Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9586 2023-10-14 12:56 file.exe  

fac282b834711d71edb59aa5fcfa3466


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.0 39 ZeroCERT

9587 2023-10-14 12:55 ratherplan.exe  

2244407bb2d42d5f4eac695f41b6fb5f


Gen1 Emotet Generic Malware Malicious Library UPX ScreenShot AntiDebug AntiVM PE File PE64 CAB OS Processor Check PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files RWX flags setting unpack itself Check virtual network interfaces AppData folder Windows ComputerName Remote Code Execution DNS Cryptographic key crashed
1 1 1 15.4 M 44 ZeroCERT

9588 2023-10-14 12:53 windviewcikon2.1.exe  

898a7d62ce8f67a4bf58a4d697ee65da


NSIS Malicious Library UPX PE File PE32 FormBook Malware download Cobalt Strike Cobalt VirusTotal Malware c&c suspicious privilege Malicious Traffic Check memory Creates executable files ICMP traffic unpack itself
4 9 2 4.8 38 ZeroCERT

9589 2023-10-14 12:53 audiodgse.exe  

9a2273d43305150b70e4cfa69bff2231


LokiBot Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 12.2 44 ZeroCERT

9590 2023-10-14 08:13 inCFxdZ2eOW7KAW.exe  

709e4bfe015ece74ba2f90752f1c1164


task schedule Malicious Packer .NET framework(MSIL) AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName DNS Cryptographic key
1 12.4 M 54 guest

9591 2023-10-13 09:22 191.exe  

4c321e07bba6c01aab73acdaa9c28b52


Cutwail Malic Malware download VirusTotal Malware Buffer PE MachineGuid Code Injection Malicious Traffic Check memory buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process suspicious TLD sandbox evasion Tofsee Interception Windows Backdoor ComputerName DNS Cryptographic key DoTNet
261 1912 9 17.0 M 34 ZeroCERT

9592 2023-10-13 08:45 Setup.exe  

635da4ec16e32532e4e1f6919dad1df3


Malicious Library UPX PE File PE64 OS Processor Check VirusTotal Malware PDB IP Check ComputerName DNS
1 51 1 4.0 M 5 ZeroCERT

9593 2023-10-13 08:41 svchost.exe  

c9abc0932559d7ecced02a9125acea05


Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check VirusTotal Malware unpack itself crashed
1.8 M 13 ZeroCERT

9594 2023-10-13 08:41 owenzx.exe  

47ea784b5aa582da550a12add7ccd74d


PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself DNS
3 3.2 M 47 ZeroCERT

9595 2023-10-13 08:40 stub.exe  

7267c31ceaa3b35c96494360402a4788


Generic Malware Malicious Library UPX Malicious Packer PE File PE64 OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Telegram MachineGuid Windows utilities Tofsee Ransomware Windows Browser Email DNS Software crashed
85 4 6.6 M 10 ZeroCERT

9596 2023-10-13 08:39 ansi.exe  

ca838ae291296ed4c06535f48a35bf32


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself
1.8 M 43 ZeroCERT

9597 2023-10-13 08:36 audiodgse.exe  

6f78ea4133f958f8f064071729a12c3b


PE File PE32 .NET EXE VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.2 M 23 ZeroCERT

9598 2023-10-13 05:58 NMemo1Setp.exe  

f12aa4983f77ed85b3a618f7656807c2


Confuser .NET PE File PE32 .NET EXE VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee Ransomware DNS
3 3 3.8 M 59 guest

9599 2023-10-13 04:24 NMemo1Setp.exe  

f12aa4983f77ed85b3a618f7656807c2


Confuser .NET PE File PE32 .NET EXE VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee Ransomware DNS
3 3 3.8 M 59 guest

9600 2023-10-13 01:05 Password_ps1.txt  

975d7d238a824cf37893450cc62d2b9f


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest