Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10441 2021-07-23 10:13 3.txt  

83be60383dbe5cd4e9b29cdfedab74eb


Antivirus Malicious Packer VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 9.2 M 1 ZeroCERT

10442 2021-07-23 10:41 Fbck.jpg  

ee991f2813337a82a3329f3e84b4c184


Antivirus AntiDebug AntiVM VirusTotal Malware Code Injection Check memory buffers extracted unpack itself WriteConsoleW
7.2 M 2 ZeroCERT

10443 2021-07-23 11:24 Encoding.txt.html  

9849195d7fe53ea210a2115dc190207f

VirusTotal Malware crashed
0.6 1 ZeroCERT

10444 2021-07-23 11:24 Encoding.txt.vbs  

4f99ce54f75fdc843e734244c8aa7fd5

unpack itself crashed
0.6 ZeroCERT

10445 2021-07-23 11:33 Encoding.txt.vbs  

c6aa34d0503da140b004fd439e0c37d1


Antivirus powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 1 6.6 ZeroCERT

10446 2021-07-23 16:27 faster4pc.exe  

b8371590264db62ecbba4b7f481a21a8


Generic Malware PE64 PE File VirusTotal Malware crashed
1.6 M 25 r0d

10447 2021-07-23 16:36 http://198.46.132.159/sww/vbc....  

422e50c25edd184233d2b19609cb1e05


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM PE32 PE File MSOffice File Malware download VirusTotal Malware Code Injection Malicious Traffic Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Tofsee Windows Exploit DNS crashed Downloader
1 6 6.2 M 28 guest

10448 2021-07-23 16:40 vbc.exe  

4f71bce958bbbe6c82bde2df84e4d61e


Generic Malware Malicious Library PE32 PE File VirusTotal Malware RWX flags setting unpack itself DNS
1 2.2 M 27 r0d

10449 2021-07-23 17:07 http://198.46.132.159/sww/vbc....  

422e50c25edd184233d2b19609cb1e05


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File PE32 PE File Malware download VirusTotal Malware Code Injection Malicious Traffic Creates executable files exploit crash unpack itself Windows utilities AppData folder malicious URLs Tofsee Windows Exploit DNS crashed Downloader
1 6 6.2 M 28 guest

10450 2021-07-23 17:18 64CO.exe  

a80b79de02d6881d5e54afcefa38298a


Antivirus UPX Malicious Library PE64 OS Processor Check PE File VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows utilities suspicious process AntiVM_Disk sandbox evasion WriteConsoleW shadowcopy delete Turn off Windows Error Recovery notification window VM Disk Size Check Ransomware Windows Browser ComputerName crashed
11.0 17 ZeroCERT

10451 2021-07-23 17:18 64RA.exe  

4d2c614ba98df43601b6d9551bd26684


UPX Malicious Library PE64 OS Processor Check PE File VirusTotal Malware suspicious privilege sandbox evasion WriteConsoleW shadowcopy delete Windows
3.8 29 ZeroCERT

10452 2021-07-23 17:20 3ad34ec6e377aa9cafa5ecb64ac28b...  

1f2ee35a12165b1c1d19907171248e29


Generic Malware UPX Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 25 ZeroCERT

10453 2021-07-23 17:20 mmdos.exe  

839de683df6ed956916017ff901d58f3


Generic Malware AntiDebug AntiVM PE32 .NET EXE PE File FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows Cryptographic key crashed
6 11 1 2 8.4 M 29 ZeroCERT

10454 2021-07-23 17:22 OneDrive.exe  

e419475aef86f5fd60955c438d46209d


RAT Generic Malware Malicious Packer PE32 .NET EXE PE File Malware download njRAT VirusTotal Malware PDB suspicious privilege Check memory Checks debugger ICMP traffic unpack itself ComputerName
2 1 4.2 27 ZeroCERT

10455 2021-07-23 17:22 Runtime%20Broker.exe  

742d07180cb13ef49af926500163da5d


Generic Malware UPX PE32 .NET EXE PE File VirusTotal Malware MachineGuid Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows ComputerName
3 6 1 5.0 54 ZeroCERT