Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10711 2023-08-15 19:13 hunresgytv.hta  

4e0111996bd46a5eadce11ea29ebae3c


Generic Malware Antivirus AntiDebug AntiVM PowerShell MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Exploit ComputerName DNS Cryptographic key crashed
9.2 16 ZeroCERT

10712 2023-08-15 19:12 upd-download(st-ct).url  

bad6f985683173fbda122d222a10e010


AntiDebug AntiVM URL Format MSOffice File VirusTotal Malware Code Injection Malicious Traffic Creates shortcut RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3 1 5.0 2 ZeroCERT

10713 2023-08-15 19:12 build1234.exe  

5fb59ec46fd6a15ac0856e37fe226573


RedLine Infostealer RedLine stealer UPX .NET framework(MSIL) Confuser .NET OS Processor Check .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6.2 52 ZeroCERT

10714 2023-08-15 16:15 PNe5J9o1XCKpHYk.exe  

40be18ff344e38f80cec056f5bd97f21


UPX .NET framework(MSIL) Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware Buffer PE suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key
1 15.4 M 55 guest

10715 2023-08-15 10:44 wininit.exe  

866092635503625027bd65cacbeb3abd


Formbook Generic Malware Antivirus PWS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
6 6 11.6 M 39 ZeroCERT

10716 2023-08-15 10:41 000000000000000%23%23%23%23%23...  

856951e629035c756ed107835a218653


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
5 6 5.0 M 32 ZeroCERT

10717 2023-08-15 10:40 crypted.exe  

97ec989085e99d2df0426b73620812b0


UPX Malicious Library Malicious Packer AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Code Injection Check memory buffers extracted unpack itself Collect installed applications sandbox evasion WriteConsoleW anti-virtualization installed browsers check Browser ComputerName DNS
1 1 10.4 M 52 ZeroCERT

10718 2023-08-15 10:39 EGK.vbs  

6b1d1a7455742408ac22e8d243998296


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName Cryptographic key
3 3 8.8 M 2 ZeroCERT

10719 2023-08-15 10:36 ewrqqfaaa.exe  

3798e6dae3df606799111b63bf54aad9


UPX Malicious Packer OS Processor Check PE File PE32 VirusTotal Malware Checks debugger Remote Code Execution
1.6 M 14 ZeroCERT

10720 2023-08-15 10:35 C1pNaIqyfDshEdy.exe  

c36113ac380951204651c549f3eab824


Formbook NSIS UPX Malicious Library ASPack PE File PE32 OS Processor Check DLL VirusTotal Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself AppData folder
4 8 1 4.6 M 40 ZeroCERT

10721 2023-08-15 10:33 chrme.exe  

5b04c44af744f95bf670840cea457616


ASPack PE File PE32 VirusTotal Malware suspicious privilege sandbox evasion Browser ComputerName Remote Code Execution
3.6 M 23 ZeroCERT

10722 2023-08-14 17:36 PeriodicalConiform.exe  

43bbed8db3d574acd479bb95fdaeb89f


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB
2.2 M 48 ZeroCERT

10723 2023-08-14 17:33 smss.exe  

5e70d5ff581e40445e432f6ade284716


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself Remote Code Execution
2.0 M 29 ZeroCERT

10724 2023-08-14 16:49 capetown.hta  

60c5404627e66d12644251117cd52cbd


Generic Malware Antivirus AntiDebug AntiVM PowerShell MSOffice File VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut exploit crash unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Exploit ComputerName DNS Cryptographic key crashed
9.2 16 ZeroCERT

10725 2023-08-14 16:16 us-en(DOWNLOAD).url  

0dcc09dbbfc8d4bcc64ca2f0f253435f


AntiDebug AntiVM VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName DNS Cryptographic key
4 1 7.0 M 2 ZeroCERT