Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
9991 2023-07-26 13:25 IDBh.hta  

42add60c5e71accdfbb0a16bd34515ae


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key
1 7.0 5 ZeroCERT

9992 2023-07-26 11:41 CMSh.hta  

d73b4775abeed46e879675ddd0d311d2


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key
1 7.2 14 ZeroCERT

9993 2023-07-26 11:23 File_pass1234.7z  

dd48d433b225a68e26ca5b6446f0e5f9


Escalate priviledges PWS KeyLogger AntiDebug AntiVM suspicious privilege Check memory Checks debugger unpack itself
1.6 M ZeroCERT

9994 2023-07-26 09:44 vbcript.vbs  

75281ab6ea5a12725d427b34accd2325


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 8.2 M 11 ZeroCERT

9995 2023-07-26 09:41 setup-rc18.exe  

c7feee4698e4d22fead87c243d9cb8ad


UPX PE64 PE File VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself crashed
3.2 M 35 ZeroCERT

9996 2023-07-26 09:39 system32.vbs  

08548ae48deaeeb8bb880d74ccaf9707


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 2 1 7.6 M 2 ZeroCERT

9997 2023-07-26 09:39 ohoyeczx.doc  

51dfac37926ca4687d0a84dd43f491ce


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
1 2 5 4.4 M 28 ZeroCERT

9998 2023-07-26 08:09 secdukaszx.doc  

b3da431b3d8c5c8680024b81ce71bd85


MS_RTF_Obfuscation_Objects RTF File doc Malware download Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
13 14 5 4.0 M ZeroCERT

9999 2023-07-26 08:08 wininit.exe  

99566b51018706a1b36b1440dc9b9d23


Formbook .NET framework(MSIL) AntiDebug AntiVM .NET EXE PE File PE32 Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself DNS
14 13 2 12 8.8 M ZeroCERT

10000 2023-07-26 08:02 IDBHIDBHIDBHIDBHIDBHIDBH%23%23...  

454cb83cf56a83f08d9506a7de9e475a


MS_RTF_Obfuscation_Objects RTF File doc Vulnerability Malware Malicious Traffic exploit crash unpack itself Exploit DNS crashed
1 1 3 3.2 M ZeroCERT

10001 2023-07-26 08:00 no_halt_7891.msi  

394f500a708c457b2a5eb4e839896c22


Malicious Library OS Processor Check CAB MSOffice File VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself AntiVM_Disk VM Disk Size Check ComputerName DNS
1 4.4 M 8 ZeroCERT

10002 2023-07-26 07:58 secdukaszx.exe  

410dec2d786b542c67397ab8cc7ecaf3


.NET framework(MSIL) AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself
12 13 9.0 M 19 ZeroCERT

10003 2023-07-26 07:58 IBMCENTOSIBMCENTOSIBMCENTOSIBM...  

2d691029ea7c7963db78038eab462842


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic RWX flags setting exploit crash Tofsee Exploit DNS crashed
1 4 2 4.2 30 ZeroCERT

10004 2023-07-26 07:58 BBCGBBCGBBCGBBCGBBCGCBBCGBBCGB...  

434a56206f1cda6955268658efeb1db3


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic exploit crash unpack itself Tofsee Exploit DNS crashed
1 3 2 4.2 30 ZeroCERT

10005 2023-07-26 07:56 file.exe  

7c18df4a1aab5314b4a499c3e84f055c


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself
1.6 M 27 ZeroCERT