Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8701 2023-11-29 00:09 [Content_Types].xml  

10720bd1e11273d47d78cc6f2d215894


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

8702 2023-11-28 14:51 보안메일.html.scr  

d0e8c1574fbd022e5723b85988c902a4


Eredel Stealer Extended NSIS Malicious Library UPX AntiDebug AntiVM PE32 PE File OS Processor Check .NET EXE PNG Format MSOffice File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic RWX flags setting exploit crash unpack itself Windows utilities Check virtual network interfaces AppData folder Tofsee Windows Exploit DNS Cryptographic key crashed
9 2 1 9.6 11 ZeroCenter

8703 2023-11-28 14:17 hv.exe  

096406c4d94995f150e36fbb4f8fa05b


Admin Tool (Sysinternals etc ...) .NET framework(MSIL) Malicious Library UPX PWS AntiDebug AntiVM PE32 PE File .NET EXE PNG Format DLL OS Processor Check Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces AppData folder installed browsers check SectopRAT Windows Browser Backdoor ComputerName DNS Cryptographic key Software crashed
1 1 14.8 4 ZeroCERT

8704 2023-11-28 14:17 obizx.exe  

22033619d1075b112f8b58d657f536f8


Formbook .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 11.8 M 51 ZeroCERT

8705 2023-11-28 11:29 vbsss.jpg.exe  

db2ee1ea937d2e49bc3f237edde48cfb


Generic Malware Antivirus PE32 PE File DLL .NET DLL VirusTotal Malware Check memory unpack itself
1.2 14 ZeroCERT

8706 2023-11-28 11:20 hta.jpg.exe  

0f259f4cb66106371ece0128de84bfb2


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware Check memory unpack itself
1.6 38 ZeroCERT

8707 2023-11-28 10:44 server1.exe  

2390cfec047769ff220db8d9d5d5c78d


UPX Confuser .NET PE32 PE File .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself
2.2 M 35 ZeroCERT

8708 2023-11-28 10:20 hta.jpg.exe  

0f259f4cb66106371ece0128de84bfb2


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware
1.0 38 ZeroCERT

8709 2023-11-28 10:19 js.jpg.exe  

cb3540aebe2027f561ec83f5effae983


Generic Malware Malicious Library Antivirus UPX PE32 PE File DLL OS Processor Check .NET DLL VirusTotal Malware
1.2 42 ZeroCERT

8710 2023-11-28 10:09 3tuvq.js  

a758953be379c89a34398eb1fc1f233a


Generic Malware Antivirus ActiveXObject PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
4 5 2 9.0 8 ZeroCERT

8711 2023-11-28 10:04 afriq.js  

0cd971ef91e57c0c285da2fe74c2d6ec


ActiveXObject VirusTotal Malware wscript.exe payload download Tofsee
1 2 2 2.0 5 ZeroCERT

8712 2023-11-28 09:58 BMW.txt.exe  

d3495009e35cc99a03329dda752d0bf4


AgentTesla Malicious Library Malicious Packer UPX PE32 PE File .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
2 4 5.2 49 ZeroCERT

8713 2023-11-28 09:58 ndldll.txt.exe  

4e88cb52fa6c33f10aeeac975b2e4cd4


UPX PE32 PE File DLL VirusTotal Malware Check memory Checks debugger RWX flags setting unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check Browser ComputerName Remote Code Execution DNS
1 5.4 M 35 ZeroCERT

8714 2023-11-28 09:57 File_HTA.hta  

dba4ee200dd745d57b7bb1f6dcdfe8d5


Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows Exploit ComputerName DNS Cryptographic key crashed
3 3 2 10.0 4 ZeroCERT

8715 2023-11-28 09:56 brAZILLLFile_HTA.hta  

e72b286e211eec5f15fcd218ffcc389c


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 3 1 10.0 4 ZeroCERT