Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11686 2021-08-23 19:18 ksbgixgq.exe  

5be9bfad00f219b0d219261448a57bda


PWS Loki[b] Loki.m AgentTesla RAT Gen1 Formbook browser info stealer Generic Malware UPX Malicious Library ASPack Malicious Packer ScreenShot AntiDebug AntiVM PE File .NET EXE PE32 OS Processor Check DLL JPEG Format Browser Info Stealer Malware download FTP Client Info Stealer Vidar Arkei VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Buffer PE PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee ArkeiStealer OskiStealer Stealer Windows Browser Email ComputerName DNS Software Password
10 6 9 4 18.8 M 17 ZeroCERT

11687 2021-08-23 19:18 vbc.exe  

162c0de193b3ba1d3f873bb06a8bdd60


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
1.8 M 22 ZeroCERT

11688 2021-08-23 19:20 kdotzx.exe  

691180d2c31121f24a2fee1ee8a34b2c


Generic Malware Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName Cryptographic key crashed
9.2 M 22 ZeroCERT

11689 2021-08-23 19:23 lv.exe  

7cb7086237327a68a89f9ffebbe5a228


Emotet Gen1 NPKI Gen2 Malicious Library UPX Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloader P2P persistence AntiD AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows
1 5.4 M ZeroCERT

11690 2021-08-23 19:25 vbc.exe  

d64d6e211e21f9bc7f8bd2c68ea42b54


Malicious Library PE File OS Processor Check PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege MachineGuid Check memory unpack itself installed browsers check Browser Email ComputerName DNS Software
1 1 1 6.8 M 40 ZeroCERT

11691 2021-08-23 19:25 iqewbieiqbubqw.dll  

58fab5a273bc3bdca01648663e4f7be2


RAT Generic Malware PE File .NET DLL DLL PE32 VirusTotal Malware PDB
0.6 M 3 ZeroCERT

11692 2021-08-24 08:22 jquery.ps1  

bb1166e6ffd66a072c8a58a2c377919c


Generic Malware Antivirus PE File .NET DLL DLL PE32 Check memory buffers extracted WMI Creates executable files unpack itself Windows utilities AppData folder Windows ComputerName Cryptographic key
4.2 guest

11693 2021-08-24 08:24 Saturn.exe  

8bde7b905bea26c52a7576b133e11279


UPX Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
1.8 M 28 ZeroCERT

11694 2021-08-24 09:00 soul3ss.exe  

e16f915796d4762014fc3864d4444ac3


RAT PWS .NET framework Generic Malware Malicious Library DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Internet API FTP ScreenShot Http API Steal credential Downloader P2P AntiDebug AntiVM PE File PE64 OS Pro Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces AppData folder WriteConsoleW installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
3 7 1 13.4 M 23 ZeroCERT

11695 2021-08-24 09:01 sufile.exe  

ff3152ecd477958a1a8dc359a648c651


Malicious Library PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.0 M 26 ZeroCERT

11696 2021-08-24 09:02 warzx.exe  

00db430a07a7ebfe2dda4d10bffbde37


NPKI email stealer Generic Malware Malicious Library Malicious Packer DNS Socket Escalate priviledges KeyLogger Code injection Downloader persistence AntiDebug AntiVM PE File .NET EXE PE32 PE64 OS Processor Check DLL Browser Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key crashed
2 1 12.2 M 39 ZeroCERT

11697 2021-08-24 09:02 solex.exe  

60a55d0c6cba71cd1215b63ee7a1cc82


UPX PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself anti-virtualization Remote Code Execution DNS DDNS crashed
1 4 1 5.2 M 23 ZeroCERT

11698 2021-08-24 09:03 Ahiles.exe  

823f3cbc0b6ad5ee6f23d1da1a49cdc4


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself DNS
1 2.6 M 30 ZeroCERT

11699 2021-08-24 09:03 ab.exe  

3f5998401e2da3c62b4ef0114b8a27a4


PE File PE32 VirusTotal Malware unpack itself
1.8 M 31 ZeroCERT

11700 2021-08-24 09:05 Neptun.exe  

d110032f570a2c3945fb844948fc1184


UPX Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself
2.0 M 34 ZeroCERT