Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
781 2024-08-21 15:16 NATO%20company.lnk.lnk  

1099227fc19bfaab01b509e016079fa0


Lnk Format GIF Format VirusTotal Malware Creates shortcut unpack itself WriteConsoleW
1 1.4 6 ZeroCERT

782 2024-08-21 15:15 통일부 5월 간담회 계획안(줄리 터너대사 방한건_인권 ...  

028075a00beb580aae25e2d60180889f


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
7.2 19 ZeroCERT

783 2024-08-21 14:27 file.pdf.lnk  

589440925b53b50ff9f6518c1b532320


Suspicious_Script_Bin Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger WMI Creates shortcut Creates executable files unpack itself Windows utilities suspicious process WriteConsoleW installed browsers check Tofsee Windows Browser ComputerName Cryptographic key crashed
1 2 1 12.6 18 ZeroCERT

784 2024-08-21 14:27 MFWBlackFilter.js  

0cece80f82110ef4c815ee2a192faaa0

crashed
0.2 ZeroCERT

785 2024-08-21 14:26 202404_주중한국대사관 한중 북중·안보현안 1.5트...  

a4bd6d00abbd79ab00161ff538cfe703


Generic Malware Antivirus AntiDebug AntiVM HWP MSOffice File Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 10.0 36 ZeroCERT

786 2024-08-21 14:25 66bc7164f05f0_xin.exe  

1b777a2e32e49705203c0cf6d9882956


Generic Malware Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Remote Code Execution
7.4 M 55 ZeroCERT

787 2024-08-21 14:23 66be1454e7648_canvaskate.exe  

4577554743dd424a633fead4bd32e277


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.8 M 30 ZeroCERT

788 2024-08-21 14:20 auto.cpl  

da0c25098a41783e8f46f3de4a0f3b7a


UPX PE File DLL PE32 OS Processor Check VirusTotal Malware PDB unpack itself
1.0 5 ZeroCERT

789 2024-08-21 14:18 66b8d94743fb4_build.exe  

03aad8d88f3b963118e539eb4d895b03


Generic Malware Malicious Library PE File PE64 FTP Client Info Stealer VirusTotal Malware Malicious Traffic Check memory buffers extracted unpack itself Tofsee ComputerName Software
1 2 1 4.6 M 56 ZeroCERT

790 2024-08-21 14:16 66c4c71a033c6_otr.exe#kisotr  

993f5fdf3bd55f35661293167e39649a


Stealc Client SW User Data Stealer ftp Client info stealer Malicious Library Http API PWS AntiDebug AntiVM PE File .NET EXE PE32 Malware download VirusTotal Malware c&c PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Stealc ComputerName DNS
2 1 1 2 8.8 M 15 ZeroCERT

791 2024-08-21 14:14 seo.exe  

6f858c09e6d3b2dbd42adc2fb19b217b


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
5.6 M 23 ZeroCERT

792 2024-08-21 14:12 66b8d920f03c6_build.exe  

265b45d7a9d3f51b3b8512f3088c2e01


Redline RedLine Infostealer RedLine stealer RedlineStealer Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 3 5 1 7.4 M 69 ZeroCERT

793 2024-08-21 14:12 weneedbuttersmoothbunwhichreal...  

03c634f3b71f5dcfca4f2016482bf5f2


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 3 1 4.6 M 35 ZeroCERT

794 2024-08-21 14:01 66c08d2750ada_PilotEdit.exe  

8c0700a14b053b5a71fb7060992f4da9


Generic Malware Malicious Library Malicious Packer UPX PE File PE64 DllRegisterServer dll OS Processor Check VirusTotal Malware crashed
1.4 M 40 ZeroCERT

795 2024-08-21 14:01 66bdeddcda135_SicGap.exe  

9aa5a0472a382d0ff57b3113643c802f


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs sandbox evasion WriteConsoleW Windows ComputerName
7.6 M 29 ZeroCERT