Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8641 2023-09-14 19:07 desktopditor.exe  

8e1c37b69493d386cb7c6fdd0afa2d10


UPX Malicious Library Admin Tool (Sysinternals etc ...) PE File PE32 OS Processor Check VirusTotal Malware PDB Check memory Tofsee Remote Code Execution
2 2 1.0 5 ZeroCERT

8642 2023-09-14 19:06 231025 (통일부 통일정책실)윤석열 정부의 대북 정...  

fb5aec165279015f17b29f9f2c730976


Generic Malware Antivirus AntiDebug AntiVM GIF Format Lnk Format HWP MSOffice File PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
11 4 1 7.8 19 ZeroCERT

8643 2023-09-14 19:06 centrolineo2.1.exe  

f111e4ac9108f1bdbb1205b23abe1d28


NSIS UPX Malicious Library PE File PE32 OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 8.4 23 ZeroCERT

8644 2023-09-14 19:04 20231025_정책간담회 사례비 양식.hwp...  

df53040b208a5ac37ad207ddfd828bb0


HWP MSOffice File GIF Format Lnk Format Checks debugger Creates shortcut Creates executable files unpack itself
1.4 ZeroCERT

8645 2023-09-14 18:59 ClientStart.hta  

12e11aec09a12f714ccf9ab425ca70e9


AntiDebug AntiVM MSOffice File VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 4.4 19 ZeroCERT

8646 2023-09-14 14:48 81loader_p1_dll_64_n1_x64_inf....  

efb7ca0300e06884e320349a64f9be3a


UPX PE File DLL PE64 OS Processor Check PDB
0.6 ZeroCERT

8647 2023-09-14 14:48 18loader_p1_dll_64_n1_x64_inf....  

27d44ee2f600dd2c250916905799eb3f


UPX PE File DLL PE64 OS Processor Check PDB
0.6 ZeroCERT

8648 2023-09-14 14:47 13loader_p1_dll_64_n1_x64_inf....  

e2e6dae8a6dc0297fa05621ab32a1217


UPX PE File DLL PE64 OS Processor Check PDB Check memory unpack itself
1.2 ZeroCERT

8649 2023-09-14 14:42 13loader_p1_dll_64_n1_x64_inf....  

e2e6dae8a6dc0297fa05621ab32a1217


UPX PE File DLL PE64 OS Processor Check PDB
0.6 ZeroCERT

8650 2023-09-14 14:36 k5.exe  

87f6774e25128d080fecd3fe5e15daa6


UPX Malicious Library AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware PDB Code Injection Checks debugger wscript.exe payload download Creates executable files suspicious process Tofsee crashed
2 4 4.8 12 ZeroCERT

8651 2023-09-14 14:36 hkcmd.exe  

38535f26390e9fea654aadb0d1ccda38


PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.6 49 ZeroCERT

8652 2023-09-14 14:33 convert-pdf-539.js  

0d5009570d1773ecfccf17e6fd65edba


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows
1 5 7.2 ZeroCERT

8653 2023-09-14 14:33 convert-pdf-591.js  

44096c929ae4aa847f13d91311eb84b8


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check suspicious privilege buffers extracted Creates executable files Windows utilities suspicious process AppData folder WriteConsoleW Windows
1 4 6.4 ZeroCERT

8654 2023-09-14 13:43 convert-pdf-487.js  

39d728cfba118beee8c54f7beb68339e


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows
1 5 6.6 ZeroCERT

8655 2023-09-14 13:41 convert-pdf-741.js  

6fbc1f4557a0eef6e411c33fd88f8339


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows
1 5 7.2 ZeroCERT