Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9826 2023-08-02 16:57 j1neaa.bat  

1551e43ba5cc0468ffa4d54d29870ac0


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Sniff Audio HTTP DNS ScreenShot Code injection Internet API FTP KeyLogger AntiDebug AntiVM suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName Cryptographic key
4.0 ZeroCERT

9827 2023-08-02 16:56 Guendengf.exe  

6e5ca3cddbfdd665aa1789800d0963b2


EnigmaProtector UPX Malicious Library Malicious Packer Antivirus OS Processor Check PE File PE32 DLL VirusTotal Malware suspicious privilege Creates executable files sandbox evasion ComputerName
3.0 M 38 ZeroCERT

9828 2023-08-02 16:53 nqwi.vbs  

7b921f547bf78eaeee0b67712518b5a9


Generic Malware Antivirus PowerShell VirusTotal Malware suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName Cryptographic key
5.8 M 16 ZeroCERT

9829 2023-08-02 16:51 nigazxbb.vbs  

d3e7b78476a9e3a9275a26549ff8d845


Generic Malware Antivirus PowerShell powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
4.8 M ZeroCERT

9830 2023-08-02 16:51 update.exe  

5057042b2949c60f1d598845c26a2a18


UPX PE File PE32 VirusTotal Malware Check virtual network interfaces Tofsee
2 3 1 3.0 M 26 ZeroCERT

9831 2023-08-02 16:46 c9f02f547a430b15b6ba7fdafc8850...  

c467fc9aafa3b840fd94d27e697649b8


PhysicalDrive Generic Malware NSIS UPX Malicious Library Malicious Packer Downloader Http API HTTP Code injection Internet API Anti_VM AntiDebug AntiVM PE File PE32 CAB OS Processor Check DLL MSOffice File VirusTotal Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Check virtual network interfaces AppData folder AntiVM_Disk China VM Disk Size Check Interception crashed
3 18 12.6 35 guest

9832 2023-08-02 13:33 C3VB.exe  

a32e1510eaf70c772b81fc4e9f4c46f3


Redline RedLine stealer LokiBot Emotet Generic Malware Downloader UPX WinRAR Malicious Library .NET framework(MSIL) Admin Tool (Sysinternals etc ...) Antivirus PWS Create Service Socket P2P DGA Steal credential Http API Escalate priviledges Sniff Audio HT Browser Info Stealer RedLine FTP Client Info Stealer VirusTotal Malware powershell AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder WriteConsoleW Firewall state off installed browsers check Tofsee Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
2 6 5 1 22.6 M 47 guest

9833 2023-08-02 10:18 asca1ex.exe  

3a59053c06f32e8400c600c3424da34a


UPX Malicious Library Malicious Packer OS Processor Check PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 5 6.2 M 28 ZeroCERT

9834 2023-08-02 10:16 fffffff.exe1  

12e493f7a5f1d8487239d477631457b9


Gozi UPX OS Processor Check PE File PE32 Malware download Cobalt Strike Ursnif VirusTotal Malware Malicious Traffic Check memory unpack itself Interception Windows ComputerName DNS
5 6 2 5 4.6 M 25 ZeroCERT

9835 2023-08-02 10:13 dufs.exe  

20a308e65c20ff7de1f2a1cd047464b5


UPX Malicious Library Malicious Packer OS Processor Check PE File PE32 VirusTotal Malware Check virtual network interfaces WriteConsoleW
1.4 M 3 ZeroCERT

9836 2023-08-02 10:11 taskhostclp.exe  

3258deefff3ca70f3dfa3e67067ca611


UPX MPRESS PE64 PE File VirusTotal Malware Remote Code Execution crashed
2.4 M 37 ZeroCERT

9837 2023-08-02 10:09 Invoice.vbs  

0a480ee9046d242cbd66e5865dabdec3


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 8.0 M 6 ZeroCERT

9838 2023-08-02 10:07 000000000000%23%23%23%23%23%23...  

44d2677ca322541c52dd751454873340


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
1 2 5 4.6 M 30 ZeroCERT

9839 2023-08-02 10:07 setup.dll  

f799870809fc731deadbf22963fc79e7


Malicious Library DLL PE64 PE File VirusTotal Malware Checks debugger unpack itself DNS
1 3.8 M 19 ZeroCERT

9840 2023-08-02 10:05 wininit.exe  

00b0d25748447094c22e11aaa1f8d0a0


UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates executable files unpack itself AppData folder Windows crashed
3.4 M 32 ZeroCERT