Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9406 2021-06-25 14:40 word.exe  

1292877a194c5c20e7c16b00ace00c73


RAT PWS .NET framework Generic Malware HTTP Escalate priviledges KeyLogger Code injection Http API Internet API ScreenShot AntiDebug AntiVM .NET EXE PE32 PE File VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Check virtual network interfaces suspicious process human activity check Tofsee Windows ComputerName DNS crashed
3 7 4 1 12.4 12 ZeroCERT

9407 2021-06-25 14:42 outlook.eml  

8d15f4990f6b8cc9f996e0ab67fe0d7f


OS Processor Check PE32 PE File VirusTotal Malware PDB Malicious Traffic Tofsee DNS
1 3 1 3.2 46 ZeroCERT

9408 2021-06-25 14:42 update.exe  

d2296420a619f59037f8ae20b43b71f2


PWS .NET framework Generic Malware Admin Tool (Sysinternals etc ...) .NET EXE PE32 PE File VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.8 34 ZeroCERT

9409 2021-06-25 14:44 uF3buKW6vp6iV6jU.txt  

ecde3439ca310e6fe9744c30baef966a


VBScript PowerShell Obfuscated File Antivirus AntiDebug AntiVM VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName DNS Cryptographic key
1 6.8 12 ZeroCERT

9410 2021-06-25 14:45 lock_Setup.exe  

4c5c0403d852fcd471a2954fb50f8e60


PE32 PE File GIF Format VirusTotal Malware Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk sandbox evasion China VM Disk Size Check installed browsers check Windows Browser ComputerName
6.8 42 ZeroCERT

9411 2021-06-25 15:00 file.exe  

3dd3e55d3843d47f8699c1a4e22c7ba2


Generic Malware Malicious Packer OS Processor Check PE32 PE File VirusTotal Malware PDB unpack itself Windows Remote Code Execution DNS crashed
1 4 4.2 27 ZeroCERT

9412 2021-06-25 15:01 puttyy.exe  

a3cc45f3e236e6466b74b18f654724c2


RAT Generic Malware PE64 PE File FormBook Malware download VirusTotal Malware suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Windows Cryptographic key
2 5 1 5.0 35 ZeroCERT

9413 2021-06-25 15:02 svhost.exe  

63c173c494e79d63ef61a432fed6a7dd


Generic Malware .NET EXE PE32 PE File VirusTotal Malware Check memory Checks debugger unpack itself Windows DNS Cryptographic key
3.2 54 ZeroCERT

9414 2021-06-25 15:19 loader_v.exe  

6463f298a5906133c8bf1b375ad3d5be


PE64 PE File VirusTotal Malware Checks debugger DNS crashed
2.6 31 ZeroCERT

9415 2021-06-25 15:19 autoupdate.exe  

63e32043d2d8713aae718fc11416153b


Gen2 Generic Malware Antivirus Anti_VM UPX PE64 OS Processor Check PE File PE32 VirusTotal Malware suspicious privilege buffers extracted Creates executable files AppData folder sandbox evasion Windows
1 2 4 6.2 26 ZeroCERT

9416 2021-06-25 15:21 QmXhZxGAX1HF6vaMC1sdLPwpJLWkkv...  

5e1792eae07b1aa1771f496f338e11c1


Gen1 Generic Malware Anti_VM Admin Tool (Sysinternals etc ...) PE64 OS Processor Check PE File DLL VirusTotal Malware Check memory Creates executable files WriteConsoleW
1.8 20 ZeroCERT

9417 2021-06-25 15:22 pc-eq.setup.2.0.0.exe  

8073587ad2b8cc9882aa1b320ba04c19


Gen2 Emotet NSIS UPX Escalate priviledges ScreenShot AntiDebug AntiVM PE32 PE File DLL PNG Format GIF Format OS Processor Check VirusTotal Malware Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check ComputerName DNS
7.4 24 ZeroCERT

9418 2021-06-25 15:22 wbem.exe  

49d86d55cd552810ff3b3eeacdfbbbc7


Generic Malware PE64 PE File VirusTotal Malware Check memory Checks debugger unpack itself
2.2 35 ZeroCERT

9419 2021-06-25 15:24 QmXUa5QT7cyz8Z6BRzomC22a6o2kzw...  

7779f0c76c2d0ec2b4f6327e7ffa04ad


Gen1 Generic Malware Anti_VM Admin Tool (Sysinternals etc ...) PE64 OS Processor Check PE File DLL VirusTotal Malware Check memory Creates executable files WriteConsoleW DNS
2.6 38 ZeroCERT

9420 2021-06-25 15:25 XyliBot.exe  

51707a312ec0701a9d63f87259ab6657


NPKI VMProtect Admin Tool (Sysinternals etc ...) PE32 PE File VirusTotal Malware unpack itself crashed
2.2 18 ZeroCERT