Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11116 2023-07-31 17:19 2907.zip  

d8491c2201483a1c75ff76fe08e17e2c


ZIP Format VirusTotal Malware Malicious Traffic NetSupport
1 5 1 2.4 13 ZeroCERT

11117 2023-07-31 16:55 3a64dce714d28968b2691168a78e03...  

6258ec13a6d93e6ca60755540abebde6


Vidar LokiBot UPX PWS AntiDebug AntiVM BitCoin OS Processor Check .NET EXE PE File PE32 VirusTotal Malware Telegram Buffer PE PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself malicious URLs Tofsee ComputerName Remote Code Execution DNS
3 5 4 2 11.2 M 17 guest

11118 2023-07-31 11:24 x64.exe  

79a0dbb12842319812690aebfd1ee580


PE64 PE File VirusTotal Malware Malicious Traffic unpack itself suspicious TLD DNS
1 2 2 3.4 38 ZeroCERT

11119 2023-07-31 11:22 8a5fd1e9c9841ff0253b2a6f1e533d...  

8a5fd1e9c9841ff0253b2a6f1e533d0e


UPX Malicious Library OS Processor Check PE File PE32 ZIP Format Word 2007 file format(docx) VirusTotal Malware PDB Check memory RWX flags setting unpack itself suspicious process Tofsee Interception
1 2 2 3.2 13 ZeroCERT

11120 2023-07-31 11:21 002105e21f1bddf68e59743c440e41...  

002105e21f1bddf68e59743c440e416a


UPX Malicious Library OS Processor Check PE File PE32 ZIP Format Word 2007 file format(docx) VirusTotal Malware PDB Check memory RWX flags setting unpack itself suspicious process Tofsee Interception
1 2 2 3.2 10 ZeroCERT

11121 2023-07-31 11:20 위믹스팀-클라우드사용금지.doc  

b6614471ebf288689d33808c376540e1


VBA_macro ZIP Format Word 2007 file format(docx) VirusTotal Malware exploit crash unpack itself WriteConsoleW Tofsee Exploit crashed
2 2 4.2 31 ZeroCERT

11122 2023-07-31 11:06 sys.exe  

e08b723ca187ecfef73c1b7b5f0ecfc8


XMRig Miner Generic Malware UPX Malicious Library Malicious Packer OS Processor Check PE64 PE File VirusTotal Malware unpack itself ComputerName
1.8 48 r0d

11123 2023-07-31 10:36 File_pass1234.7z  

c5997806d938310f6b0cbde8389b2108


Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Malware Microsoft Telegram suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself IP Check PrivateLoader Tofsee Fabookie Stealer Windows Discord RisePro DNS
40 57 32 11 6.2 M ZeroCERT

11124 2023-07-31 10:23 debug2.ps1  

385c874a9adc94c9cddb7618a86b8299


Generic Malware Antivirus Malware powershell Malicious Traffic Check memory unpack itself Check virtual network interfaces WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
2 1 1 4.6 ZeroCERT

11125 2023-07-31 10:01 secbobbyzx.doc  

50a7ad2ace11903c9d16a6c8660631de


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash Tofsee Windows Exploit DNS crashed
2 4 10 4.2 37 ZeroCERT

11126 2023-07-31 07:53 vvlio7wypLsHed.exe  

732d840080e5382a366afe1ffd3e7aa3


NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL FormBook Malware download VirusTotal Malware suspicious privilege Malicious Traffic Check memory Creates executable files unpack itself AppData folder
5 9 2 4.6 M 45 ZeroCERT

11127 2023-07-31 07:42 Tumeg.exe  

e5655066c86f74f6b444f66f3222ce07


Gen1 Emotet UPX Malicious Library Antivirus CAB PE File PE32 VirusTotal Malware AutoRuns PDB Check memory Creates executable files unpack itself Windows utilities AntiVM_Disk WriteConsoleW VM Disk Size Check Windows Remote Code Execution
4.6 28 ZeroCERT

11128 2023-07-31 07:40 Setup.exe  

9bb0bf48749cecfeadc4e6be1a2ad5ef


Emotet Gen1 UPX Malicious Library Malicious Packer AntiDebug AntiVM OS Processor Check .NET EXE PE File PE32 DLL Browser Info Stealer Malware download VirusTotal Email Client Info Stealer Malware c&c Buffer PE PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser Email ComputerName Remote Code Execution DNS plugin
8 1 17 14.2 9 ZeroCERT

11129 2023-07-31 07:35 sys.exe  

e08b723ca187ecfef73c1b7b5f0ecfc8


Generic Malware UPX Malicious Library Malicious Packer OS Processor Check PE64 PE File VirusTotal Malware unpack itself ComputerName
1.8 M 48 ZeroCERT

11130 2023-07-30 09:33 PNe5J9o1XCKpHYk.exe  

40be18ff344e38f80cec056f5bd97f21


UPX .NET framework(MSIL) Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware Buffer PE suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key
1 14.8 M 55 guest