Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8056 2021-05-15 16:36 staticc.txt.ps1  

da43b38aeb47472f876d6feaa0df358e


Antivirus VirusTotal Malware powershell Check memory Creates shortcut unpack itself Check virtual network interfaces WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
2 2 5.8 12 guest

8057 2021-05-15 16:40 Lbjmpll.exe  

1a332cb83ff3faed6778e000639c2c16


AgentTesla AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs ComputerName DNS crashed
1 10.8 M 37 ZeroCERT

8058 2021-05-15 16:40 Yphgvocx.exe  

1df3946318529c6071ca1105a4a0c5cb


AgentTesla SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Windows ComputerName DNS crashed
10.0 M 39 ZeroCERT

8059 2021-05-15 16:41 hoome.exe  

da5f7f6fe191bd61b85daf5676d2f1fe


AsyncRAT backdoor Malicious Library DNS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
8.0 24 ZeroCERT

8060 2021-05-15 18:29 xele.exe  

a63628295fd5898e92415ad1e22bed79


AsyncRAT backdoor PWS .NET framework Malicious Library AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.6 M 34 ZeroCERT

8061 2021-05-15 18:29 xele-08.exe  

92270fddc5c354aa2f14c1e36005a03a


AsyncRAT backdoor Malicious Library .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows DNS Cryptographic key
6.2 M 42 ZeroCERT

8062 2021-05-15 18:31 xele-09.exe  

e759c6e85f58e1ad641e52004eea6c6b


PWS .NET framework Malicious Library AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.6 M 35 ZeroCERT

8063 2021-05-15 18:32 origin-08.exe  

92270fddc5c354aa2f14c1e36005a03a


AsyncRAT backdoor Malicious Library AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities AppData folder Windows DNS Cryptographic key
10.6 M 42 guest

8064 2021-05-15 18:33 Cy3IDpdS0LH8Q4c.exe  

988dd31cb44ab2235655754243264fdc


AsyncRAT backdoor PWS .NET framework Malicious Library .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows Cryptographic key
2.6 M 43 ZeroCERT

8065 2021-05-15 18:35 xele-07.exe  

6d56768ebd66a316d4319b603afbae85


AsyncRAT backdoor Malicious Library AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.4 M 25 ZeroCERT

8066 2021-05-15 18:38 origin-07.exe  

6d56768ebd66a316d4319b603afbae85


AsyncRAT backdoor Malicious Library AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.4 M 25 guest

8067 2021-05-15 18:59 Cir-Bfg-Int.docx  

efaacae225968dba1880a01cd5e8c976

unpack itself
1.2 ZeroCERT

8068 2021-05-15 19:08 tingo7.rar  

3b0c19dc192dec271f3d14cf7bd51863


njRAT backdoor .NET EXE PE File PE32 VirusTotal Malware PDB DNS
1 2.0 42 ZeroCERT

8069 2021-05-17 09:19 tingo7.rar  

3b0c19dc192dec271f3d14cf7bd51863


njRAT backdoor .NET EXE PE File PE32 VirusTotal Malware PDB DNS
1 2.0 M 42 조광섭

8070 2021-05-17 16:59 c4da0137cbb99626fd44da707ae1bc...  

c4da0137cbb99626fd44da707ae1bca8


Darkside Ransomware PE File PE32 VirusTotal Malware MachineGuid
2.4 47 r0d