Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10171 2021-07-17 11:13 file.exe  

29c88b0a1cee4b9b0decdaf213f4daa4


UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.2 M 28 ZeroCERT

10172 2021-07-17 11:16 XKL.exe  

7abab65f41193a9b02bbd3ca73fb2e75


Generic Malware UPX Malicious Packer DNS AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
4 1 14.0 M 25 ZeroCERT

10173 2021-07-17 11:18 741.exe  

4e92b2862f02f6c48ec1ce2aa572608a


PWS .NET framework RAT Generic Malware Http API Steal credential ScreenShot AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Tofsee Windows DNS Cryptographic key
3 2 7.2 M 40 ZeroCERT

10174 2021-07-17 17:19 7vLHRD4IdanbLrE.exe  

87252a7dc3e57b82a34f1d27041e5ed9


Generic Malware UPX Malicious Packer SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 4 12.6 27 ZeroCERT

10175 2021-07-17 17:29 lfg.js  

e99572ebcd8e03f5ce5cf5f668fc6392

VirusTotal Malware
0.6 16 ZeroCERT

10176 2021-07-17 17:45 taskwhost.exe  

9137c99b88b701fc6315c36c67bb7b05


PWS .NET framework RAT Generic Malware UPX Malicious Packer PE File PE32 .NET EXE VirusTotal Malware WriteConsoleW IP Check ComputerName DNS
1 3 1 3.0 M 48 ZeroCERT

10177 2021-07-17 17:46 Coxes.txt.ps1  

78dc292e97eec769aeadf6c8f7fa0ffd


Antivirus Malware powershell Malicious Traffic Check memory buffers extracted WMI Creates executable files unpack itself Check virtual network interfaces WriteConsoleW Tofsee Windows ComputerName Cryptographic key
8 1 7.2 M ZeroCERT

10178 2021-07-17 17:47 frick.exe  

43626a85bb97021a92641920e305bff8


RAT Generic Malware PE File PE32 .NET EXE VirusTotal Malware AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
1 2 9.2 M 51 ZeroCERT

10179 2021-07-17 17:48 script.js  

fae487c888507f108026c1a899274f9f

crashed
0.2 ZeroCERT

10180 2021-07-17 17:50 dhs-01.exe  

8345bbcf93e9f04e6a11a8b4e9319e08


PWS .NET framework RAT Generic Malware Admin Tool (Sysinternals etc ...) AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows DNS Cryptographic key
5 12 1 4 11.2 M 28 ZeroCERT

10181 2021-07-17 17:51 1.txt.ps1  

cfc196748b5651b5ea6815fefa7aa523


Anti_VM Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.4 M 1 ZeroCERT

10182 2021-07-17 17:55 SC_hack.exe  

8d963f6419d21ded2f29c17091107438


PWS .NET framework RAT Generic Malware Themida Packer Process Kill Malicious Library UPX Admin Tool (Sysinternals etc ...) FindFirstVolume CryptGenKey PE File PE32 OS Processor Check .NET EXE PE64 GIF Format Device_File_Check DLL VirusTotal Malware AutoRuns Check memory Checks debugger Creates shortcut Creates executable files unpack itself Check virtual network interfaces AppData folder human activity check Windows ComputerName DNS Cryptographic key crashed
1 7.8 36 ZeroCERT

10183 2021-07-17 18:07 hola.doc  

843f6c0c24bfc31b6a19471935a092da


AntiDebug AntiVM VirusTotal Malware Code Injection Check memory RWX flags setting unpack itself suspicious process Interception
2 6.8 24 ZeroCERT

10184 2021-07-18 09:08 s_upd.exe  

42a2e7ec25ef66f210da4b986646f87f


UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.2 M 23 ZeroCERT

10185 2021-07-18 09:08 pl_installer.exe  

f82eb7edf5fcdd8c99cf9e1f1dcb0485


UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.2 M 26 ZeroCERT