Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9721 2023-10-10 10:33 EXX.vbs  

5d8410c20a0349ff3b5a346180455b76


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
3 3 1 8.4 1 ZeroCERT

9722 2023-10-10 10:33 ig5443.txt.exe  

6de05ad93daca1b6caf769826a404975


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Software crashed keylogger
2 4 6.4 54 ZeroCERT

9723 2023-10-10 10:33 Documenti.url  

b4ae0d79ac63532fcf65494e208cb940


AntiDebug AntiVM URL Format MSOffice File VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 1 2 5.8 8 ZeroCERT

9724 2023-10-10 10:31 Cliente.url  

7c1010e02c22a4beea97a9c2ebb53d1e


AntiDebug AntiVM URL Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 1 2 5.4 ZeroCERT

9725 2023-10-10 10:30 cgeahsl8f7.exe  

62099107e7c4a2cf1914ec1fb022db4b


Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself
2.0 56 ZeroCERT

9726 2023-10-10 10:30 ReklamX.ps1  

39aa0004099949044f6e47835101653d


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself Windows Cryptographic key
1.4 15 ZeroCERT

9727 2023-10-10 10:19 bQ2j.exe  

eb5c869423632f5d3fe31cbbe85bfdbc


Malicious Packer Downloader ScreenShot AntiDebug AntiVM PE File PE32 Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check Windows Browser Email ComputerName DNS DDNS keylogger
1 4 3 12.0 64 ZeroCERT

9728 2023-10-10 10:18 bQ1X.exe  

e230cdc004aa4fa4b61f66fbfd701ee5


Malicious Packer Downloader PE File PE32 VirusTotal Malware Windows DNS DDNS keylogger
2 2 4.4 61 ZeroCERT

9729 2023-10-10 10:16 2.txt.ps1  

a7b07e5ad9ef74d393f0b42419e8d2f5


Generic Malware Antivirus VirusTotal Malware unpack itself WriteConsoleW Windows Cryptographic key
1 1.2 4 ZeroCERT

9730 2023-10-10 10:16 1lkc5ccspw.exe  

3d666f1f41826f039ebcc3323647cd48


UPX Malicious Packer PE File PE32 .NET EXE VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself ComputerName DNS
2 1 3.8 58 ZeroCERT

9731 2023-10-10 10:16 Azienda.url  

c4cc624292ec5fcea7fee79f57199683


AntiDebug AntiVM URL Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 1 2 5.4 ZeroCERT

9732 2023-10-10 10:10 Contract-4.msi  

1b6f948f740eb0426204a9b15472b194


Malicious Library MSOffice File CAB OS Processor Check VirusTotal Malware Buffer PE suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces AntiVM_Disk VM Disk Size Check Windows ComputerName
6 4 3 4.8 1 guest

9733 2023-10-10 09:42 archive.7z  

2e47fd847063d35bda81b2ee40f1e37c


Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware download Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself suspicious TLD IP Check PrivateLoader Tofsee Windows DNS
22 24 18 7 6.0 M ZeroCERT

9734 2023-10-10 09:31 Kriwgshughb.exe  

e781b9ebdf07303d9e64f01100a5a2c7


UPX PE File PE64 OS Processor Check VirusTotal Malware Buffer PE Check memory Checks debugger buffers extracted unpack itself
3.4 M 46 ZeroCERT

9735 2023-10-10 08:12 188.exe  

f96c1d0accec84ab6ddca3c0bafc6cbc


Cutwail Malicious Library UPX Http API ScreenShot Escala Malware download VirusTotal Malware Buffer PE MachineGuid Code Injection Malicious Traffic Check memory buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process suspicious TLD sandbox evasion Tofsee Windows Backdoor ComputerName DNS Cryptographic key
212 1124 7 17.0 M 26 ZeroCERT