Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9361 2023-10-24 07:46 2.exe  

ad122be61ff9f19db11fd4ff53178d09


Malicious Library UPX PE File PE32 MZP Format Remote Code Execution
1 0.4 M ZeroCERT

9362 2023-10-24 07:46 timeSync.exe  

7c67bbeaf13309161aa474205259692f


Malicious Library UPX PE File PE32 OS Processor Check PDB unpack itself Remote Code Execution
1.2 M ZeroCERT

9363 2023-10-23 17:08 sus.exe  

2e3f17e7e9001ff7b7cf8ab412462a48


Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check VirusTotal Malware PDB Code Injection buffers extracted
7.2 M 27 ZeroCERT

9364 2023-10-23 16:58 foto2552.exe  

4cdb3ee7e130e01a02d7b8a7d8dae6ec


Amadey RedLine stealer Gen1 Emotet Malicious Library UPX Admin Tool (Sysinternals etc ...) ScreenShot PWS AntiDebug AntiVM PE File PE32 CAB PNG Format MSOffice File DLL OS Processor Check Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware Microsoft AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Stealc Stealer Windows Exploit Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
24 17 13 4 20.4 M 46 ZeroCERT

9365 2023-10-23 16:52 nalo.exe  

99187f5197d70ceccc4e0fde10fc7f30


Malicious Library UPX AntiDebug AntiVM PE File PE32 OS Processor Check Malware download VirusTotal Malware PDB Code Injection Malicious Traffic buffers extracted unpack itself Stealc Browser DNS
1 1 2 1 9.4 M 24 ZeroCERT

9366 2023-10-23 16:50 herom.exe  

979c731d6aee4715335cd65dd1bcc21e


Malicious Library PE File PE32 DLL Check memory Checks debugger Creates executable files unpack itself AppData folder WriteConsoleW
2.2 ZeroCERT

9367 2023-10-23 16:47 cbchr.exe  

d88a06a393582a79ab6da48982ec87ae


Generic Malware Downloader Malicious Library UPX Malicious Packer Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 OS P VirusTotal Malware AutoRuns Code Injection Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
4.2 19 ZeroCERT

9368 2023-10-23 16:08 setup.7z  

a4e3febc2031d844ad89ed5f3ed2c206


Stealc PrivateLoader Amadey Vidar Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Dridex Malware c&c powershell Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader
57 110 53 28 7.2 M ZeroCERT

9369 2023-10-23 16:01 7725eaa6592c80f8124e769b4e8a07...  

5ac8db8e129863d0a9aaa7534cc644ff


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself Remote Code Execution
2.2 32 ZeroCERT

9370 2023-10-23 15:35 setup.7z  

bf2d71ede12b007cdabbf513b081fcb7


PrivateLoader Vidar Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Dridex Malware c&c Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader
41 84 46 18 7.0 M ZeroCERT

9371 2023-10-23 13:24 xCvecthUdXEH.exe  

0b6133d5b36cd98c3391f03ae97633d7


Browser Login Data Stealer Generic Malware Malicious Library UPX Malicious Packer Downloader PE File PE32 OS Processor Check Malware download Remcos VirusTotal Malware Malicious Traffic Check memory Windows DNS DDNS keylogger
1 4 4 3.8 61 ZeroCERT

9372 2023-10-23 13:24 nix.txt.exe  

c01e90db99bcc939f829a181aef2c348


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE OS Name Check OS Memory Check OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
4 5 7.4 56 ZeroCERT

9373 2023-10-23 13:15 nicko.vbs  

9693079116e9abb7ac2160191c8164af


LokiBot Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PowerShell Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Exploit Browser Email ComputerName DNS Cryptographic key Software crashed keylogger
2 7 6 19.4 M 15 ZeroCERT

9374 2023-10-23 13:15 nigazxbb.vbs  

4f67a35c1cef3eea2e6734e08beed57f


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 8.8 16 ZeroCERT

9375 2023-10-23 13:14 kwen.vbs  

6919d3ccefbb9391a2f2a4deb3e52e70


Generic Malware Antivirus PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 8.8 16 ZeroCERT