Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8836 2023-11-17 18:47 build.exe  

55c69dde71aa6dc2b44ccdcc36f379ea


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.2 M 30 ZeroCERT

8837 2023-11-17 18:45 Copia_de_la_demanda.wsf  

a326a7a8ff5a700c80932dbcc4a78a9b


Generic Malware Antivirus wget powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 5.4 M ZeroCERT

8838 2023-11-17 18:42 500strim.exe  

1ed9f9bb8c6f1d5c482b4bbf61cf8ee8


UPX PE File PE64 OS Processor Check VirusTotal Malware Buffer PE suspicious privilege MachineGuid Check memory Checks debugger buffers extracted unpack itself Windows ComputerName DNS Cryptographic key
1 4.4 M 16 ZeroCERT

8839 2023-11-17 18:41 OFICIO_DE_EMBARGO_Nro_81_RAMA_...  

b935dc0f2d44f314601d7cc4e6e72989


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 5 2 9.0 M 5 ZeroCERT

8840 2023-11-17 18:38 build.exe  

0161cdb73a523464e8caeea489bc0eef


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.2 M 35 ZeroCERT

8841 2023-11-17 18:37 AWB_Ref#.5839077413pdf.exe  

7ac9bc3020e21341f1c2d8f9e938f9e3


AgentTesla PWS SMTP KeyLogger AntiDebug AntiVM PE32 PE File .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
1 4 5 13.0 19 ZeroCERT

8842 2023-11-17 18:36 update.exe  

bcabfc8a72168c9c59967950ba586367


Gen1 Malicious Library UPX Malicious Packer PE32 PE File DLL OS Processor Check Browser Info Stealer Malware download VirusTotal Malware RecordBreaker MachineGuid Malicious Traffic Check memory Creates executable files unpack itself Collect installed applications AppData folder installed browsers check Stealer Windows Update Browser DNS
9 1 11 7.2 M 40 ZeroCERT

8843 2023-11-17 18:36 Copia_de_la_demanda.wsf  

7011eb5b696d312f9dc5d22b43e9ae59


Generic Malware Antivirus wget VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 5.8 M 5 ZeroCERT

8844 2023-11-17 18:36 minup.exe  

3cedd61842d8ecbe2edce64e0f129a7e


.NET framework(MSIL) PE File PE64 .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself
2.2 M 38 ZeroCERT

8845 2023-11-17 18:34 Copia_de_la_demanda.wsf  

3c96de6adfa3e3cc9d2c8660b6e880c6


Generic Malware Antivirus wget VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 5.8 M 2 ZeroCERT

8846 2023-11-17 18:19 ef9b73d4c7e0eb1eaf832e6b801a8d...  

ef9b73d4c7e0eb1eaf832e6b801a8d79


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
1 6.2 M ZeroCERT

8847 2023-11-17 14:24 MLB_KOREAN_JOB_DESCRIPTION.pdf...  

9fcea5ddaa37780e9ae0a8415ded4b84


Generic Malware Downloader Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process human activity check Windows ComputerName Cryptographic key
1 7.6 16 ZeroCERT

8848 2023-11-17 07:57 CheatWiz.exe  

cee8be42d8a32ec2c409c34df0158e19


Gen1 Emotet Generic Malware Malicious Library ASPack UPX Malicious Packer PE File PE64 OS Processor Check DLL ZIP Format DllRegisterServer dll Malware Check memory Creates executable files Ransomware
1.8 M ZeroCERT

8849 2023-11-17 07:50 build.exe  

127a6cc954fbbb101a902b92785d406a


Malicious Library UPX PE32 PE File OS Processor Check unpack itself Windows crashed
1.6 M ZeroCERT

8850 2023-11-17 07:49 build.exe  

8db522805e565ad411c8b713dd5558a1


Malicious Library PE32 PE File PDB unpack itself Remote Code Execution
1.2 ZeroCERT