Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8401 2021-05-28 11:08 file21.exe  

f9003a4991f68b4b07e73ac1e89cf374


Generic Malware Malicious Packer PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Windows crashed
2.8 M 38 r0d

8402 2021-05-28 11:11 file2.exe  

8e459aae5e232ee1e29e70645cd0fa83


Generic Malware Malicious Packer PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Windows crashed
3.0 M 47 r0d

8403 2021-05-28 16:43 bmw.exe  

cffded7466d8a28a09577a407c907fc3


Generic Malware Malicious Library Malicious Packer PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Windows crashed
2.6 22 ZeroCERT

8404 2021-05-28 16:45 bmw1.exe  

6387d9c50daa7741006fbe72cf0ee048


Generic Malware Malicious Library Malicious Packer PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Windows crashed
2.6 24 ZeroCERT

8405 2021-05-28 16:47 D3q0V9hldAyJ1xR.exe  

3206c82d7448508708770a5537362024


PWS .NET framework .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows Cryptographic key
2.4 29 ZeroCERT

8406 2021-05-31 09:17 bmw1.exe  

05b5c49112ebf3d93b737c5540a28faa


Generic Malware Malicious Packer PE File OS Processor Check PE32 PDB unpack itself Windows Remote Code Execution DNS crashed
3.0 ZeroCERT

8407 2021-05-31 09:17 google.bat  

362fbb934eb02fbb301049a2bce6eac9


AgentTesla Antivirus DGA DNS Socket Create Service Sniff Audio HTTP Escalate priviledges KeyLogger FTP Code injection Http API Internet API Steal credential ScreenShot Downloader P2P AntiDebug AntiVM VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
5.0 1 ZeroCERT

8408 2021-05-31 09:19 drunk.exe  

3b053dc6b2a1fd69b96cde6a7d320034


AsyncRAT backdoor PWS .NET framework .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces IP Check ComputerName DNS crashed
1 3 1 6.6 M 55 ZeroCERT

8409 2021-05-31 09:19 ao.exe  

b1d319888860b7a6400c5e5099d59e48


.NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 45 ZeroCERT

8410 2021-05-31 09:21 clip.exe  

24b6fa846f9d1e068e55654ab7ab451b


Malicious Library PE File PE32 OS Processor Check DLL VirusTotal Malware Check memory Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName DNS
5.4 M 56 ZeroCERT

8411 2021-05-31 09:21 filename.exe  

6196cc4ad4f0a19ace433c987b0fc94a


Generic Malware Malicious Packer PE File OS Processor Check PE32 PDB unpack itself Windows Remote Code Execution crashed
2.4 ZeroCERT

8412 2021-05-31 09:31 al.exe  

52abd9b0522751f14763b92baf4afa37


NPKI Antivirus PE64 PE File VirusTotal Malware powershell suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process Windows ComputerName Cryptographic key
7.4 36 ZeroCERT

8413 2021-05-31 09:31 NmX.txt.html  

f69a35821e442a111ebbe08c7fc22060


Antivirus AntiDebug AntiVM VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName DNS Cryptographic key
4 2 6.8 17 ZeroCERT

8414 2021-05-31 09:32 ccsetup579.exe  

195eecffa8cb3f26eb11eb4aa379eaf6


AsyncRAT backdoor Antivirus DNS Socket HTTP Code injection Http API Internet API ScreenShot Downloader AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process AppData folder Windows ComputerName Cryptographic key crashed
10.4 M 42 ZeroCERT

8415 2021-05-31 09:32 new.exe  

03abf4527d2c88e4716e194e93c9b07b


AsyncRAT backdoor PWS .NET framework AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
7.8 40 ZeroCERT