Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
11701 2023-07-06 18:06 nellyzx.exe  

f9db6526d2f609f91d136a90e9033b69


Formbook Generic Malware Antivirus PWS AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows ComputerName Cryptographic key
2 4 1 11.8 23 ZeroCERT

11702 2023-07-06 17:52 catzx.doc  

59926b69f6b1dce035ba256215430c52


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself IP Check Tofsee Windows Exploit DNS crashed
1 5 8 4.8 29 ZeroCERT

11703 2023-07-06 17:52 nellyzx.doc  

492aadf83dc7f018a4328b5d6aed4123


MS_RTF_Obfuscation_Objects RTF File doc FormBook Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
4 7 6 4.4 29 ZeroCERT

11704 2023-07-06 17:50 ibm_Centos.exe  

96747c013d4d5da97af5acb7bce91c33


NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger Creates executable files unpack itself Check virtual network interfaces AppData folder IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
2 2 7.6 47 ZeroCERT

11705 2023-07-06 17:49 secslimzx.exe  

009dfe5001a2a856a2d15bbb01a1b8a3


AgentTesla PWS KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
2 2 11.0 43 ZeroCERT

11706 2023-07-06 17:46 ExtraSofts_Setup-x64.msix  

a97c344d176ed2c809ee89f9dada5a42


ZIP Format VirusTotal Malware
0.6 12 ZeroCERT

11707 2023-07-06 17:45 simox.vbs  

6cf4d1674599d213e31c9aa3b9572174


LokiBot Generic Malware Antivirus Socket PWS DNS Hide_URL AntiDebug AntiVM PowerShell Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process malicious URLs installed browsers check Windows Browser Email ComputerName DNS Cryptographic key Software
4 5 8 1 10.0 3 ZeroCERT

11708 2023-07-06 17:05 Wllcsochcbi.exe  

45dce82d48aaae2c56cf79f3cc4be96d


Generic Malware UPX .NET framework(MSIL) Antivirus AntiDebug AntiVM .NET EXE PE File PE32 PowerShell Malware download VirusTotal Malware powershell suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName DNS Cryptographic key
1 2 3 17.8 42 ZeroCERT

11709 2023-07-06 17:02 catzx.exe  

8ff79ca4985e0adae1a132ec02ac10ab


Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
4 3 15.0 44 ZeroCERT

11710 2023-07-06 15:47 setup294.exe  

cadf44b7edefc154b772ab4000d7f694


UPX Malicious Library AntiDebug AntiVM OS Processor Check PE File PE32 DLL PDB Code Injection Checks debugger Creates executable files unpack itself AppData folder Remote Code Execution crashed
3.6 ZeroCERT

11711 2023-07-06 14:25 Invoice_20-28_18846.pdf  

dd6414d53a9546ba886e9b88e1660f87


PDF Suspicious Link PDF
guest

11712 2023-07-06 13:33 prosperzx.exe  

f754f9da84951f3c00646cc572d7de45


.NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself
2.4 30 ZeroCERT

11713 2023-07-06 11:13 File_pass1234.7z  

6f19b6cd920a34b60b5a59f2f20746b6


UPX Malicious Library Escalate priviledges PWS KeyLogger AntiDebug AntiVM PE File PE64 RedLine Malware download Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself suspicious TLD IP Check PrivateLoader Tofsee Fabookie Stealer Windows Trojan DNS Downloader
38 37 19 12 7.4 ZeroCERT

11714 2023-07-06 11:09 haitianzx.exe  

b7933e126bd2fadfae8d36319c9e9e26


RedLine Infostealer UltraVNC UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself Windows Cryptographic key crashed
6.0 49 r0d

11715 2023-07-06 10:59 tonyspecialzx.exe  

b4df3d7f0826501829e1a03991e1fe81


AgentTesla Generic Malware Antivirus PWS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
13.0 33 r0d