Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
841 2020-07-21 18:29 http://t-lawadvisors.com/aviso...  

7159a277e9012d98d6877c5efe6c4ba7


VirusTotal Malware suspicious privilege Code Injection buffers extracted Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit ComputerName DNS crashed
1 2 1 9.0 39

842 2020-07-22 10:22 http://braxmedia.nl/test/invoi...  

d418ef78fa11b92cd7b01bbe0a90d3cf


VirusTotal Malware DNS
4 1 1.4

843 2020-07-22 11:09 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
7 3 3 4.6

844 2020-07-22 11:16 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
7 3 3 4.6

845 2020-07-22 12:33 http://systemidentifytheprotoc...  

16dc050b380c8161b7973a01b8c7b879


Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files exploit crash unpack itself Windows utilities suspicious process AppData folder malicious URLs Tofsee Windows Exploit Browser Email ComputerName Trojan DNS Cryptographic key Software crashed
3 3 4 15.6 8

846 2020-07-22 12:33 http://systemidentifytheprotoc...  

374fb48a959a96ce92ae0e4346763293


Malware download FTP Client Info Stealer VirusTotal Malware Code Injection Check memory Checks debugger Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Windows Exploit Trojan DNS Software crashed Downloader
1 1 4 7.6 4

847 2020-07-22 12:37 INVOICE LXQ977_276688832.doc  

14d86378e0250e64120d6985bd846056


Vulnerability VirusTotal Malware unpack itself
2.4 18

848 2020-07-22 12:37 Inv ET5808_565971217.doc  

e83403331092ea4ebf89495eb3823deb


Vulnerability VirusTotal Malware Malicious Traffic unpack itself Tofsee DNS
2 2 1 4.2 19

849 2020-07-22 12:41 Inv-XBGH1130_23212865.doc  

c2e592fbfb05a17f76becd999e52a01b


Vulnerability VirusTotal Malware unpack itself Tofsee DNS
1 1 1 3.4 19

850 2020-07-22 12:43 K346LDRF.doc  

8798bfb453d87e028368dddd174d8352


Vulnerability VirusTotal Malware unpack itself
2.4 16

851 2020-07-22 13:19 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
7 3 3 4.6

852 2020-07-22 13:32 http://afboxmarket.com/antonio...  

b5396c9184694dbf1ee6e27ab075258c


VirusTotal Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder Tofsee Windows Exploit DNS crashed
2 2 2 5.2

853 2020-07-22 13:37 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
7 8 3 4.6

854 2020-07-22 13:39 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
7 8 3 4.6

855 2020-07-22 13:52 견적서20200702,pdf.exe  

3b9887f9f9ff50f1c1862b654dea0b80


VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs Tofsee DNS
1 1 1 8.8 31