Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9256 2023-08-21 10:22 Setup3.exe  

f0e7def68cf0ad13fa1465a84081e7fa


Malicious Library UPX OS Processor Check PE File PE64 VirusTotal Malware DNS
1 1.8 M 36 ZeroCERT

9257 2023-08-21 10:21 1808tui.exe  

34dc3b6f5ad9472d3eee5fe006b97b4a


Gen1 Emotet .NET framework(MSIL) UPX Malicious Library PWS SMTP Socket DNS Javascript_Blob AntiDebug AntiVM PE File .NET EXE PE32 CAB PE64 PNG Format JPEG Format Lnk Format GIF Format Browser Info Stealer FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces AppData folder installed browsers check Interception Windows Browser ComputerName DNS Cryptographic key Software crashed
11 10 18.4 M 40 ZeroCERT

9258 2023-08-21 10:18 nuIex_crypted.exe  

55994b5392dc148b6ffad440403bcf06


Malicious Library UPX AntiDebug AntiVM OS Processor Check PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Windows Browser ComputerName DNS Cryptographic key Software crashed
1 11.6 M 28 ZeroCERT

9259 2023-08-21 10:18 okka25.exe  

006667191f1b2b04e3fb0a2d38d789e0


UPX Malicious Packer PE File PE64 VirusTotal Malware PDB unpack itself Remote Code Execution
1 2 2.4 M 41 ZeroCERT

9260 2023-08-21 10:08 careabout.hta  

8b0909661c0bc5e93ac4404879901b9e


Generic Malware Antivirus AntiDebug AntiVM PowerShell MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Exploit ComputerName DNS Cryptographic key crashed
9.2 17 ZeroCERT

9261 2023-08-21 10:08 BRR.exe  

0cb74296cc79ff0a20f5046f8e80d7b0


Themida Packer UPX PE File .NET EXE PE32 Browser Info Stealer VirusTotal Malware Check memory Checks debugger unpack itself Checks Bios Collect installed applications Detects VMWare VMware anti-virtualization installed browsers check Windows Browser ComputerName Firmware DNS Cryptographic key crashed
1 9.4 M 40 ZeroCERT

9262 2023-08-21 10:02 data64_1.exe  

1c76706643695bfd003d768b2c14f925


.NET framework(MSIL) UPX PWS SMTP AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Windows Browser ComputerName DNS Cryptographic key Software crashed
2 11.2 40 ZeroCERT

9263 2023-08-21 10:00 QmdMgsGfToPREXeXQyQMhwmt9NvDGE...  

23ec1b2da69f3e63540041a9ccd53840


Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
4 15.8 M 36 ZeroCERT

9264 2023-08-21 10:00 data64_3.exe  

8ddf6828d0af91fe8984277aa7b8e497


Gen1 Emotet Malicious Library PE File CAB PE64 .NET EXE PE32 VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Windows Remote Code Execution Cryptographic key
2 6.0 40 ZeroCERT

9265 2023-08-21 09:58 data64_2.exe  

48a0efb20b34146d249e1d2ec6e4b635


.NET framework(MSIL) UPX AntiDebug AntiVM PE File .NET EXE PE32 Lnk Format GIF Format VirusTotal Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Windows ComputerName
10.4 M 40 ZeroCERT

9266 2023-08-21 09:56 okka25.exe  

9a3d39a36e8da1542ed79190e778b587


Malicious Library UPX Malicious Packer PE File PE64 VirusTotal Malware PDB Remote Code Execution crashed
1.4 M 7 ZeroCERT

9267 2023-08-21 09:49 _rdf_client_8cs.html  

18ed6dd97044aab9c4cf481ebfbde44e


AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

9268 2023-08-21 09:47 _literal_rule_8cs.html  

ccf07b81417a66132ce5feb65426a468


AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

9269 2023-08-21 09:47 _i_search_client_8cs.html  

3228c6e05c5d0db1313fe8f73e71e95d


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM PNG Format MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.8 guest

9270 2023-08-21 09:46 _i_rdf_connector_8cs.html  

0dff087c0f9b51812aec4622f14150af


AntiDebug AntiVM PNG Format MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest