Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9901 2021-07-12 09:50 f5aacf8c46f43d01d08fa79d2d72cf...  

64976dbee1d73fb7765cbec2b3612acc


Gen1 Gen2 Generic Malware PE File PE32 OS Processor Check DLL VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself AppData folder sandbox evasion IP Check ComputerName
3 7 2 7.6 M 40 ZeroCERT

9902 2021-07-12 09:52 bat_update.exe  

bbf3c7740a3507b482260efa0b4c4a82


Gen1 PE File PE32 JPEG Format DLL OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency suspicious privilege MachineGuid Malicious Traffic Check memory WMI Creates executable files unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare suspicious process AppData folder sandbox evasion WriteConsoleW VMware anti-virtualization installed browsers check Windows Update Browser Email ComputerName Firmware DNS Software crashed
10 3 2 15.8 M 33 ZeroCERT

9903 2021-07-12 09:53 bat_english.exe  

2e666d262882b4262701b63378d44cb2


Gen1 PE File PE32 JPEG Format DLL OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency suspicious privilege MachineGuid Malicious Traffic Check memory WMI Creates executable files unpack itself Windows utilities Checks Bios Collect installed applications Detects VirtualBox Detects VMWare suspicious process AppData folder sandbox evasion WriteConsoleW VMware anti-virtualization installed browsers check Windows Browser Email ComputerName Firmware DNS Software crashed
10 3 2 16.6 M 48 ZeroCERT

9904 2021-07-12 09:53 allocate.dot  

c7810b25c8edd6269c92af482560e600


VBA_macro MSOffice File VirusTotal Malware unpack itself
2.2 20 ZeroCERT

9905 2021-07-12 09:54 mixx.exe  

aac724c619e3d7826c2b5688d23f0947


PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 27 ZeroCERT

9906 2021-07-12 09:56 dexploer.exe  

d4602d1663b6b8b5dea53a0ef463eaf6


PE File PE32 VirusTotal Malware Check virtual network interfaces DNS
3 2.2 48 ZeroCERT

9907 2021-07-12 10:03 M0071.cab  

f26a05a36ff69e67a17144c7d75fd36b

ZeroCERT

9908 2021-07-12 10:04 index.php.html  

97034187ab9def80518c895abf06350f


AntiDebug AntiVM JPEG Format PNG Format MSOffice File Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
33 8 4.6 ZeroCERT

9909 2021-07-12 10:08 SC_hack.exe  

8d963f6419d21ded2f29c17091107438


PWS .NET framework RAT Generic Malware Themida Packer Process Kill Malicious Library Admin Tool (Sysinternals etc ...) UPX FindFirstVolume CryptGenKey PE File PE32 .NET EXE OS Processor Check PE64 Device_File_Check DLL GIF Format VirusTotal Malware AutoRuns Check memory Checks debugger Creates shortcut Creates executable files unpack itself Check virtual network interfaces AppData folder AntiVM_Disk VM Disk Size Check human activity check Windows ComputerName DNS Cryptographic key crashed
1 8.2 36 ZeroCERT

9910 2021-07-12 10:31 dexploer.exe  

d4602d1663b6b8b5dea53a0ef463eaf6


IAmTheKing Family Malicious Library PE File PE32 VirusTotal Malware Check virtual network interfaces
2 1.6 48 r0d

9911 2021-07-12 10:31 app.dll  

0bb29556ece1c51c751cb4e7c8752ddc


Generic Malware PE File PE32 DLL OS Processor Check VirusTotal Malware PDB MachineGuid unpack itself ComputerName crashed
2.0 23 ZeroCERT

9912 2021-07-12 11:19 mixx.exe  

aac724c619e3d7826c2b5688d23f0947


RedLine Stealer PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 27 r0d

9913 2021-07-12 11:21 mixx.exe  

aac724c619e3d7826c2b5688d23f0947


RedLine Stealer PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 27 r0d

9914 2021-07-12 13:31 0071801_002710.js  

3ed273cac81d6427c6682d8893bd43c2

VirusTotal Malware VBScript wscript.exe payload download Dropper
1 1 10.0 42 ZeroCERT

9915 2021-07-12 13:32 app.exe  

7b7bcf7dc5d1f4d0ea8f9c5d6a1b5868


PWS .NET framework Generic Malware Antivirus PDF PE64 PE File .NET EXE PE32 VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities suspicious process AppData folder sandbox evasion Windows ComputerName Cryptographic key
10.6 37 ZeroCERT