Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11401 2023-07-19 09:11 NewInquiry.exe  

0f8e91832e32058f848f5855908e0e59


Formbook Generic Malware .NET framework(MSIL) Antivirus PWS AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 5 1 9.8 ZeroCERT

11402 2023-07-19 09:10 dma.hta  

9302aa42d7bd92c8bfe93a441fe7b147

VirusTotal Malware unpack itself crashed
1.2 17 ZeroCERT

11403 2023-07-19 09:05 Svmninge.vbs  

862907006745ef6b2bdc5dd2664f06ec


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
2 3 7.2 M 5 ZeroCERT

11404 2023-07-19 09:04 41b98681-d329-4aa6-b4a2-8363ee...  

988d5bae53c91628093b527af3da0dcd


UPX .NET framework(MSIL) Malicious Library Malicious Packer Antivirus OS Processor Check .NET EXE PE File PE32 Check memory Checks debugger unpack itself
0.8 ZeroCERT

11405 2023-07-19 09:01 4000c697-1826-4119-9050-597c59...  

f6a377ac917f0dbf3f2bbd523848cd88


.NET framework(MSIL) Malicious Packer .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.2 48 ZeroCERT

11406 2023-07-19 08:58 Kimlik fotokopileri.bat  

4a8b70cd1762106c5b75a6b946f53630


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Sniff Audio HTTP DNS ScreenShot Code injection Internet API FTP KeyLogger AntiDebug AntiVM suspicious process WriteConsoleW Discord DNS
1 2 2 1.4 ZeroCERT

11407 2023-07-19 07:54 r_IAITO15TDUFRHSKV.bin  

1e269967ea1fafd10db80aadc6dc918c


AntiDebug AntiVM Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.4 guest

11408 2023-07-19 07:41 c9665058c3ef16b  

0acb06da48d86e1ef15c27a4f5a3bddd


UPX Malicious Library PE File PE32 PDB Check memory WriteConsoleW
0.6 ZeroCERT

11409 2023-07-19 07:37 lega.exe  

19771209e384f1f8e7ca013b72e0d1fe


Gen1 Emotet UPX Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
3 2 9 15.8 ZeroCERT

11410 2023-07-19 07:34 photo113.exe  

7308bb341cd27493d2939ecbbc6c7436


Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
6 3 11 3 17.0 ZeroCERT

11411 2023-07-19 07:34 dmw.exe  

51173f4615fda6188760cb468b593a27


Client SW User Data Stealer Backdoor RemcosRAT browser info stealer Generic Malware Google Chrome User Data Downloader Antivirus Create Service Socket Escalate priviledges PWS Sniff Audio DNS ScreenShot Internet API KeyLogger AntiDebug AntiVM .NET EXE PE Malware download Remcos Malware powershell Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process Windows ComputerName Cryptographic key crashed keylogger
1 4 2 12.2 ZeroCERT

11412 2023-07-19 07:34 officialzx.doc  

aed387c2000a4a37308a90431ddf9070


MS_RTF_Obfuscation_Objects RTF File doc LokiBot Malware download Malware c&c Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
2 2 12 4.0 ZeroCERT

11413 2023-07-19 07:33 logzx.exe  

2bbe7bfa4829bf0bcdc2952b93bd9bd9


.NET framework(MSIL) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Malware download FTP Client Info Stealer Email Client Info Stealer Malware AgentTesla PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Windows Browser Email ComputerName DNS Cryptographic key Software crashed
3 2 11.0 ZeroCERT

11414 2023-07-19 07:27 officialzx.exe  

f3fca96a7b2dbbd19c62c9a798e4ddb0


LokiBot .NET framework(MSIL) Socket PWS DNS AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 1 7 13.6 ZeroCERT

11415 2023-07-19 07:25 summ.exe  

221b4dce039b2a7feaa20a87cffc4dc0


AgentTesla Generic Malware .NET framework(MSIL) Antivirus KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Email Client Info Stealer PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName Cryptographic key crashed
2 2 10.8 ZeroCERT