Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
8881 2023-09-06 07:48 Services.exe  

ca7502cd02a0a170d9f4305c18410126


PrivateLoader RedLine Infostealer RedLine stealer Generic Malware Malicious Library UPX VMProtect .NET framework(MSIL) Confuser .NET Malicious Packer PWS SMTP AntiDebug AntiVM PE File PE32 OS Processor Check .NET EXE PE64 DLL Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Checks Bios Collect installed applications Check virtual network interfaces suspicious process AppData folder suspicious TLD sandbox evasion WriteConsoleW anti-virtualization IP Check installed browsers check PrivateLoader Tofsee Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
27 57 22 7 23.8 M 52 ZeroCERT

8882 2023-09-06 07:46 6606.exe  

8e17227d496580ab3015b0196442e49f


AsyncRAT UPX .NET framework(MSIL) Malicious Packer OS Processor Check PE File .NET EXE PE32 VirusTotal Malware DNS
1 3.2 53 ZeroCERT

8883 2023-09-06 07:46 update.exe  

f8714a5169debbd07cacc5cd529f117a


Malicious Library UPX Malicious Packer PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser Email ComputerName DNS Software crashed
4 4 5.2 53 ZeroCERT

8884 2023-09-06 07:45 DocRecevutta.exe  

334df8989da06aff9a71ab0f6534301a


njRAT backdoor Generic Malware Malicious Library UPX Antivirus OS Name Check OS Processor Check CAB PE File PE32 MSOffice File VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself Windows Remote Code Execution DNS Cryptographic key
2 4.2 M 26 ZeroCERT

8885 2023-09-06 07:45 file.exe  

16b14dbba5d98857cc8b06fd9319d68a


Generic Malware Malicious Library UPX Malicious Packer Anti_VM OS Processor Check PE File PE64 VirusTotal Malware crashed
1.0 M 25 ZeroCERT

8886 2023-09-06 07:42 Fnvtdhenapsfwu.exe  

cffe529403460c6affe0f52c1e7de602


Malicious Library UPX Admin Tool (Sysinternals etc ...) MZP Format PE File PE32 URL Format Remcos VirusTotal Malware Check memory unpack itself Windows keylogger
1 5 1 3.4 M 32 ZeroCERT

8887 2023-09-05 21:10 aaeaf69dc4dd105e8e2d637a9336af...  

8333b78c2a3eacf8cfd843a7b62ce6ba


Generic Malware UPX Malicious Packer AntiDebug AntiVM PE File PE32 VirusTotal Malware Buffer PE Code Injection buffers extracted Creates executable files RWX flags setting unpack itself malicious URLs Remote Code Execution crashed
2 1 7.2 56 guest

8888 2023-09-05 21:07 4f0926d0d27a4ac8d93749b86cc9cb...  

7d9cc6628fad0eb20977796f5c2335a7


Emotet Malicious Library UPX OS Processor Check PE File DllRegisterServer dll PE32 VirusTotal Malware unpack itself
1.4 22 guest

8889 2023-09-05 09:23 Uni.bat  

aa2cc8f91afd53faea6991ab256a8a7e


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Sniff Audio HTTP DNS ScreenShot Code injection Internet API FTP KeyLogger Anti_VM AntiDebug AntiVM suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities WriteConsoleW Windows ComputerName Cryptographic key
3.0 ZeroCERT

8890 2023-09-05 09:16 invoiceID485.wsf  

02f6d3f1ccfefe7a445d2a3f65f434a5


Generic Malware Antivirus ZIP Format VirusTotal Malware VBScript powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key Dropper
2 1 10.0 M 2 ZeroCERT

8891 2023-09-05 08:57 gen.txt.vbs  

cd6bed1ef56b1e58d23ede753dc7e9e5


Generic Malware Antivirus PowerShell powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 8.6 M ZeroCERT

8892 2023-09-05 08:47 foto7866.exe  

86e1e4c7dd69a31a2c6fe3d9e40c923f


Gen1 Emotet Malicious Library UPX CAB PE File PE32 AutoRuns PDB suspicious privilege Check memory Checks debugger Creates executable files unpack itself Windows utilities Disables Windows Security suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows Update Remote Code Execution Cryptographic key crashed
7.4 M ZeroCERT

8893 2023-09-05 08:44 pusan.exe  

4fc4f4eef8a8dcb87b99721fda7113f2


Malicious Library UPX Anti_VM AntiDebug AntiVM OS Processor Check PE File PE32 DLL PDB Code Injection Check memory RWX flags setting unpack itself suspicious process AppData folder ComputerName Remote Code Execution
3.6 M ZeroCERT

8894 2023-09-05 08:43 main.exe  

db4801f350f32e49f20e81ddba0e91a6


Gen1 Emotet Generic Malware Malicious Library UPX ASPack OS Processor Check PE File PE64 DLL ZIP Format ftp DllRegisterServer dll VirusTotal Malware Check memory Creates executable files crashed
2.4 M 39 ZeroCERT

8895 2023-09-05 08:43 e4C7Fwop.wsf  

6f83b9c7c240127c0b92ce814d02bcb0

wscript.exe payload download DNS
1 1 2.8 ZeroCERT