Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11566 2023-07-12 17:50 csrssmd.exe  

dd9ad309b65f30ea83791cec013a90e0


Formbook AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware Buffer PE suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself DNS crashed
15 20 4 14 11.6 M 47 ZeroCERT

11567 2023-07-12 17:47 win.exe  

d4fe9ca0baa8b18233d058024e4b6f2d


Generic Malware PDF Suspicious Link .NET framework(MSIL) Antivirus UPX Internet API PDF AntiDebug AntiVM .NET EXE PE File PE32 ZIP Format DLL VirusTotal Email Client Info Stealer Malware Buffer PE suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Windows Email ComputerName Cryptographic key crashed
1 4 3 13.4 M 42 ZeroCERT

11568 2023-07-12 17:46 ptbinzx.exe  

482e0572bd0f90583765ea3e5a06d4fb


Formbook .NET framework(MSIL) PWS AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
3 6 1 8.2 M 24 ZeroCERT

11569 2023-07-12 17:46 Historiers.exe  

109dbd7130e7c7e519eddac87ccbc34c


UPX Malicious Library PE File PE32 OS Processor Check DLL PE64 PNG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
3.0 M 31 ZeroCERT

11570 2023-07-12 17:45 WSD.exe  

b205c78be14c4df122a02ca9a6261d47


.NET framework(MSIL) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
4 4 14.2 M 47 ZeroCERT

11571 2023-07-12 17:45 Ads.exe  

69479c1cca7d8e7c58a1d4b6d7c02e2a


UPX ScreenShot KeyLogger AntiDebug AntiVM PE64 PE File VirusTotal Malware Buffer PE MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs Tofsee Windows Cryptographic key
1 2 1 7.2 M 24 ZeroCERT

11572 2023-07-12 17:44 crypted1.exe  

34b4037287a02c8d02d26e30be52e390


UPX Malicious Library Malicious Packer AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces WriteConsoleW IP Check ComputerName
1 2 1 9.8 M 48 ZeroCERT

11573 2023-07-12 17:39 maintest.exe  

836dfa8ecf57ce861f4cacfe4a85572d


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware WMI RWX flags setting unpack itself ComputerName crashed
4.2 M 52 ZeroCERT

11574 2023-07-12 17:39 firmresource.exe  

ae830ab4838b8fb88af7a8fcf0071d1b


Gen1 Emotet Malicious Library .NET framework(MSIL) Malicious Packer CAB PE64 PE File .NET EXE PE32 VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Windows Remote Code Execution Cryptographic key
2 2 5.6 M 27 ZeroCERT

11575 2023-07-12 17:38 csrss00.exe  

601f2b22a16a96c9ddaae24e2c5611f2


UPX Malicious Library PE File PE32 DLL VirusTotal Malware Check memory Creates shortcut Creates executable files unpack itself AppData folder
4.0 M 43 ZeroCERT

11576 2023-07-12 17:35 crypted.exe  

aa06cd111cb6800e04353ec34723044b


UPX Malicious Library Malicious Packer AntiDebug AntiVM OS Processor Check PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName DNS Cryptographic key Software crashed
1 3 10.8 M 30 ZeroCERT

11577 2023-07-12 17:34 clip64.dll  

da32ba5704b945ff08dc50e17ce1bb5c


UPX Admin Tool (Sysinternals etc ...) Malicious Library OS Processor Check DLL PE File PE32 VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 58 ZeroCERT

11578 2023-07-12 17:34 ptbinzx.doc  

f351161a0fbeea7aede8237afb6e9b1f


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
2 5 6 4.4 M 28 ZeroCERT

11579 2023-07-12 17:33 KGC.exe  

af90d735ce31e71e2d2204957dddd081


.NET framework(MSIL) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed
4 4 13.2 M 47 ZeroCERT

11580 2023-07-12 17:31 chicka.exe  

2bf0aebcee63482e0068407b25adc5f3


RedLine Infostealer RedLine stealer UPX .NET framework(MSIL) Confuser .NET OS Processor Check .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows DNS Cryptographic key
1 4.4 M 54 ZeroCERT