Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9736 2023-10-10 07:49 netTimer.exe  

5e355722e1e969c504c4fe59591ec4ce


UPX Malicious Packer PE File PE64 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself anti-virtualization ComputerName DNS
31 5.4 M 32 ZeroCERT

9737 2023-10-10 07:46 windows.exe  

edc44d75d9e3205cbd90be3d8352f504


Malicious Library UPX Malicious Packer Antivirus .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check VirusTotal Malware Check memory Checks debugger unpack itself DNS
1 2.6 M 56 ZeroCERT

9738 2023-10-10 07:46 kung.exe  

20f562d14af01da92b246896e45e9459


LokiBot Socket PWS DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs suspicious TLD installed browsers check Browser Email ComputerName DNS Software
1 2 9 14.6 43 ZeroCERT

9739 2023-10-10 07:44 1712.exe  

0e0b669d90c80cea6398e81d139d7d29


task schedule KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Malware download AsyncRAT NetWireRC VirusTotal Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities WriteConsoleW Windows ComputerName DNS Cryptographic key
53 3 12.4 49 ZeroCERT

9740 2023-10-10 07:43 udat1.exe  

243b6e0960e9d3b63d924ba0c2b8a6fd


UPX PE File PE64 OS Processor Check VirusTotal Malware unpack itself crashed
2.0 21 ZeroCERT

9741 2023-10-10 07:40 audiodgs.exe  

7a9336c2f3ed97231960fc993881c6ad


Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 4 14.8 M 22 ZeroCERT

9742 2023-10-10 07:40 shekinga2.1.exe  

4018b3beefce0db09ca018c8d99262e3


NSIS Malicious Library UPX PE File PE32 OS Processor Check Remcos VirusTotal Malware AutoRuns Malicious Traffic Check memory Creates executable files unpack itself AppData folder Windows DNS DDNS
1 4 2 5.6 M 27 ZeroCERT

9743 2023-10-10 02:05 gate9_pass1234.7z  

fb744c58353b153a548fd04fd959b232


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.4 M ticklesc

9744 2023-10-09 17:59 http://192.168.8.1  


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 5.8 guest

9745 2023-10-09 13:23 helpscientistpro.exe  

f54931aaae6cff496f607d6991cc1437


Gen1 Emotet Malicious Library UPX Http API ScreenShot PWS Internet API AntiDebug AntiVM PE File PE64 CAB Browser Info Stealer Malware download Malware Cryptocurrency wallets Cryptocurrency Buffer PE AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Check virtual network interfaces suspicious TLD sandbox evasion Ransomware Lumma Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key
3 3 5 1 15.0 M ZeroCERT

9746 2023-10-09 13:21 cutarise.exe  

71c3e327a97a8836a70a129d1c547670


PE File PE32 .NET EXE VirusTotal Malware Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
1 2 1 2.4 45 ZeroCERT

9747 2023-10-09 13:20 differentdatabase.exe  

3f0ca10225ca292ea31be0d292dcfb70


UPX .NET framework(MSIL) ScreenShot PWS AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check Malware Buffer PE AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows DNS Cryptographic key
1 1 1 10.4 M ZeroCERT

9748 2023-10-09 13:20 discoversophisticatedpro.exe  

79de5ff2273d613a14ca4c8edff7d5ec


Gen1 Emotet Generic Malware Malicious Library UPX .NET framework(MSIL) Http API ScreenShot Internet API AntiDebug AntiVM PE File PE64 CAB PE32 .NET EXE OS Processor Check Malware download Malware Buffer PE AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Check virtual network interfaces AppData folder Lumma Stealer Windows Remote Code Execution DNS Cryptographic key crashed
3 3 1 2 13.6 M ZeroCERT

9749 2023-10-09 13:19 helpscientistpro.exe  

f54931aaae6cff496f607d6991cc1437


Gen1 Emotet Malicious Library UPX .NET framework(MSIL) PE File PE64 CAB PE32 .NET EXE OS Processor Check Malware Buffer PE AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Check virtual network interfaces AppData folder Windows Remote Code Execution DNS Cryptographic key
2 1 1 2 11.0 M ZeroCERT

9750 2023-10-09 13:19 lastsciiencepro.exe  

81d34d81c4b40ba209760c61baaad458


Gen1 Emotet Malicious Library UPX .NET framework(MSIL) Http API ScreenShot PWS Internet API AntiDebug AntiVM PE File PE64 CAB PE32 .NET EXE OS Processor Check Malware download VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Check virtual network interfaces AppData folder Lumma Stealer Windows Remote Code Execution DNS Cryptographic key crashed
3 3 1 1 14.6 M 19 ZeroCERT