Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11191 2023-07-27 10:29 raman.exe  

f113913b1fed45145f205fb3d808bf68


UPX Malicious Library OS Processor Check PE File PE32 DLL PDB unpack itself suspicious process AppData folder Remote Code Execution DNS
1 2.4 M ZeroCERT

11192 2023-07-27 10:27 clp8.exe  

1c88f016b6d72ca7ef779a70c24db73f


PE File PE32 VirusTotal Malware AutoRuns Check memory Creates executable files unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName
4.8 39 ZeroCERT

11193 2023-07-27 10:25 ChromeSetup.exe  

72001bce22646a1c43c8f5d2cd1778cc


AgentTesla Generic Malware .NET framework(MSIL) Antivirus SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
2 2 15.0 22 ZeroCERT

11194 2023-07-27 10:22 govno.exe  

1c7c3de28a865fcdec6618bf3be4d6ec


Malicious Library PE File PE32 VirusTotal Malware PDB
1.8 29 ZeroCERT

11195 2023-07-27 10:20 wininit.exe  

e9957181ffe5cf7bebf817c774eae4ae


Malicious Library PE64 PE File VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself
2.4 35 ZeroCERT

11196 2023-07-27 10:20 11.exe  

0fe4cd989e5b3992e9bf3b118f838436


PE64 PE File VirusTotal Malware
2 1.6 M 43 ZeroCERT

11197 2023-07-26 18:32 AN-1003.pdf  

d56437052eade48fbe45adfc73748b28


PDF
guest

11198 2023-07-26 17:52 INV-Details-JUL2023(224).exe  

68def46fcf9076181826880b68a40191


PE64 PE File
guest

11199 2023-07-26 17:40 setup.exe  

b634d0b3af3d6a147f871701da357207


Themida Packer PE64 PE File VirusTotal Malware unpack itself Windows DNS crashed
1 3.0 18 ZeroCERT

11200 2023-07-26 17:40 TENTENTNTNTENTNTETNETNETNETNE%...  

568895b24ab301b43808273df671c0ba


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
2 3 6 4.6 32 ZeroCERT

11201 2023-07-26 17:34 code.exe  

e4efed1ac69b15ff3dfc8024a28eb967


UPX Malicious Library OS Processor Check PE64 PE File Malware download Cobalt Strike Cobalt VirusTotal Malware Check memory unpack itself ComputerName DNS
2 1 2 3.4 51 ZeroCERT

11202 2023-07-26 17:33 ChromeSetup.exe  

cca558a61d6125ecd91f1f5b9b3070a5


Client SW User Data Stealer Backdoor RemcosRAT browser info stealer Google Chrome User Data Downloader ScreenShot Create Service Socket Escalate priviledges PWS Sniff Audio DNS Internet API KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware Buffer PE AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key keylogger
2 5 1 15.8 24 ZeroCERT

11203 2023-07-26 17:33 ChromeSetup.exe  

e731b730b77e82c08ada3ecd859751c9


AgentTesla Generic Malware .NET framework(MSIL) Antivirus PWS SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer powershell AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
3 2 14.4 ZeroCERT

11204 2023-07-26 17:32 ChromeSetup.exe  

e9a32c39471da0a007579b86dfd4ce38


Generic Malware Antivirus UPX PWS Internet API AntiDebug AntiVM .NET EXE PE File PE32 DLL VirusTotal Malware powershell Buffer PE AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder WriteConsoleW Windows ComputerName DNS Cryptographic key crashed
1 3 1 13.8 27 ZeroCERT

11205 2023-07-26 17:31 explore.exe  

0eb17599a6d6340826cde1fb9555a801


UPX Malicious Library OS Processor Check PE64 PE File VirusTotal Malware buffers extracted unpack itself Check virtual network interfaces DNS
1 2 3.8 51 ZeroCERT