Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8656 2021-06-08 10:49 file22.exe  

4b7f05a9dc569f83f9a2aed17d165e29


PE File PE32 Remote Code Execution
1.4 ZeroCERT

8657 2021-06-08 10:50 jooyu.exe  

aed57d50123897b0012c35ef5dec4184


Gen2 Emotet PE File OS Processor Check PE32 Browser Info Stealer VirusTotal Malware PDB Malicious Traffic Check memory Creates executable files ICMP traffic Check virtual network interfaces AppData folder IP Check Tofsee Browser Remote Code Execution DNS
6 10 2 2 7.8 M 57 ZeroCERT

8658 2021-06-08 11:42 Invoice~details012.exe  

6cad5773b9830105a0862848919987ce


AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself crashed
8.6 M 23 ZeroCERT

8659 2021-06-08 11:46 ayowa.exe  

8b3db2945a73ca4d3ffc48166eaf8d6b


PWS .NET framework PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName DNS Cryptographic key Software crashed
1 7.4 30 ZeroCERT

8660 2021-06-08 12:22 BTQbrowser.exe  

b12fbbf68290508b870ea4f9d38a25b4


AsyncRAT backdoor PWS .NET framework BitCoin AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious TLD Tofsee Windows Cryptographic key
1 4 1 1 10.0 M 28 ZeroCERT

8661 2021-06-08 12:22 setup.exe  

3150a1bf870aa243738b71875a62c51b


Process Kill PE File OS Processor Check PE32 Device_File_Check Browser Info Stealer VirusTotal Malware Malicious Traffic Check memory buffers extracted ICMP traffic Windows utilities suspicious process AppData folder anti-virtualization Tofsee Windows Browser DNS
4 4 1 7.2 M 41 ZeroCERT

8662 2021-06-08 12:24 file7.exe  

d62aad019ac19432a4e859684dea793e


AsyncRAT backdoor PWS .NET framework BitCoin AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces suspicious TLD installed browsers check Tofsee Windows Browser ComputerName Cryptographic key crashed
3 6 2 1 11.2 M 38 ZeroCERT

8663 2021-06-08 12:25 file8.exe  

e8a064a89592dd0838137155a048a5a3


AsyncRAT backdoor PE File .NET EXE OS Processor Check PE32 PE64 VirusTotal Malware Malicious Traffic Tofsee Windows DNS crashed
2 2 4 4.2 M 49 ZeroCERT

8664 2021-06-08 12:29 app.exe  

f0e0670ed51fa999a58e0efeb03a8b54


Generic Malware Malicious Packer PE File OS Processor Check PE32 Malware PDB Malicious Traffic unpack itself Tofsee Windows Remote Code Execution DNS crashed
3 5 4 3.8 M ZeroCERT

8665 2021-06-08 12:29 file6.exe  

f3ffc2d2687032af9b489438f51cc484


PWS .NET framework PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself Tofsee Windows DNS Cryptographic key
3 6 3 4.2 M 16 ZeroCERT

8666 2021-06-08 12:31 Setup2.exe  

623c88cc55a2df1115600910bbe14457


Gen2 Emotet AsyncRAT backdoor Generic Malware VMProtect PE File PE32 DLL .NET DLL OS Processor Check GIF Format Browser Info Stealer VirusTotal Malware suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic unpack itself Check virtual network interfaces AppData folder AntiVM_Disk sandbox evasion IP Check VM Disk Size Check installed browsers check Tofsee Browser ComputerName crashed
8 13 2 4 11.4 M 48 ZeroCERT

8667 2021-06-08 13:15 Pb3Setp.exe  

ef4cd87768670dbe24f609336ebed7f7


AsyncRAT backdoor PWS .NET framework BitCoin AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Ransomware Windows ComputerName DNS Cryptographic key crashed
8 6 1 6 15.0 M 23 ZeroCERT

8668 2021-06-08 13:18 XPP.exe  

7faf83341e5db899efe051b69a718045


Generic Malware PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself anti-virtualization ComputerName DNS
3.0 M 12 ZeroCERT

8669 2021-06-08 13:21 WXC.exe  

35629d91d42d813e3bd6940439fb9ef2


Generic Malware PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself anti-virtualization ComputerName DNS
3.0 M 14 ZeroCERT

8670 2021-06-08 13:21 filename.exe  

b962ee63b8f28568191028fa44df69ee


Generic Malware Malicious Packer PE File OS Processor Check PE32 PDB unpack itself Windows Remote Code Execution DNS crashed
2.6 M ZeroCERT