Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10066 2023-07-24 16:56 IE_NET.vbs  

cb32044962932d0d581cd6fdb72d6a3b


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 2 9.2 3 ZeroCERT

10067 2023-07-24 16:56 IBNSDIFBSDNIWEFBSIFNFSIDFBISDN...  

f6abfd2fa1bf65db8d73e3c3ed3c76a5


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted RWX flags setting exploit crash Exploit DNS crashed
2 3 1 4.6 M 30 ZeroCERT

10068 2023-07-24 16:30 FreeWMAToMP3Converter.exe  

b4d654755e5fb496138ed0e9c4121e84


Emotet Gen1 UPX Malicious Library Malicious Packer AntiDebug AntiVM MZP Format PE File PE32 MSOffice File PNG Format DLL PE64 GIF Format OS Processor Check JPEG Format Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting exploit crash unpack itself Windows utilities AppData folder AntiVM_Disk VM Disk Size Check Tofsee Windows Exploit ComputerName DNS crashed
1 2 2 7.0 Speedmeup

10069 2023-07-24 13:20 "https://tglrrran.0rg.shop/"  


AntiDebug AntiVM MSOffice File PNG Format JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 2 3.8 ZeroCenter

10070 2023-07-24 09:33 kgec63hr0ubmn.exe  

79982cf6836eebddfc2aa3e773f54f38


Generic Malware UPX Malicious Library Antivirus AntiDebug AntiVM OS Processor Check PE File PE32 PowerShell VirusTotal Malware Microsoft Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself suspicious process WriteConsoleW IP Check Tofsee Windows ComputerName DNS Cryptographic key crashed
5 10 3 14.4 30 ZeroCERT

10071 2023-07-24 09:32 setup294.exe  

ea7a66c1eaf1ddaca7ad98a7b8490099


UPX Malicious Library Create Service Escalate priviledges AntiDebug AntiVM OS Processor Check PE File PE32 DLL PDB Code Injection unpack itself AppData folder Remote Code Execution DNS
1 3.0 ZeroCERT

10072 2023-07-24 09:13 install-alevrola.exe  

8d6d682cbd51a88075c184966aa0de17


Generic Malware Malicious Library UPX PE File PE32 PNG Format MZP Format GIF Format AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check Windows ComputerName Remote Code Execution DNS
8 2 3.8 guest

10073 2023-07-24 09:12 install-alevrola.exe  

8d6d682cbd51a88075c184966aa0de17


Generic Malware Malicious Library UPX PE File PE32 GIF Format PNG Format MZP Format VirusTotal Malware AutoRuns Check memory Creates shortcut Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check Windows ComputerName
4.4 57 guest

10074 2023-07-24 09:06 File_pass1234.7z  

4d25d513d85869b1c08713a0f9c11718


Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Cryptocurrency Miner Malware Cryptocurrency Microsoft suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself IP Check PrivateLoader Tofsee Fabookie Stealer Windows Remote Code Execution Trojan DNS Downloader
28 69 31 12 7.0 M ZeroCERT

10075 2023-07-24 07:42 photo170.exe  

65c0aab9f3cc5187b6d90b66fc734abc


Gen1 Emotet RedLine Infostealer RedLine stealer UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer .NET framework(MSIL) Confuser .NET CAB PE File PE32 OS Processor Check DLL PE64 .NET EXE Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Kelihos Tofsee Stealer Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed Downloader
6 6 18 6 18.4 M ZeroCERT

10076 2023-07-24 07:39 file.exe  

a931716cf0d4b79b442699547acce00a


UPX Malicious Library OS Processor Check PE File PE32 unpack itself
0.8 M ZeroCERT

10077 2023-07-24 07:39 taskmask.exe  

126db18bbcf58a186b422970c57e4dbf


Emotet UPX Admin Tool (Sysinternals etc ...) Malicious Library PWS SMTP AntiDebug AntiVM OS Processor Check .NET EXE PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Collect installed applications Check virtual network interfaces installed browsers check Tofsee Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 3 2 13.6 50 ZeroCERT

10078 2023-07-24 07:37 file.exe  

8fa8bfb9b75a7c33d9d8cc65a7172a7c


UPX Malicious Library OS Processor Check PE File PE32 unpack itself
0.8 M ZeroCERT

10079 2023-07-24 05:09 IMG-20230723-WA0017.jpg  

3bdfda87698750389aa90c72652c25bf


JPEG Format
guest

10080 2023-07-23 13:33 ROOTROOTROOOTROOOTROTROOTROT%2...  

1e2437d520b6cf1964cd8146261ab344


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware VBScript Malicious Traffic buffers extracted exploit crash unpack itself Tofsee Exploit DNS crashed
1 3 2 1 4.6 M 34 guest