Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8476 2023-12-11 19:51 updHost.exe  

f635abf65a40a5de7cebafcc57a562da


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 M 49 ZeroCERT

8477 2023-12-11 19:51 clip64.dll  

c06513af505f65393b4ebcd2a11a2ee4


Amadey Malicious Library UPX PE32 PE File DLL OS Processor Check VirusTotal Malware Malicious Traffic Checks debugger unpack itself DNS
1 1 3.6 M 58 ZeroCERT

8478 2023-12-11 19:50 wlanext.exe  

f8dd68662d873c903364ab250ca25e7d


Generic Malware Malicious Library UPX Antivirus PE32 PE File powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key crashed
6.0 M ZeroCERT

8479 2023-12-11 19:49 setup294.exe  

3c3a0dc705cffd3f56b4315750c18e37


Malicious Library AntiDebug AntiVM PE32 PE File DLL VirusTotal Malware Code Injection Check memory Checks debugger Creates executable files unpack itself AppData folder
5.2 M 52 ZeroCERT

8480 2023-12-11 19:44 xyoriginzx.exe  

410f943c02ead92432bccafe75f3617a


PE32 PE File .NET EXE VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself
5.6 M 42 ZeroCERT

8481 2023-12-11 19:44 microsoftdecidedtodeleteentire...  

c0e36e7962911cb2865904a96323da33


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware buffers extracted exploit crash unpack itself Exploit DNS crashed
1 4.8 M 30 ZeroCERT

8482 2023-12-11 19:42 Cerber.exe  

c7aa2871e40be6337beaf13e1e07576a


PE32 PE File .NET EXE VirusTotal Malware Buffer PE suspicious privilege Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
3.6 M 48 ZeroCERT

8483 2023-12-11 19:42 31.exe  

c24fb9e28286976460a9f0d29f68e634


UPX PE32 PE File .NET EXE OS Processor Check VirusTotal Malware AutoRuns suspicious privilege MachineGuid Check memory Checks debugger unpack itself Windows DNS
1 5.8 M 63 ZeroCERT

8484 2023-12-11 19:40 cleaneruop.exe  

c8360d1235aa3bf925228bfe6a1c8a62


Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows Cryptographic key
3.2 M 52 ZeroCERT

8485 2023-12-11 19:40 Microsoftdecidedtodeleteentire...  

2163e4abe634b604518567a27c2b57cd


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 2 1 4.6 M 36 ZeroCERT

8486 2023-12-11 19:39 fred.exe  

8b81d38713e8269f1fd5aff7be5a5788


Emotet Malicious Library UPX PE32 PE File OS Processor Check DLL VirusTotal Malware Check memory Creates executable files RWX flags setting AppData folder DNS
2 2.8 M 28 ZeroCERT

8487 2023-12-11 19:39 scan-docs.exe  

03727c8d3165d315b14dc409305c2693


Malicious Library Admin Tool (Sysinternals etc ...) UPX PE32 PE File MZP Format OS Processor Check VirusTotal Email Client Info Stealer Malware Code Injection buffers extracted unpack itself sandbox evasion Browser Email
7.0 M 43 ZeroCERT

8488 2023-12-11 19:38 Winlock.exe  

18563c62462e92e3c81dfe737e3a8997


Emotet Malicious Library UPX PE32 PE File OS Processor Check DLL VirusTotal Malware AutoRuns Check memory Creates executable files RWX flags setting Windows utilities suspicious process AppData folder sandbox evasion WriteConsoleW Tofsee Windows Browser Advertising Google ComputerName
2 4 1 8.6 M 51 ZeroCERT

8489 2023-12-11 19:36 q.exe  

e606a8d90dc0458e72508b428e950038


Malicious Library .NET framework(MSIL) UPX PE32 PE File .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 62 ZeroCERT

8490 2023-12-11 19:34 hv.exe  

8deb02b15e78ebf05834e4c32771c665


Admin Tool (Sysinternals etc ...) .NET framework(MSIL) UPX Malicious Library PWS AntiDebug AntiVM PE32 PE File .NET EXE DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder installed browsers check SectopRAT Windows Browser Backdoor ComputerName DNS Cryptographic key Software crashed
1 1 16.2 M 43 ZeroCERT