Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7876 2023-10-10 10:19 bQ2j.exe  

eb5c869423632f5d3fe31cbbe85bfdbc


Malicious Packer Downloader ScreenShot AntiDebug AntiVM PE File PE32 Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check Windows Browser Email ComputerName DNS DDNS keylogger
1 4 3 12.0 64 ZeroCERT

7877 2023-10-10 10:18 bQ1X.exe  

e230cdc004aa4fa4b61f66fbfd701ee5


Malicious Packer Downloader PE File PE32 VirusTotal Malware Windows DNS DDNS keylogger
2 2 4.4 61 ZeroCERT

7878 2023-10-10 10:16 2.txt.ps1  

a7b07e5ad9ef74d393f0b42419e8d2f5


Generic Malware Antivirus VirusTotal Malware unpack itself WriteConsoleW Windows Cryptographic key
1 1.2 4 ZeroCERT

7879 2023-10-10 10:16 1lkc5ccspw.exe  

3d666f1f41826f039ebcc3323647cd48


UPX Malicious Packer PE File PE32 .NET EXE VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself ComputerName DNS
2 1 3.8 58 ZeroCERT

7880 2023-10-10 10:16 Azienda.url  

c4cc624292ec5fcea7fee79f57199683


AntiDebug AntiVM URL Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 1 2 5.4 ZeroCERT

7881 2023-10-10 10:10 Contract-4.msi  

1b6f948f740eb0426204a9b15472b194


Malicious Library MSOffice File CAB OS Processor Check VirusTotal Malware Buffer PE suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces AntiVM_Disk VM Disk Size Check Windows ComputerName
6 4 3 4.8 1 guest

7882 2023-10-10 09:42 archive.7z  

2e47fd847063d35bda81b2ee40f1e37c


Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware download Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself suspicious TLD IP Check PrivateLoader Tofsee Windows DNS
22 24 18 7 6.0 M ZeroCERT

7883 2023-10-10 09:31 Kriwgshughb.exe  

e781b9ebdf07303d9e64f01100a5a2c7


UPX PE File PE64 OS Processor Check VirusTotal Malware Buffer PE Check memory Checks debugger buffers extracted unpack itself
3.4 M 46 ZeroCERT

7884 2023-10-10 08:12 188.exe  

f96c1d0accec84ab6ddca3c0bafc6cbc


Cutwail Malicious Library UPX Http API ScreenShot Escala Malware download VirusTotal Malware Buffer PE MachineGuid Code Injection Malicious Traffic Check memory buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process suspicious TLD sandbox evasion Tofsee Windows Backdoor ComputerName DNS Cryptographic key
212 1124 7 17.0 M 26 ZeroCERT

7885 2023-10-10 07:49 netTimer.exe  

5e355722e1e969c504c4fe59591ec4ce


UPX Malicious Packer PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself anti-virtualization ComputerName DNS
31 5.4 M 32 ZeroCERT

7886 2023-10-10 07:46 windows.exe  

edc44d75d9e3205cbd90be3d8352f504


Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself DNS
1 2.6 M 56 ZeroCERT

7887 2023-10-10 07:46 kung.exe  

20f562d14af01da92b246896e45e9459


LokiBot Socket PWS DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs suspicious TLD installed browsers check Browser Email ComputerName DNS Software
1 2 9 14.6 43 ZeroCERT

7888 2023-10-10 07:44 1712.exe  

0e0b669d90c80cea6398e81d139d7d29


task schedule KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Malware download AsyncRAT NetWireRC VirusTotal Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities WriteConsoleW Windows ComputerName DNS Cryptographic key
53 3 12.4 49 ZeroCERT

7889 2023-10-10 07:43 udat1.exe  

243b6e0960e9d3b63d924ba0c2b8a6fd


UPX PE File PE64 OS Processor Check VirusTotal Malware unpack itself crashed
2.0 21 ZeroCERT

7890 2023-10-10 07:40 audiodgs.exe  

7a9336c2f3ed97231960fc993881c6ad


Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 14.8 M 22 ZeroCERT