Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10231 2023-07-18 07:33 IDBKIIDBKIDIBDKIDIBKIDIBKIDIBK...  

df4bd2b1d9372a42167da3e6c16d451c


MS_RTF_Obfuscation_Objects RTF File doc Vulnerability VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 1 3 4.6 32 ZeroCERT

10232 2023-07-18 07:31 rxtygf.exe  

ad607f046a6f855f06d0e7b2cab189c1


.NET framework(MSIL) Admin Tool (Sysinternals etc ...) Malicious Library Http API Escalate priviledges HTTP Internet API AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic unpack itself Windows utilities suspicious process malicious URLs AntiVM_Disk WriteConsoleW VMware Ransom Message IP Check VM Disk Size Check Tofsee Ransomware Windows Browser Tor ComputerName Cryptographic key
3 4 2 1 18.0 26 ZeroCERT

10233 2023-07-18 07:28 wwwtwwwrwwewwwrwwwewwwtwwwy%23...  

2e09089eee318e853c221beded5376e1


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself IP Check Tofsee Windows Exploit DNS crashed
1 4 7 4.6 30 ZeroCERT

10234 2023-07-18 07:28 an.exe  

10e841b7d0bff1a7aa989ebdf7f35976


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware RWX flags setting unpack itself DNS crashed
1 2.4 22 ZeroCERT

10235 2023-07-18 07:28 csrssfs.exe  

2bdd38681778a2be9d40177c6f8a3319


NSIS UPX Malicious Library PE File PE32 DLL FormBook Malware download VirusTotal Malware suspicious privilege Malicious Traffic Check memory Creates executable files ICMP traffic unpack itself AppData folder DNS
23 23 3 5.8 43 ZeroCERT

10236 2023-07-18 07:24 foto135.exe  

327b57745b8c136ea8d4e4e1519f508d


Gen1 Emotet RedLine Infostealer RedLine stealer UPX Malicious Library .NET framework(MSIL) Confuser .NET Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check .NET EXE DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger WMI Creates executable files RWX flags setting unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Kelihos Stealer Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed Downloader
9 3 14 3 17.8 42 ZeroCERT

10237 2023-07-18 07:24 NBbH87.exe  

e8a59b068f08284eb4159afadb10110e


LokiBot RedLine Infostealer UltraVNC UPX Malicious Library PWS DNS AntiDebug AntiVM OS Processor Check PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName DNS Cryptographic key Software crashed
1 1 7 13.8 49 ZeroCERT

10238 2023-07-18 07:24 file.exe  

a8dcd1088cd200430129217d92db5f37


Malicious Library PE File PE32 VirusTotal Malware PDB
2.2 47 ZeroCERT

10239 2023-07-18 07:23 rofl.exe  

2ee4b1df29fe85c016c84d5855b0ec9f


UPX Malicious Library ScreenShot AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Buffer PE PDB Code Injection buffers extracted WMI RWX flags setting unpack itself ComputerName crashed
9.4 38 ZeroCERT

10240 2023-07-18 07:23 repack.exe  

d072480d939a819969bab643d14dbab8


UPX Malicious Library Malicious Packer OS Processor Check PE64 PE File VirusTotal Malware AutoRuns Windows
3.0 44 ZeroCERT

10241 2023-07-18 07:21 fotod25.exe  

74b51238ceac125ca090efeb2b3bce46


Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
6 2 10 3 16.6 44 ZeroCERT

10242 2023-07-17 16:49 main.exe  

c66ec2c36b8a47ae1b81ea9576519478


Gen1 Emotet Generic Malware UPX Malicious Library ASPack Admin Tool (Sysinternals etc ...) Anti_VM OS Processor Check PE64 PE File DLL ZIP Format VirusTotal Malware Check memory Checks debugger Creates executable files unpack itself
2.8 35 ZeroCERT

10243 2023-07-17 16:47 jawazx.exe  

a15da9fdfd935a4b05adc5e0cf0053a0


NSIS UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
3.0 13 ZeroCERT

10244 2023-07-17 16:46 build.exe  

eabf49a55264bcc12f51bd2710718d3d


Malicious Library PE File PE32 VirusTotal Malware PDB
2.2 M 51 ZeroCERT

10245 2023-07-17 16:44 2E0ECB2F.Png.msi  

f725bab929df4fe2626849ba269b7fcb


Malicious Library CAB MSOffice File suspicious privilege Check memory Checks debugger unpack itself AntiVM_Disk VM Disk Size Check ComputerName
1.8 M ZeroCERT