Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11131 2021-08-09 23:53 luawrapfiles.bytes  

03e76da0dbde0c8b741e05aa6febbed1


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

11132 2021-08-09 23:53 memorydump.bytes  

a62c187a2f9e9586b13fd22553a6bd63


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

11133 2021-08-09 23:54 typecheck.bytes  

584de4e6b6ec0e0dce154120afeb73af


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

11134 2021-08-09 23:54 monitor.bytes  

b7b72dea02a7a301ecac42a47ca8f25a


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

11135 2021-08-09 23:55 md5.bytes  

fe0ce4cafefde55959b6031e0ae32ad7


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 5.2 guest

11136 2021-08-09 23:56 autotestlogfileutils.bytes  

92b048b4fd6d2adfaec8c84257ecd83b


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

11137 2021-08-09 23:56 autotestmgr.bytes  

536b6dcd8f98a5466d3e4ab8613857ae


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

11138 2021-08-09 23:58 autotestmgrinc.bytes  

e408c001ecfaf192bd37406c5d45a2e2


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 5.2 guest

11139 2021-08-09 23:58 autotest_chat.bytes  

3647de8a61419580912b312e99338be9


DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 5.8 guest

11140 2021-08-10 09:25 Stolen Images Evidence.js  

e7e9a4dde67ffa52bca76cbfda724428


Antivirus UPX Malicious Library AntiDebug AntiVM PE64 OS Processor Check DLL PE File VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process Windows ComputerName Cryptographic key crashed
2 2 3 10.0 2 ZeroCERT

11141 2021-08-10 09:31 المريض باسل دراغمة_0001 pdf.ex...  

d60edd62ea6f2965e663c1a4ed2fdea8


UPX Malicious Packer Malicious Library Admin Tool (Sysinternals etc ...) PDF OS Processor Check PE File PE32 JPEG Format GIF Format Malware download VirusTotal Malware AutoRuns suspicious privilege MachineGuid Malicious Traffic Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces sandbox evasion installed browsers check Tofsee Micropsia Windows Browser ComputerName Remote Code Execution crashed
8 2 4 10.6 19 ZeroCERT

11142 2021-08-10 09:37 wechat-35355.exe  

e988d1994581870c6aac979f87ab2a5c


NPKI PWS Loki[b] Loki[m] Gen2 Gen1 Generic Malware Malicious Library UPX Antivirus Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal Browser Info Stealer VirusTotal Malware powershell Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder malicious URLs AntiVM_Disk sandbox evasion WriteConsoleW Firewall state off VM Disk Size Check installed browsers check Tofsee Windows Browser ComputerName Remote Code Execution Cryptographic key crashed
6 2 17.0 12 ZeroCERT

11143 2021-08-10 09:45 15_17.html  

009787920198ce72bf36f71df40b1f88


Antivirus AntiDebug AntiVM PNG Format Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process Tofsee Windows ComputerName Cryptographic key
21 18 1 9.0 ZeroCERT

11144 2021-08-10 10:02 wznT7y3i9OrU  

7725fccbae0011ec120a5851d37ef819


Generic Malware Malicious Library DLL PE File PE32 VirusTotal Malware Windows crashed
2.2 31 ZeroCERT

11145 2021-08-10 10:02 g4cG1btyd  

4ebe058d038c65e38491452e12ff670a


Malicious Library DLL PE File PE32 Windows crashed
1.2 ZeroCERT