Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9076 2023-11-07 07:52 jucostam2.1.exe  

1f6a213c979c6adff88e31e059d2825d


Formbook NSIS Malicious Library UPX PE File PE32 FormBook Malware download Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself
3 8 2 1 3.4 M ZeroCERT

9077 2023-11-07 07:51 putty.exe  

cf3bc964f791ee22366b3277ee099329


Malicious Library UPX PE File PE32 OS Processor Check unpack itself
0.8 M ZeroCERT

9078 2023-11-07 07:49 xinchao.exe  

18e92e00cd0e14cee7e4448e8fa476ef


Malicious Library Malicious Packer PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
2 4 5.2 M ZeroCERT

9079 2023-11-07 07:48 123.exe  

ceac8d319a011ba082cf1ab197d328e9


PE File PE32 .NET EXE Check memory Checks debugger unpack itself ComputerName
1.4 M ZeroCERT

9080 2023-11-07 07:47 arinzezx.exe  

0fbfa908ef2e4abb29788d67bcc9c736


.NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Browser Email ComputerName Software crashed
2 2 10.6 M ZeroCERT

9081 2023-11-07 07:46 Services.exe  

d9ce98a0b0029d26876ac86409bac27e


UPX VMProtect PE File PE32 Malware download Malware MachineGuid Malicious Traffic Check memory buffers extracted unpack itself Check virtual network interfaces IP Check PrivateLoader Tofsee DNS crashed
9 24 4 3 5.6 M ZeroCERT

9082 2023-11-07 07:46 3.exe  

5bf9f652395cac44406e102289501e57


Malicious Library Malicious Packer PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 5.2 ZeroCERT

9083 2023-11-07 07:45 build.exe  

37e4a5aab62b40cf415b116cb246b2e2


Malicious Library UPX PE File PE32 OS Processor Check PDB unpack itself Remote Code Execution
1.2 M ZeroCERT

9084 2023-11-07 07:42 My2.exe  

9873907d252dcecd6baea9a11ac4b0da


PE File PE64 Cryptocurrency Miner DNS CoinMiner
2 1 0.4 M ZeroCERT

9085 2023-11-07 07:42 Ads.exe  

5462d8767b051ba3fc66f78d9ded9f41


PE File PE32 .NET EXE Check memory Checks debugger unpack itself ComputerName
1.4 M ZeroCERT

9086 2023-11-06 18:26 nord.exe  

b3e87b107b029e8c0ab14b095119b263


AsyncRAT Malicious Library UPX Malicious Packer .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check DNS
1 2.2 M ZeroCERT

9087 2023-11-06 14:17 whesilozx.exe  

a117d7af8f85cacb310671b834482605


AgentTesla .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
3 2 11.4 r0d

9088 2023-11-06 14:10 defounderzx.exe  

2ed10c1ecb18c82e28180b08eb96fbc2


AgentTesla .NET framework(MSIL) PWS KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer Email Client Info Stealer Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Discord Browser Email ComputerName DNS crashed keylogger
2 3 3 1 11.4 r0d

9089 2023-11-06 14:07 MKiJjiii77.exe  

5aefabd29d2955e7c86c5c6a24f2502b


AgentTesla Confuser .NET PWS SMTP KeyLogger AntiDebug AntiVM PE File PE64 Browser Info Stealer Malware download FTP Client Info Stealer Email Client Info Stealer Malware AgentTesla suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName Software crashed keylogger
2 2 9.6 r0d

9090 2023-11-06 10:55 clips.exe  

c6ae3bd0ab0e78257468cdab2b867707


Themida Packer Downloader UPX VMProtect Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 AutoRuns Code Injection Check memory Creates executable files unpack itself Windows utilities Checks Bios Detects VirtualBox Detects VMWare suspicious process WriteConsoleW VMware anti-virtualization Windows ComputerName Firmware crashed
9.6 ZeroCERT