Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8131 2023-09-30 13:38 rankobazx.exe  

4849feb37691a61269212d9d323e6f79


UPX .NET framework(MSIL) PE File PE32 .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself
5.4 M 37 ZeroCERT

8132 2023-09-30 13:38 x.xx.x.x.doc  

ad154e6d30789f35ac383edc8c671806


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
2 4 2 4.0 M 29 ZeroCERT

8133 2023-09-30 13:36 audiodg.exe  

d8f6b1d6c8b4210fec0826280dccf0fa


UPX .NET framework(MSIL) PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.6 M 46 ZeroCERT

8134 2023-09-30 13:36 cqBmSn7ZZ0p6a7K.exe  

727987dd54cdd7bce9f056b2a80731e9


.NET framework(MSIL) PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.6 M 52 ZeroCERT

8135 2023-09-30 13:34 Updater.exe  

67e741557eaa3124261105bff38bc62a


Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check VirusTotal Malware PDB Check memory Tofsee
2 2 2.0 M 33 ZeroCERT

8136 2023-09-30 13:34 audiodg.exe  

a1f785bfdea5c75ed569fc48681eb610


LokiBot Admin Tool (Sysinternals etc ...) .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
15 4 11.8 M 50 ZeroCERT

8137 2023-09-30 13:33 IOI0ioio0OIOIO0IOI0ioi0i000000...  

750637aa4adce8ce221b8d8755dbbaf8


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Tofsee Windows Exploit Google DNS crashed
5 28 8 4.4 M 29 ZeroCERT

8138 2023-09-30 13:32 audiodg.exe  

44467cb97748f78289cca59f5ad2cc3a


NSIS Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Check memory Creates executable files unpack itself AppData folder crashed
4.0 M 51 ZeroCERT

8139 2023-09-30 13:31 audiodg.exe  

71471d6ba26a1046e49cc34cf9b1122e


UPX .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself Check virtual network interfaces
2.4 M 44 ZeroCERT

8140 2023-09-30 13:30 MD.doc  

67d3cae949ee03c6d70466c4c2735a57


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware exploit crash unpack itself Exploit DNS crashed
1 4.6 M 25 ZeroCERT

8141 2023-09-30 13:29 I0OIIOIOi0ioii0oiioi0ioiooi0i0...  

647d8be1ca923f60c2d571eb746ef0e2


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash suspicious TLD Windows Exploit DNS crashed
15 18 7 5.2 M 27 ZeroCERT

8142 2023-09-30 13:28 audiodg.exe  

54326c193800ac78407da899e591e86d


NSIS Malicious Library UPX PE File PE32 OS Processor Check Check memory Creates executable files unpack itself AppData folder DNS crashed
1 3.4 M ZeroCERT

8143 2023-09-30 13:28 123.exe  

9648cd34630e6a0e149ea9f49911c7cd


Emotet Suspicious_Script_Bin Downloader Malicious Library UPX Malicious Packer Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check Windows ComputerName
7.4 M 20 ZeroCERT

8144 2023-09-30 13:28 agodzx.doc  

b53d71a64cb165fb5bd36e7f22879546


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware exploit crash unpack itself IP Check Tofsee Windows Exploit DNS crashed
1 5 10 4.2 M 34 ZeroCERT

8145 2023-09-30 13:26 ja8drj17aq2.exe  

31c3b0ab9b83cafb8eb3a7890e2d05ca


RedLine stealer Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Collect installed applications WriteConsoleW installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 11.4 M 52 ZeroCERT