Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10051 2023-09-28 08:37 dyke.txt.exe  

5b3c222b7554df5dd2dfe06f4ac288e8


Malicious Library UPX Malicious Packer PE File PE32 .NET EXE Browser Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger unpack itself Windows Browser Email ComputerName crashed
5.0 56 ZeroCERT

10052 2023-09-28 08:27 imolight2.1.exe  

56a626b9244c18ac768b5d3db7e014ed


NSIS Malicious Library UPX Anti_VM PE File PE32 OS Processor Check VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder human activity check Windows ComputerName DNS
1 10.2 49 ZeroCERT

10053 2023-09-28 08:26 unqgl.txt.exe  

af158ce8c4950113f3886aa922725b50


Malicious Packer PE File PE32 .NET EXE
ZeroCERT

10054 2023-09-28 03:01 Szun-ce - A háború művészete.p...  

7fcb7c5a54d6e7aeee4f3c4cc80c7cb0


PDF
guest

10055 2023-09-27 18:45 gate9_pass1234.7z  

fb744c58353b153a548fd04fd959b232


PrivateLoader Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Malware Microsoft suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Stealc Stealer Windows Browser RisePro Trojan DNS Downloader
44 89 41 22 7.8 M ZeroCERT

10056 2023-09-27 17:39 asca1ex.exe  

bf58b6afac98febc716a85be5b8e9d9e


Malicious Library PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Microsoft suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 4 6.4 M 57 ZeroCERT

10057 2023-09-27 17:36 rh111.exe  

1b87684768db892932be3f0661c54251


UPX .NET framework(MSIL) PE File PE32 .NET EXE OS Processor Check FlawedAmmyy VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.2 50 ZeroCERT

10058 2023-09-27 17:34 rh_0.4.9rc1123.exe  

1cf749dd7209e826e36d8ece08aa6a7a


Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware WMI RWX flags setting unpack itself ComputerName crashed
4.2 M 61 ZeroCERT

10059 2023-09-27 17:34 clean.exe  

9fa10337d494e4b832b790bd53352fc4


Gen1 Emotet Malicious Library UPX PE File PE32 CAB VirusTotal Malware unpack itself AntiVM_Disk VM Disk Size Check Remote Code Execution crashed
2.0 4 ZeroCERT

10060 2023-09-27 16:26 Hu.pdf  

59f3ad81657e7bf282b2f89f6f238185


PDF Suspicious Link PDF
1 guest

10061 2023-09-27 14:42 ff2177c078dfed4b10a0214acefabf...  

4df9fa7cef7bd7e19456e219b135ae69


Malicious Library UPX .NET framework(MSIL) Socket ScreenShot Steal credential DNS AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check Browser Info Stealer Malware download VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Collect installed applications malicious URLs AntiVM_Disk sandbox evasion anti-virtualization IP Check VM Disk Size Check installed browsers check Tofsee Ransomware Browser RisePro Email ComputerName DNS
1 5 6 14.8 31 ZeroCERT

10062 2023-09-27 14:25 GXQ.pdf.lnk  

a86dd3a01720be4344548792139aa419


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Malware Code Injection Malicious Traffic Creates shortcut unpack itself suspicious process WriteConsoleW DNS crashed
1 1 2 4.0 ZeroCERT

10063 2023-09-27 14:25 UTA.pdf.lnk  

1bce56d959ee53f48cc0cced5acbfa2c


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Malware Code Injection Malicious Traffic Check memory Creates shortcut unpack itself suspicious process WriteConsoleW DNS crashed
1 1 2 4.2 ZeroCERT

10064 2023-09-27 14:24 OT.pdf.lnk  

220870fa38f822a0403218114a08b31d


Generic Malware AntiDebug AntiVM Lnk Format GIF Format Code Injection Creates shortcut ICMP traffic suspicious process WriteConsoleW DNS
1 1 4.4 ZeroCERT

10065 2023-09-27 13:33 documentblur.exe  

5fac40a82226f46504aef22f79233ad7


XWorm WebCam KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process AntiVM_Disk VM Disk Size Check Windows ComputerName Cryptographic key keylogger
11.4 M 50 r0d