Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10696 2023-08-16 09:37 invoice.exe  

47699e23b8a46230799ae564517d7519


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself
1 2.2 M 44 ZeroCERT

10697 2023-08-16 09:00 Capture_Data.dmg  

74b6e3b8b30844ab6637b09465a8deae


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.4 guest

10698 2023-08-16 07:52 addo.exe  

6730aa28aed92b39ba1a23d43c45399a


AgentTesla Generic Malware UPX Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File PE32 Browser Info Stealer Email Client Info Stealer Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted RWX flags setting unpack itself Check virtual network interfaces IP Check Windows Browser Email ComputerName crashed
2 9.8 ZeroCERT

10699 2023-08-16 07:45 Chromium.exe  

903d5f8adb6f17e25f419df6db9c6a77


NSIS UPX Malicious Library PE File PE32 DLL VirusTotal Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself Windows utilities AppData folder Windows
3 6 5.6 38 ZeroCERT

10700 2023-08-16 07:43 00000000000o0o0o0o0O0O0O0O000o...  

64c604cd64a22ab5d6f05ea9770c3212


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Exploit DNS crashed
2 5 4.0 28 ZeroCERT

10701 2023-08-16 07:42 client32.exe  

a2b46c59f6e7e395d479b09464ecdba0


UPX PE File PE32 VirusTotal Malware PDB
0.6 5 ZeroCERT

10702 2023-08-16 07:40 yugozx.exe  

d78d90977bd9addab19038a3367f7804


SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
2 13.0 31 ZeroCERT

10703 2023-08-16 07:40 chromium.exe  

013a719564fee962f64473767b1e8cd8


Formbook AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious TLD
2 5 9.8 M 31 ZeroCERT

10704 2023-08-16 07:39 Chromium.exe  

6072355596f3a49926f9bffbaae67427


NSIS UPX Malicious Library PE File PE32 DLL VirusTotal Malware suspicious privilege Check memory Creates executable files unpack itself AppData folder
20 22 4.2 M 29 ZeroCERT

10705 2023-08-16 07:38 wininit.exe  

b3fc98596e410ebebb2c1f39007abaf5


Generic Malware UPX Malicious Library PE File PE32 DLL PE64 PNG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.4 20 ZeroCERT

10706 2023-08-16 07:37 chromium.exe  

c1ac31ebcbfb8dc95d4eea6d4c95a474


.NET framework(MSIL) Admin Tool (Sysinternals etc ...) .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself Windows Cryptographic key
2.8 M 49 ZeroCERT

10707 2023-08-16 07:36 wininit.exe  

7f162aac8d8d2af6c52e87a85a1547e5


Formbook Confuser .NET AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
17 18 16 8.8 M 26 ZeroCERT

10708 2023-08-16 07:36 wininit.exe  

64870ba5b0e92b05dc383959e02782ce


Formbook Confuser .NET AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious TLD
22 24 20 9.6 M 48 ZeroCERT

10709 2023-08-16 07:36 chromium.exe  

3333fe1aabfb8bdfd7ad0453b532976a


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself Remote Code Execution
2.4 M 47 ZeroCERT

10710 2023-08-15 19:16 builsrtdd.exe  

3656380b872547ff69f460c90328d257


UPX Malicious Library Anti_VM OS Processor Check PE File PE32 VirusTotal Malware MachineGuid Malicious Traffic Creates executable files unpack itself ComputerName DNS crashed
4 5 4.4 M 37 ZeroCERT