Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9361 2024-06-05 03:19 FPTool.exe  

f421bbe1658cfb4615537c78e5311534


PhysicalDrive Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Check memory unpack itself RCE
2.2 5 guest

9362 2024-06-04 23:46 svchost.exe  

8ec922c7a58a8701ab481b7be9644536


Gen1 Generic Malware Malicious Packer UPX PE64 PE File PDB RCE
0.6 guest

9363 2024-06-04 17:23 Resume+LetterofSI-2023.10.7-Fo...  

cfb5465e301f3850d70480660f188e17


MSOffice File unpack itself
1.2 guest

9364 2024-06-04 13:26 new_image.jpg.exe  

34401908a80bd0bedd2a44cd93beb367


Malicious Library Malicious Packer Antivirus UPX PE File DLL PE32 OS Processor Check .NET DLL VirusTotal Malware PDB
1.2 37 ZeroCERT

9365 2024-06-04 13:25 new_image.jpg.exe  

34401908a80bd0bedd2a44cd93beb367


Malicious Library Malicious Packer Antivirus UPX PE File DLL PE32 OS Processor Check .NET DLL VirusTotal Malware PDB
1.2 37 ZeroCERT

9366 2024-06-04 11:06 BjDYewiY.vbs  

7b5b8d04475bc1ebbb77601f57e3e625


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process Tofsee Windows ComputerName Cryptographic key
3 3 1 8.6 23 ZeroCERT

9367 2024-06-04 10:19 temp1.zip  

25d2fe0a75b2e677c1ce76e732c5b59c


ZIP Format VirusTotal Malware IP Check Tofsee DNS
4 6 2.0 10 ZeroCERT

9368 2024-06-04 10:14 StatRKZU.msi  

b896c2b2ae51f7100a342c73f5062896


ScreenShot AntiDebug AntiVM MSOffice File CAB Lnk Format GIF Format Malware download NetWireRC VirusTotal Email Client Info Stealer Malware Campaign suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut Creates executable files unpack itself AntiVM_Disk VM Disk Size Check installed browsers check Konni Browser RAT Email ComputerName
3 2 3 6.8 40 ZeroCERT

9369 2024-06-04 09:57 StatRKZU.msi  

b896c2b2ae51f7100a342c73f5062896


MSOffice File CAB VirusTotal Malware suspicious privilege Check memory Checks debugger Creates shortcut unpack itself AntiVM_Disk VM Disk Size Check ComputerName
3.4 40 ZeroCERT

9370 2024-06-04 09:33 avg_secure_browser_setup.exe  

60feb08011db31607cee2a5bc1f2206f


HermeticWiper NSIS Generic Malware PhysicalDrive Malicious Library UPX Malicious Packer PE File PE32 DLL DllRegisterServer dll OS Processor Check PE64 MSOffice File CAB Browser Info Stealer VirusTotal Malware AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Collect installed applications Auto service Check virtual network interfaces AppData folder AntiVM_Disk sandbox evasion anti-virtualization VM Disk Size Check installed browsers check Tofsee Ransomware Fortinet Windows Browser ComputerName Firmware DNS
5 8 2 21.0 3 ZeroCERT

9371 2024-06-04 09:27 X.vbs  

d5313cc18e38615e3a8eb94ea331cf1d


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted wscript.exe payload download Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process Tofsee Windows ComputerName Cryptographic key
3 5 1 9.2 M 6 ZeroCERT

9372 2024-06-04 09:25 ocean.scr  

fe4ebc62a5498c4d43699abe554febb0


Client SW User Data Stealer Backdoor RemcosRAT browser info stealer Google Chrome User Data Downloader Malicious Library .NET framework(MSIL) UPX ScreenShot Create Service Socket Escalate priviledges PWS Sniff Audio DNS Internet API KeyLogger AntiDebug An Browser Info Stealer Malware download Remcos VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Windows Browser Email ComputerName DNS DDNS keylogger
1 4 4 14.0 46 ZeroCERT

9373 2024-06-04 09:25 lionsareinternationallykingoft...  

99e65c433745f1db70b929bf97d855c7


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
3 6 2 4.2 M 34 ZeroCERT

9374 2024-06-04 09:13 ATHM.txt.exe  

4cadcfbc01966e7247d9baa9c39ad5bf


Browser Login Data Stealer Generic Malware Malicious Library Downloader Malicious Packer UPX ScreenShot AntiDebug AntiVM PE File PE32 OS Processor Check Browser Info Stealer Malware download Remcos VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS keylogger
1 3 2 11.8 64 ZeroCERT

9375 2024-06-04 07:37 igcc.exe  

cfaef1fbcfc3a09ccc8baf621b681025


AgentTesla Malicious Library .NET framework(MSIL) PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed
1 4 3 12.6 M 31 ZeroCERT