Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8881 2021-06-14 20:32 file7.exe  

5fadd583b92b33403dec2566d5e94fa5


AsyncRAT backdoor PWS .NET framework PE File .NET EXE OS Processor Check PE32 Browser Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Windows Browser ComputerName Remote Code Execution Cryptographic key crashed
2 4 2 7.4 M 38 ZeroCERT

8882 2021-06-14 20:32 ConsoleAa16.exe  

9f6f8cb5647da0fc5df0142e82ac12ee


AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware ComputerName DNS
1 3.4 24 ZeroCERT

8883 2021-06-14 20:33 dvbXGgTWnakwjEf.exe  

b30ee4898e8b728051cba76a6511db8c


AsyncRAT backdoor PWS .NET framework Admin Tool (Sysinternals Devolutions inc) Malicious Library PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows Cryptographic key
2.2 M 29 ZeroCERT

8884 2021-06-14 20:33 IMG_003_166_372.exe  

ac54156a7e43cf2ff559eccab719cd56


PWS Loki[b] Loki[m] WebCam SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces AntiVM_Disk IP Check VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 4 3 16.2 M 25 ZeroCERT

8885 2021-06-14 20:36 bxfgbttp528.exe  

048ec3a35503f53f26bba3c4fb831e75


Gen2 Gen1 Emotet Anti_VM PE File OS Processor Check PE32 DLL PNG Format GIF Format MSOffice File JPEG Format PE64 VirusTotal Malware PDB suspicious privilege MachineGuid Check memory buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder AntiVM_Disk China anti-virtualization VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser ComputerName Remote Code Execution
56 16 3 10.4 M 20 ZeroCERT

8886 2021-06-14 20:38 smytprepush0601.exe  

043662a4b5e44eb83cec615f2a519906


Gen2 Gen1 Emotet Anti_VM PE File OS Processor Check PE32 DLL GIF Format PNG Format JPEG Format MSOffice File PE64 VirusTotal Malware PDB suspicious privilege MachineGuid Check memory buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder AntiVM_Disk China anti-virtualization VM Disk Size Check human activity check installed browsers check Tofsee Ransomware Windows Browser ComputerName Remote Code Execution
51 17 3 10.8 M 20 ZeroCERT

8887 2021-06-14 20:39 bzsc_taskpoprepush610.exe  

3e1936560764da4e13811919dbd3a4f7


Gen1 Emotet PE File OS Processor Check PE32 DLL MSOffice File VirusTotal Malware PDB buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk China anti-virtualization VM Disk Size Check human activity check Windows Browser ComputerName Remote Code Execution
8 6 1 7.6 M 23 ZeroCERT

8888 2021-06-14 20:40 m.dot  

56e5691ddfadf1e5fb84ab02c956c35d


RTF File doc AntiDebug AntiVM Malware download VirusTotal Malware MachineGuid Malicious Traffic Check memory exploit crash unpack itself Windows Exploit DNS crashed
1 1 7 4.8 M 28 ZeroCERT

8889 2021-06-14 20:42 sdly_taskpop61.exe  

bc7522c569863c07247effeed6adda85


Gen2 Gen1 Emotet Anti_VM PE File OS Processor Check PE32 DLL JPEG Format PNG Format MSOffice File PE64 GIF Format VirusTotal Malware PDB suspicious privilege MachineGuid Check memory buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself AppData folder AntiVM_Disk China anti-virtualization VM Disk Size Check installed browsers check Tofsee Ransomware Windows Browser ComputerName Remote Code Execution
51 17 4 10.4 M 24 ZeroCERT

8890 2021-06-14 23:48 2.dll  

cdc6ef36562b097aa88cd1d4e7e839cb


PE File PE64 DLL OS Processor Check VirusTotal Malware Checks debugger unpack itself crashed
1.4 9 ZeroCERT

8891 2021-06-15 01:08 DOCUMENT.EXE  

53964b6a40bfe2b10d36ba5e3d52966a


PWS Loki[b] Loki[m] .NET framework Admin Tool (Sysinternals Devolutions inc) Malicious Library DNS KeyLogger ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key
6.4 guest

8892 2021-06-15 02:14 converted-1620651173-127d take...  

6610377e92153714fb04734249387c2b

unpack itself
1.2 guest

8893 2021-06-15 10:16 img_23_61_78_802.exe  

d45879197ce5a42e7c810bca5e020af5


PWS Loki[b] Loki[m] DNS AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Malicious Traffic Check memory malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 1 5 1 8.4 M 33 guest

8894 2021-06-15 10:19 MONDAY-FAX(EMAIL).exe  

e5fc908b43a9096e833093739b2421b6


Admin Tool (Sysinternals Devolutions inc) Malicious Library DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Buffer PE PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key
1 13.4 29 ZeroCERT

8895 2021-06-15 10:19 vbc.exe  

5cea1235379d5c9fbe382c5514fd1335


AsyncRAT backdoor PWS .NET framework Admin Tool (Sysinternals Devolutions inc) Malicious Library AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key crashed
8.2 M 18 ZeroCERT