Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
7951 2023-10-07 14:48 x.x.x.x.doc  

15c5d883802631d122728961cb66c596


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 4 2 4.2 M 34 ZeroCERT

7952 2023-10-07 14:47 UFX.txt.exe  

66d2a9ccb1c8fc3c130ee3941e8c97dd


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Browser Email ComputerName Software crashed
4.4 50 ZeroCERT

7953 2023-10-07 14:45 DgKW9Ycr.bat  

17787170abd9adf8dcdfcfefdeea0194


Suspicious_Script_Bin Downloader Malicious Library Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM PE File PE32 ZIP For VirusTotal Malware Code Injection Check memory Creates executable files unpack itself AppData folder malicious URLs WriteConsoleW human activity check crashed
5.0 M 27 ZeroCERT

7954 2023-10-06 19:15 zip.7z  

9de1f996f53b99da8ad9bcb3f8e3f120


PrivateLoader Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Dridex Malware Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealer Windows Discord RisePro Trojan DNS Downloader
50 88 44 20 7.0 M ZeroCERT

7955 2023-10-06 18:40 Cerber.exe  

8b3d0bc69064a0155a205a4202417330


Malicious Library UPX Admin Tool (Sysinternals etc ...) PE File PE32 Malware download VirusTotal Malware MachineGuid Check memory buffers extracted WMI Creates shortcut ICMP traffic unpack itself Windows utilities AntiVM_Disk WriteConsoleW Firewall state off VM Disk Size Check Ransomware Windows ComputerName Remote Code Execution DNS
1088 1 7.8 57 guest

7956 2023-10-06 18:23 zinda.exe  

3141032e3b1e4f3ee0d0a1fe68ccc6e8


Emotet Gen1 Malicious Library UPX Confuser .NET AntiDebug AntiVM PE File PE32 .NET EXE DLL MZP Format PE64 OS Processor Check CHM Format DllRegisterServer dll VirusTotal Cryptocurrency Miner Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces AppData folder WriteConsoleW Tofsee Windows ComputerName DNS crashed CoinMiner
7 6 11.2 M 45 ZeroCERT

7957 2023-10-06 17:53 putty.exe  

9872c3c580e8bd1a22cd4698e73e3f9a


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
1.6 M 30 ZeroCERT

7958 2023-10-06 17:51 get4.exe  

ff7517e244f6545e7936becd68aa0578


PE File PE64 VirusTotal Malware Check memory
1.6 M 11 ZeroCERT

7959 2023-10-06 17:49 Tugksta.exe  

1f4795e3a6a434601ec37a38ffc99ff5


Formbook UPX .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check FormBook Malware download VirusTotal Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows DNS Cryptographic key
17 20 12 14 11.2 M 35 ZeroCERT

7960 2023-10-06 17:49 HTMLc.exe  

ac1e4067e159504a3bfc2c12b1221d10


LokiBot PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
2 4 10.6 M 42 ZeroCERT

7961 2023-10-06 17:47 fotha0925877.exe  

65ef2eef1ccf3146b44010406a235cb7


Gen1 Emotet Generic Malware Malicious Library UPX Malicious Packer PE File PE32 CAB OS Processor Check DLL PE64 Lnk Format GIF Format VirusTotal Malware AutoRuns PDB Check memory Checks debugger WMI Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization VM Disk Size Check Windows ComputerName Remote Code Execution crashed
3 8.8 M 24 ZeroCERT

7962 2023-10-06 17:44 Akh.exe  

ea7e83d83566d5aeceef44caf31cc59d


PE File PE64 VirusTotal Malware Check memory
1.6 M 11 ZeroCERT

7963 2023-10-06 14:45 doser.exe  

4b30467bb8a0c1f50d0705febb02c35d


Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check VirusTotal Malware unpack itself crashed
1.8 18 ZeroCERT

7964 2023-10-06 14:09 okilo.txt.exe  

f2d429cdb651892f83759f28ae6b939c


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer suspicious privilege Check memory Checks debugger unpack itself Browser Email ComputerName Software crashed
3.2 ZeroCERT

7965 2023-10-06 13:56 ReklamX.ps1  

4529da5fd57f762d9286c19c609f015c


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself Windows Cryptographic key
1.4 15 ZeroCERT