdoor PWS .NET framework Malicious Library .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows Cryptographic key
3.2 M 20 ZeroCERT

7875 2021-05-05 10:23 d.dot  

3874ba5a2e4e803b953be9100aac273a


RTF File doc AntiDebug AntiVM Malware download VirusTotal Malware MachineGuid exploit crash unpack itself Zeus Exploit DNS crashed Downloader
1 2 2 4.2 M 23 ZeroCERT