Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9676 2021-07-04 18:14 file.exe  

04ed8e9dea6cc0df1f7366ae15377868


PE File PE32 PDB unpack itself Remote Code Execution
1.6 M ZeroCERT

9677 2021-07-04 18:15 lv.exe  

b0945aff58dda8a00735b6e95a89cad6


NPKI Gen1 Gen2 UPX Malicious Library DGA DNS Socket Create Service Sniff Audio HTTP Escalate priviledges KeyLogger FTP Hijack Network Code injection Http API Internet API Steal credential ScreenShot Downloader P2P persistence AntiDebug AntiVM PE File PE32 VirusTotal Malware Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows DNS
1 7.8 M 44 ZeroCERT

9678 2021-07-04 18:17 ac.exe  

cef1b7bd026c509526f86b30aa1b630c


PWS .NET framework Generic Malware Malicious Packer AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName DNS
3 13.8 M 51 ZeroCERT

9679 2021-07-04 18:17 file9.exe  

7fbd67a4066a92a135ccde4e1d6df413


PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.8 M 47 ZeroCERT

9680 2021-07-04 18:19 servces.exe  

41d1920c3a5744c80f6a61dfe25737b3


PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 20 ZeroCERT

9681 2021-07-04 18:20 file1.exe  

c18df26dba847ee1c67d1080e129f709


Themida Packer PE File .NET EXE PE32 Browser Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Firmware DNS Cryptographic key crashed
2 3 2 10.2 M 45 ZeroCERT

9682 2021-07-04 18:21 proxy-IRXC-setup.exe  

757cf5b6eced6132860dd0f2df643d7f


PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution DNS
1 3.0 M 21 ZeroCERT

9683 2021-07-04 18:22 app.exe  

89e0a36b57563ebf002eda8fd2678374


PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.2 19 ZeroCERT

9684 2021-07-04 18:24 file7.exe  

932957d14a082c94d068b5d810e98aae


Themida Packer Anti_VM PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Checks Bios Detects VMWare Check virtual network interfaces VMware anti-virtualization Windows Firmware Cryptographic key crashed
2 7.0 31 ZeroCERT

9685 2021-07-05 09:04 1.exe  

03b05d8cc99932a1a6e476927be4e70a


PE File PE32 Malware download Malware AutoRuns Malicious Traffic unpack itself human activity check Windows Remote Code Execution Trojan DNS
1 3 2 3.8 ZeroCERT

9686 2021-07-05 09:24 1.exe  

7dd61c6a7e7beed8940474434c750877


PE File PE32 AutoRuns unpack itself human activity check Windows Remote Code Execution DNS
1 1 3.0 M ZeroCERT

9687 2021-07-05 09:33 new order.scr  

23873f7412c1985c6b227e7b0a9f3ae5


Code injection AntiDebug AntiVM PE File PE32 VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW VMware anti-virtualization Windows ComputerName DNS crashed
15.4 3 ZeroCERT

9688 2021-07-05 09:35 loki.exe  

4b6578fc588a11c4388c68cf34fa79cd


PWS .NET framework RAT Generic Malware PE File .NET EXE PE32 JPEG Format Browser Info Stealer Malware download FTP Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI unpack itself Check virtual network interfaces IP Check installed browsers check Browser ComputerName Trojan DNS Software crashed
2 4 5 7.0 ZeroCERT

9689 2021-07-05 09:36 D9975372A070C4965F56D329571CD8...  

d9975372a070c4965f56d329571cd89a


PWS Loki[b] Loki[m] Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware MachineGuid Code Injection Malicious Traffic Check memory buffers extracted unpack itself malicious URLs AntiVM_Disk sandbox evasion VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software crashed
1 2 4 12.2 M 51 ZeroCERT

9690 2021-07-05 09:39 文書名 -scan-1931.xls  

4e7768c1f32cf5da49f21bd81c2939f2


VBA_macro MSOffice File VirusTotal Malware unpack itself DNS
2.2 41 ZeroCERT