Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8581 2023-12-04 18:32 VmManagedSetup.exe  

7ee103ee99b95c07cc4a024e4d0fdc03


SystemBC Malicious Library Antivirus PE File PE64 VirusTotal Malware powershell AutoRuns Windows DNS
1 3.0 M 45 ZeroCERT

8582 2023-12-04 18:32 toolspub2.exe  

11b1cc83dc32d2b8764c543b8619e7a9


Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware unpack itself Windows crashed
3.2 M 55 ZeroCERT

8583 2023-12-04 18:31 cp.exe  

67c91a40f9550dca6e0caf57325b9a10


Themida Packer Downloader UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE32 PE File VirusTotal Malware AutoRuns Code Injection Check memory Creates executable files RWX flags setting unpack itself Windows utilities Checks Bios Detects VirtualBox Detects VMWare suspicious process WriteConsoleW VMware anti-virtualization Windows ComputerName Firmware crashed
10.6 M 33 ZeroCERT

8584 2023-12-04 18:29 Stealer%20Resou%E2%80%AEnls.sc...  

87e782c7ef3f46a86d7df12b399d6fcb


PE32 PE File .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
2 1 2.6 M 49 ZeroCERT

8585 2023-12-04 18:28 1701517543-Srnsa.exe  

ff92658bebd4081e2389e1c82490c745


PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
3.8 M 49 ZeroCERT

8586 2023-12-04 18:27 good.exe  

8ea7dc740a4d382a7dc9322b1649f6f2


Generic Malware Malicious Library Malicious Packer UPX PE32 PE File OS Processor Check Lnk Format GIF Format Malware download VirusTotal Malware AutoRuns suspicious privilege MachineGuid Creates shortcut Creates executable files Windows utilities Disables Windows Security suspicious process WriteConsoleW IP Check human activity check Tofsee Windows RisePro ComputerName DNS
1 5 4 9.2 M 50 ZeroCERT

8587 2023-12-04 18:26 Elbfyhag.exe  

0f60f086665fd4d442821851c878c21b


PE32 PE File .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself Check virtual network interfaces DNS
1 4.0 M 54 ZeroCERT

8588 2023-12-04 18:25 xmrig.exe  

edbbe60d5fc43c859be7363de9eb5798


XMRig Miner Malicious Library Malicious Packer UPX PE File PE64 OS Processor Check VirusTotal Malware
1.4 M 41 ZeroCERT

8589 2023-12-04 18:24 miiyyjss.exe  

78f61ca5653a07ec5b698e07d5642c0a


UPX PE32 PE File VirusTotal Malware unpack itself Remote Code Execution DNS crashed
1 3.8 M 49 ZeroCERT

8590 2023-12-04 18:24 1701007523-Hzxlsavkq.exe  

29620f5d86c39fa73939fdb10803f683


PE32 PE File .NET EXE VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key crashed
3.4 M 57 ZeroCERT

8591 2023-12-04 18:23 setup_uncnow.msi  

c8903eb5763c670a15049d74d764188c


Malicious Library MSOffice File CAB OS Processor Check VirusTotal Malware Buffer PE suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk VM Disk Size Check ComputerName
25 9 4.4 M 5 ZeroCERT

8592 2023-12-04 18:22 microsoftdeletedentirehistoryc...  

6a1c0cb2c30f2bd30ac02506afd5701a


MS_RTF_Obfuscation_Objects RTF File doc Malware download Remcos VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
2 7 6 4.2 M 36 ZeroCERT

8593 2023-12-04 18:21 z1.bat  

97dc80d3844b01587d9fd6377b9ab0a7


Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Anti_VM AntiDebug AntiVM VirusTotal Malware suspicious privilege WMI Windows utilities suspicious process WriteConsoleW Windows ComputerName
4.2 M 18 ZeroCERT

8594 2023-12-04 18:18 clip64.dll  

3727880831612b8461cf81cc4e05d2a3


Amadey Malicious Library UPX PE32 PE File DLL OS Processor Check VirusTotal Malware Malicious Traffic Checks debugger unpack itself DNS
1 1 3.6 M 51 ZeroCERT

8595 2023-12-04 18:17 wlanext.exe  

925cc5d77586311bd5cefbb430d051e1


PE32 PE File .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself DNS
1 3.2 M 50 ZeroCERT