Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8116 2023-10-01 17:21 nix.txt.exe  

5d5a750c6c99cae5b8ca7d277b1dac50


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 6.4 57 ZeroCERT

8117 2023-10-01 17:21 2023.exe.exe  

027a60b4337dd0847d0414aa8719ffec


Aurora Stealer Malicious Library UPX Malicious Packer PE File PE32 OS Processor Check VirusTotal Malware ICMP traffic DNS
1 4.4 M 58 ZeroCERT

8118 2023-10-01 17:18 Umm2.exe  

2a2e7e3b0c0aee191ade0c57516abf99


PE File PE32 .NET EXE VirusTotal Malware Buffer PE PDB Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key
3.6 M 26 ZeroCERT

8119 2023-10-01 17:18 Umm.exe  

e38c7f0fa1a4d8ffc18742eb0df40048


PE File PE32 .NET EXE VirusTotal Malware Buffer PE PDB Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key
4.2 M 26 ZeroCERT

8120 2023-10-01 17:17 borilpokonta2.1.exe  

ff5073e7ca0e1ec86ee0268f040af237


NSIS Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Check memory Creates executable files unpack itself AppData folder crashed
4.0 M 52 ZeroCERT

8121 2023-10-01 16:48 AC.pdf.lnk  

80c2dde809389cff2dbb6c4bc7b26e9d


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Malware Code Injection Malicious Traffic Creates shortcut unpack itself suspicious process WriteConsoleW DNS crashed
1 1 2 4.0 ZeroCERT

8122 2023-10-01 16:48 5BL.pdf.lnk  

f99a611041175e3d94c2d68a8aa4b90b


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Malware Code Injection Malicious Traffic Check memory Creates shortcut unpack itself suspicious process WriteConsoleW DNS crashed
1 1 2 4.2 ZeroCERT

8123 2023-10-01 16:47 0ETT.pdf.lnk  

eb895053a7bee85c754348f1eea7b020


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Malware Code Injection Malicious Traffic Creates shortcut suspicious process WriteConsoleW DNS
1 1 2 3.4 ZeroCERT

8124 2023-09-30 13:49 47f036f9996df7d9d5809b698fd41f...  

47f036f9996df7d9d5809b698fd41f75


Malicious Library UPX Antivirus .NET framework(MSIL) Malicious Packer PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 55 ZeroCERT

8125 2023-09-30 13:47 tiworker.exe  

b51f67297d5dd494ed1acecf85c989f8


Formbook NSIS Malicious Library UPX PE File PE32 FormBook Malware download VirusTotal Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself
4 9 1 2 4.2 M 57 ZeroCERT

8126 2023-09-30 13:47 betterconsiderableresspro.exe  

99fe507e16e1bc59c788bce2d138b9f4


Gen1 Emotet Malicious Library UPX PE File PE64 CAB PE32 .NET EXE VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Windows Remote Code Execution
2 1 4.6 14 ZeroCERT

8127 2023-09-30 13:47 bestunderstandingresspro.exe  

c64258c1d7fef95b76f9aca64d707ac7


Gen1 Emotet Malicious Library UPX PE File PE64 CAB VirusTotal Malware AutoRuns PDB Creates executable files Windows Remote Code Execution
3.0 14 ZeroCERT

8128 2023-09-30 13:45 prosperzx.exe  

98b5d1281fc45604bb645cd9eea268b4


Formbook .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
2 4 1 8.6 M 49 ZeroCERT

8129 2023-09-30 13:43 3231322212.exe  

6419a1e59348225baafa1b58ed611fc9


Downloader UPX .NET framework(MSIL) Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P SMTP AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities Collect installed applications suspicious process WriteConsoleW installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 15.2 M 35 ZeroCERT

8130 2023-09-30 13:40 calc2.exe  

02c0527b5d7ae4a6e5fb3176b3edef66


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB DNS
1 2.2 M 36 ZeroCERT