Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10351 2021-07-22 11:03 lv.exe  

de9a1e3fbb72d4a01fabee53230f2017


Gen1 Gen2 UPX Malicious Packer PE32 PE File DLL OS Processor Check VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.6 M 37 ZeroCERT

10352 2021-07-22 11:03 Invoice_657894.xls  

bd59e42a9ee00ba415448c31190e57d7


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself suspicious process Windows
2 1 3.6 M 16 ZeroCERT

10353 2021-07-22 11:05 Invoice_9429770.xls  

8e3797b1d0fbf7becdd633bc0635ba71


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself suspicious process Windows
1 2 1 3.0 17 ZeroCERT

10354 2021-07-22 11:06 Invoice_37416487.xls  

c5bc7b7069bee39283ffe9a974de6600


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself suspicious process Windows
2 1 3.6 M 15 ZeroCERT

10355 2021-07-22 11:07 Kbf2P.png  

45d9d9c13a4b2f77a5635a64cd58bd03


Dridex PE32 DLL PE File VirusTotal Malware
1.0 16 ZeroCERT

10356 2021-07-22 11:07 Invoice_78814340.xls  

5d7e91a055573a70c596b58c5c7506d9


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself suspicious process Windows
1 2 1 1 3.0 M 18 ZeroCERT

10357 2021-07-22 11:07 avaron1.exe  

1f9033906c2c884ad7125d2392793ff7


PWS Loki[b] Loki[m] .NET framework Generic Malware Malicious Packer UPX DNS Socket AntiDebug AntiVM PE32 .NET EXE PE File Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW installed browsers check Windows Browser Email ComputerName DNS Software crashed
1 1 6 1 16.4 M 39 ZeroCERT

10358 2021-07-22 11:09 Invoice_9255471.xls  

556daf1119d264ba2732fee95b65ea70


VBA_macro MSOffice File VirusTotal Malware unpack itself
1.0 M 16 ZeroCERT

10359 2021-07-22 11:10 vbc.exe  

f223962d913a5a81a1e8ede9f2751d1b


PWS .NET framework RAT Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE32 OS Processor Check .NET EXE PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 3 13.0 M 44 ZeroCERT

10360 2021-07-22 11:11 Invoice_730621.xls  

15d1252024d046b76737f80017b31b5e


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files RWX flags setting unpack itself suspicious process Windows
2 2 1 1 3.4 M 15 ZeroCERT

10361 2021-07-22 11:11 Invoice_902620.xls  

f70346d437f79aed8085934da8051603


Dridex VBA_macro MSOffice File PE32 DLL PE File VirusTotal Malware Check memory buffers extracted Creates executable files unpack itself suspicious process Windows
2 1 3.0 M 15 ZeroCERT

10362 2021-07-22 11:11 MfbNKrx.png  

aae1e725e2dbfd91213be22e857f9d02


Dridex PE32 DLL PE File
0.4 M ZeroCERT

10363 2021-07-22 11:12 main.exe  

60bb544289cfeb878cf212268ad90d9b


Ave Maria WARZONE RAT NPKI Malicious Packer UPX Antivirus PE32 OS Processor Check PE File Browser Info Stealer Email Client Info Stealer powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself powershell.exe wrote suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName Remote Code Execution DNS Cryptographic key DDNS
3 1 10.6 M ZeroCERT

10364 2021-07-22 11:13 a.exe  

cf53febec7e1376c2e42b3857ab25424


PE32 PE File Browser Info Stealer VirusTotal Malware PDB Browser Remote Code Execution
2.0 46 ZeroCERT

10365 2021-07-22 11:13 file.exe  

7671047a15b52a9c82fab0b123d38504


UPX PE32 PE File VirusTotal Malware PDB unpack itself
2.4 M 30 ZeroCERT