Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
991 2024-09-24 13:23 ufw.exe  

6b4b9ced2c07fb6c8eb710e0b1f2c4cf


RedLine stealer Antivirus PWS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself DNS
1 8.6 M 54 ZeroCERT

992 2024-09-24 13:21 lgrn.exe  

94c5abd0eccd77846b4e0f641906bb19


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 55 ZeroCERT

993 2024-09-24 13:20 lgfjd.exe  

da06c340e4f32ce73c4a1aa4c3e1906d


Antivirus ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.4 M 56 ZeroCERT

994 2024-09-24 13:19 otra.exe  

65baa89a777d2177397a4e6d844cdadb


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself ComputerName Remote Code Execution
3.0 M 17 ZeroCERT

995 2024-09-24 13:18 66f16f7e683b4_Trippers.exe  

ae200d6beebb4cfcc2c10f8a07f97998


ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.2 M 39 ZeroCERT

996 2024-09-24 13:15 1.txt.ps1  

4a9fa455783eb4455c279a0a5e738bd6


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.4 8 ZeroCERT

997 2024-09-24 11:15 66f18a5501651_ww_a.exe  

221942540e2630630887a7b59a855ec2


Gen1 Generic Malware Malicious Library .NET framework(MSIL) UPX Malicious Packer PWS Anti_VM AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check DLL PE64 ftp DllRegisterServer dll ZIP Format Browser Info Stealer Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself malicious URLs IP Check Tofsee Ransomware Windows Browser ComputerName Remote Code Execution DNS crashed Downloader
6 13 13 15.6 M 19 ZeroCERT

998 2024-09-24 11:09 66f1aed72de87_crypted.exe#1  

ca91eecc39a0e55259001edf9a6f52fd


ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself
7.0 M 29 ZeroCERT

999 2024-09-24 11:08 wsd.exe  

f1a4608262276d12a77a5db012189fa6


Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE File PE64 OS Processor Check DLL ZIP Format VirusTotal Malware Check memory Checks debugger Creates executable files
2.0 M 23 ZeroCERT

1000 2024-09-24 11:08 66f18e5598f87_kaloa.exe  

712d466cf9f8e982f18eb3355131e5c0


Malicious Library .NET framework(MSIL) UPX PE File .NET EXE PE32 OS Processor Check VirusTotal Malware PDB suspicious privilege Check memory Checks debugger unpack itself ComputerName
3.0 M 24 ZeroCERT

1001 2024-09-24 11:07 key.exe  

4cdc368d9d4685c5800293f68703c3d0


Malicious Library UPX PE File ftp PE32 OS Processor Check PDB crashed
0.8 M ZeroCERT

1002 2024-09-24 11:05 66f19da1b85de_cryotr.exe#kisot...  

8f13e73a3c7d22ee7c1730cf8821f7ac


Generic Malware Malicious Library UPX PE File PE32 ftp OS Processor Check VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName
6.6 M 22 ZeroCERT

1003 2024-09-24 11:04 66f1b3d23ffe5_lyla1.exe  

34e07317817ca03f5eb4566851fe0cf3


Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware unpack itself Remote Code Execution
1.8 M 29 ZeroCERT

1004 2024-09-24 11:02 asegurar.vbs  

4a31a1de3d99c80d908ddda051e2f761


Generic Malware Antivirus Hide_URL VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 7.6 M 4 ZeroCERT

1005 2024-09-24 11:02 invoicesss.lnk  

f5a8227c071b79abce0748f0a65de2f8


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format PowerShell VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut RWX flags setting unpack itself powershell.exe wrote suspicious process WriteConsoleW Interception Windows ComputerName DNS Cryptographic key
1 1 10.0 23 ZeroCERT