Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9016 2023-08-28 17:28 CS-Cheat-Installer.exe  

64f1d67b14dafea71c599e9c5498edc2


Browser Login Data Stealer Amadey Malicious Library UPX Admin Tool (Sysinternals etc ...) Http API HTTP ScreenShot Code injection Internet API AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check DLL PE64 JPEG Format Malware download Amadey VirusTotal Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder suspicious TLD WriteConsoleW installed browsers check Tofsee Interception Windows Browser ComputerName DNS Cryptographic key crashed
4 4 9 2 15.8 M 44 ZeroCERT

9017 2023-08-28 17:27 Bratty_Family.exe  

5a5e1481a6d57f81703097f832379fb2


Generic Malware Malicious Library UPX Malicious Packer OS Processor Check PE File PE64 VirusTotal Malware PDB unpack itself crashed
1.4 3 ZeroCERT

9018 2023-08-28 17:26 Mysecondfamily.exe  

f6fcfa4a011f9a073aa53830e78157f9


Generic Malware Malicious Library UPX Malicious Packer OS Processor Check PE File PE64 VirusTotal Malware PDB crashed
1.0 8 ZeroCERT

9019 2023-08-28 17:17 ok.exe  

ba84cb431da839bba1bf4dedb3e2ee8f


Generic Malware Downloader task schedule Malicious Library UPX Antivirus Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Sniff Audio HTTP DNS ScreenShot Code injection Internet API FTP KeyLogger AntiDebug AntiVM OS Process VirusTotal Malware powershell Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security Checks Bios Auto service Detects VirtualBox powershell.exe wrote suspicious process WriteConsoleW VMware anti-virtualization Windows ComputerName Cryptographic key Software crashed
17.8 22 ZeroCERT

9020 2023-08-28 15:14 COD_MW2_Steam.exe  

be82ea0c15a8161fcd03fd624ffef4f3


Emotet Gen1 Generic Malware Malicious Library UPX Admin Tool (Sysinternals etc ...) Malicious Packer Anti_VM OS Processor Check PE File PE64 DLL DllRegisterServer dll ZIP Format ftp VirusTotal Malware Check memory Creates executable files Ransomware
1.8 4 guest

9021 2023-08-28 10:05 religiousplanpro.exe  

93cc75015ca399e68d2176adecea521d


Gen1 Emotet Malicious Library UPX Anti_VM PE File CAB PE64 .NET EXE PE32 VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Windows Remote Code Execution
2 1 4.6 10 ZeroCERT

9022 2023-08-28 10:03 reliigiousplanpro.exe  

265f3a4af704826afeb581c091445847


Gen1 Emotet Malicious Library UPX Anti_VM PE File CAB PE64 VirusTotal Malware AutoRuns PDB MachineGuid Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces Tofsee Windows Remote Code Execution
2 1 4.4 11 ZeroCERT

9023 2023-08-28 09:45 oebd595d1a23f36763e746f48750d1...  

2d4fd05bdccee76bac5231cfa4da5130


PE File PE32 VirusTotal Malware Checks debugger unpack itself
2.0 33 ZeroCERT

9024 2023-08-28 09:43 File_pass1234.7z  

134ceb06f8f77fcdb5dedf95f32a3f27


Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey VirusTotal Malware Microsoft suspicious privilege Malicious Traffic Check memory Checks debugger unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Remote Code Execution Trojan DNS DDNS DoTNet Downloader
30 52 38 10 7.0 M 1 ZeroCERT

9025 2023-08-28 07:55 http://hcdnl.push-rtmps.ovc.gs...  


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 2 2 4.2 guest

9026 2023-08-28 07:43 AiBTQrkJNY.exe  

93e7784defa1b30dcc93427bae186724


Generic Malware UPX Antivirus OS Processor Check PE File .NET EXE PE32 Lnk Format GIF Format VirusTotal Malware AutoRuns PDB MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself Check virtual network interfaces Tofsee Windows ComputerName
2 2 3.8 M 15 ZeroCERT

9027 2023-08-28 07:40 toolspub2.exe  

d3d867c6722255ebcbc51a11a3a39347


Malicious Library UPX AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware PDB Remote Code Execution
3.0 M 42 ZeroCERT

9028 2023-08-28 07:40 Client.exe  

f9391638fc3c6dec9b7319d1c8adeebb


Malicious Library .NET framework(MSIL) UPX ASPack Malicious Packer Antivirus OS Processor Check PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 48 ZeroCERT

9029 2023-08-28 07:37 religionprosig.exe  

3eb7278ffb8ab7d3f190a56756239e64


Gen1 Emotet Generic Malware Downloader Malicious Library UPX Antivirus Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Sniff Audio HTTP DNS ScreenShot Code injection Internet API FTP KeyLogger AntiDebug AntiVM PE File CAB VirusTotal Malware powershell AutoRuns PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Remote Code Execution Cryptographic key
2 2 3 8.8 M 20 ZeroCERT

9030 2023-08-28 07:36 billinv.exe  

81af4f2d111cb10c9b5922d02b3751e6


Malicious Packer PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself
2.4 M 34 ZeroCERT