Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11446 2023-07-18 18:19 invoice.pdf.lnk  

e2ef58cea3134177185a50584111495d


Antivirus AntiDebug AntiVM GIF Format PowerShell powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName Cryptographic key
10.0 ZeroCERT

11447 2023-07-18 18:19 Jcojp.jpg  

d387e700d3de3abafab61f1b5d3b8f27


PE64 PE File MachineGuid Check memory Checks debugger unpack itself Windows ComputerName Cryptographic key
1.8 ZeroCERT

11448 2023-07-18 18:17 Client.jpg  

c16d714f359d4659a1f5fef8be99fd30


UPX OS Processor Check .NET EXE PE File PE32 VirusTotal Malware suspicious privilege MachineGuid Check memory Checks debugger unpack itself DNS
1 5.2 55 ZeroCERT

11449 2023-07-18 18:17 winBx.exe  

c03d3f3fac3615256c7c0805743819a2


UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates shortcut Creates executable files unpack itself AppData folder
3.4 13 ZeroCERT

11450 2023-07-18 18:13 003jfb3bb2.dll  

742ac4a9557745ec565ada6511f4a31f


Malicious Library DLL PE64 PE File PDB Checks debugger unpack itself crashed
1.6 ZeroCERT

11451 2023-07-18 18:12 03fdbbbb.dll  

5879c02976fe70a64d9dbc0d38b8b973


Malicious Library DLL PE64 PE File PDB Checks debugger unpack itself crashed
1.6 ZeroCERT

11452 2023-07-18 13:57 idbk.hta  

b4c8fe36366bf1542935f0367270eba5


Generic Malware Antivirus AntiDebug AntiVM PowerShell VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process Windows ComputerName Cryptographic key
7.0 7 ZeroCERT

11453 2023-07-18 13:57 Invoice-1736478793~pdf.vbs  

01a331d778290adb3b875563a34c0c97


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 5.2 1 ZeroCERT

11454 2023-07-18 13:53 wwwr.exe  

c9ca9b64c5afd8ff22c00b717966283e


AgentTesla Generic Malware .NET framework(MSIL) Antivirus KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName Cryptographic key crashed keylogger
2 2 13.4 36 ZeroCERT

11455 2023-07-18 13:51 Remittance_Advice_120723.exe  

4b53952ca3d4332a530e7a9c9e5f09f7


.NET framework(MSIL) .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.6 48 ZeroCERT

11456 2023-07-18 13:49 g.exe  

cf2f8459d17cd077ead9115058819b45


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself Remote Code Execution
2.0 32 ZeroCERT

11457 2023-07-18 10:18 File_pass1234.7z  

2e36fd87f02328791390c79351931433


Escalate priviledges PWS KeyLogger AntiDebug AntiVM RedLine Malware download Amadey Cryptocurrency Miner Malware Cryptocurrency suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself IP Check PrivateLoader Tofsee Fabookie Stealer Windows Remote Code Execution Trojan DNS Downloader
44 66 27 12 7.0 ZeroCERT

11458 2023-07-18 07:43 wininit.exe  

a147b043c9bf220c3f7c30e5fab35414


.NET framework(MSIL) PWS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself DNS
13 14 2 8.6 24 ZeroCERT

11459 2023-07-18 07:33 IDBKIIDBKIDIBDKIDIBKIDIBKIDIBK...  

df4bd2b1d9372a42167da3e6c16d451c


MS_RTF_Obfuscation_Objects RTF File doc Vulnerability VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Exploit DNS crashed
1 1 3 4.6 32 ZeroCERT

11460 2023-07-18 07:31 rxtygf.exe  

ad607f046a6f855f06d0e7b2cab189c1


.NET framework(MSIL) Admin Tool (Sysinternals etc ...) Malicious Library Http API Escalate priviledges HTTP Internet API AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic unpack itself Windows utilities suspicious process malicious URLs AntiVM_Disk WriteConsoleW VMware Ransom Message IP Check VM Disk Size Check Tofsee Ransomware Windows Browser Tor ComputerName Cryptographic key
3 4 2 1 18.0 26 ZeroCERT