Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8716 2023-09-12 07:39 trpcg.exe  

0704e4ae55e1180a2e472c337504742a


LokiBot UPX PWS DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs crashed
7.6 30 ZeroCERT

8717 2023-09-12 07:38 xdlsuthdjke456jd.exe  

35c62ad8e01089dbeac7cd63e551627c


NSIS Suspicious_Script_Bin Malicious Library UPX PE File PE32 DLL VirusTotal Malware Check memory Creates shortcut Creates executable files unpack itself AppData folder Ransomware
4.2 11 ZeroCERT

8718 2023-09-11 18:11 Outstanding Balance Invoice.ex...  

e99e9e9e9e864b38fc75f29b54771c86


NSIS Malicious Library UPX PE File PE32 OS Processor Check Malware download VirusTotal Malware suspicious privilege Check memory Creates executable files ICMP traffic unpack itself AppData folder
17 17 2 6.2 34 ZeroCERT

8719 2023-09-11 18:07 qwerty.chm  

b556bd47157695e3e0b279d56401026f


AntiDebug AntiVM CHM Format VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName
1 4.6 19 ZeroCERT

8720 2023-09-11 18:02 fxjcg.exe  

69a09092311de18b2e02203a4315f281


LokiBot UPX PWS DNS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 1 12.2 M 39 ZeroCERT

8721 2023-09-11 18:02 RaiDrive_2023.9.0_x64.exe  

a523a20f9993d562a1e2761d930cc243


Gen1 Generic Malware Malicious Library UPX Admin Tool (Sysinternals etc ...) Antivirus Malicious Packer ASPack CAB PE File PE32 OS Processor Check JPEG Format PE64 DLL BMP Format icon DllRegisterServer dll MSOffice File VirusTotal Malware Buffer PE PDB suspicious privilege Check memory buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check ComputerName
4.2 M 15 ZeroCERT

8722 2023-09-11 17:59 Document.pdf.exe  

ef9728a0916c18e4f90b6b32798dd564


Lumma Malicious Library UPX Http API ScreenShot Internet API AntiDebug AntiVM PE File PE32 OS Processor Check Browser Info Stealer Malware download VirusTotal Malware Cryptocurrency wallets Cryptocurrency Code Injection Malicious Traffic Check memory buffers extracted unpack itself Collect installed applications sandbox evasion installed browsers check Ransomware Lumma Stealer Browser ComputerName Firmware
3 2 1 3 12.4 M 51 ZeroCERT

8723 2023-09-11 17:58 install.exe  

c9a2e54e8501a2f6dd57255225999b40


UPX PE File PE32 VirusTotal Malware AutoRuns Malicious Traffic Windows utilities suspicious process WriteConsoleW Tofsee Windows ComputerName DNS
1 3 1 6.0 M 43 ZeroCERT

8724 2023-09-11 17:56 @facebyk_packlab.exe  

7c6d12dcd138418691419f9783f8d3bd


RedLine stealer Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 11.6 32 ZeroCERT

8725 2023-09-11 15:52 fasfqwrqweqw.exe  

7278b6ce3ddda7dba2473e0392e54ea6


RedLine stealer UPX AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 11.4 M 53 ZeroCERT

8726 2023-09-11 11:43 lnvoice_1332936990.js  

fd8654cbec65781ef40ef64410c93bf6


Generic Malware Antivirus powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 4.8 ZeroCERT

8727 2023-09-11 11:30 setup_pass.7z  

5c90eadfd3d0167a17483af6439fbede


PrivateLoader Vidar Stealc Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader plugin
59 99 58 23 7.2 M ZeroCERT

8728 2023-09-11 11:29 https://booking-comdetails.blo...  

b31a65581c16d9ec7688fd612974a3b7


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger Javascript_Blob AntiDebug AntiVM MSOffice File icon VirusTotal Malware Code Injection Creates executable files exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
3 4 2 4.6 M ZeroCERT

8729 2023-09-11 10:45 NGVkZTM3.doc  

a4605f24de3aba74ccce5d5ab73d67a6


VBA_macro Generic Malware Antivirus AntiDebug AntiVM Word 2007 file format(docx) ZIP Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Check virtual network interfaces suspicious process WriteConsoleW Windows Exploit ComputerName Cryptographic key crashed
1 1 9.8 41 ZeroCERT

8730 2023-09-11 10:40 клопотання_обшук_Данилець_друк...  

4eea6d2c075a3edb0a80ebab2f44e468


Doc XML Downloader Word 2007 file format(docx) ZIP Format VirusTotal Malware exploit crash unpack itself suspicious TLD Exploit crashed
2 3.6 6 ZeroCERT