Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11026 2023-08-03 13:51 pablozx.exe  

7456977c738208470a01d84ed531f081


email stealer Downloader Escalate priviledges PWS DNS Code injection persistence KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer VirusTotal Email Client Info Stealer Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key crashed
1 17.0 M 43 ZeroCERT

11027 2023-08-03 13:46 60293824632766269097.msi  

2dca491ef853829346413533f9dc7a4d


CAB MSOffice File VirusTotal Malware unpack itself crashed
1.0 4 ZeroCERT

11028 2023-08-03 10:31 I00000000q0000q00000q00000%23%...  

2e8e51303d4a8f2a575fbc72ebd19cac


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
2 1 6 4.0 M 29 ZeroCERT

11029 2023-08-03 10:29 lawzx.exe  

f7687a10bf31777ddad97b1d0907bdc6


PWS SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Browser Email ComputerName Software crashed
9.8 M 41 ZeroCERT

11030 2023-08-03 10:27 cm9292000000000000000%23%23%23...  

e26f05916ee04b50b7e98416f0905b8c


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
1 1 5 4.2 M 35 ZeroCERT

11031 2023-08-03 10:25 gdf04000000000000000000%23%23%...  

74b5dbbaecd8ad665dfa124659885fad


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic ICMP traffic exploit crash unpack itself Windows Exploit DNS crashed
4 8 7 4.8 M 29 ZeroCERT

11032 2023-08-03 10:25 Excel.exe  

79e5648312a58377ef76d2346404ef12


UPX Malicious Library Malicious Packer MZP Format PE File PE32 VirusTotal Malware RWX flags setting unpack itself
2.8 M 44 ZeroCERT

11033 2023-08-03 10:23 0TTYuKFFp2Neo.exe  

99c8b8c9c4b1e113156d2e708766d658


Malicious Library PE64 PE File VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 24 ZeroCERT

11034 2023-08-03 10:23 kpb0239848585885000000%23%23%2...  

780dc1ce7fb814935f6422561b7938bd


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
1 1 6 4.0 M 29 ZeroCERT

11035 2023-08-03 10:21 idbk6758400000000000%23%23%23%...  

7eb05bcc9d2d6f3edaa773d3d602b1a1


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
1 1 5 4.2 30 ZeroCERT

11036 2023-08-03 10:21 lawzx.doc  

bc89a42094fac06d565983f94cb4fa2a


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
1 1 5 4.4 27 ZeroCERT

11037 2023-08-03 10:20 IB_iso.exe  

4ef341e4b9c3229fe2281ddece402c22


NSIS UPX Malicious Library PE File PE32 DLL VirusTotal Malware suspicious privilege Check memory Creates executable files unpack itself AppData folder ComputerName DNS
23 23 2 4.6 30 ZeroCERT

11038 2023-08-03 10:18 schtasks.exe  

ef85c294d69ed1cc66f26b7ea200b425


AsyncRAT UPX .NET framework(MSIL) Malicious Packer OS Processor Check .NET EXE PE File PE32
2 ZeroCERT

11039 2023-08-03 10:18 IBS_Cortana.exe  

08defe80ace1f032875c8127ae5e4481


UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
1 2.4 21 ZeroCERT

11040 2023-08-03 10:16 wininit.exe  

398168319933805c70238c679be79bdb


UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.6 32 ZeroCERT