Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12406 2021-09-15 07:55 rusk.exe  

b5faf0605f312ebc4ba7db08e4642530


Themida Packer Admin Tool (Sysinternals etc ...) PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key Software crashed
1 3 1 11.2 22 ZeroCERT

12407 2021-09-15 09:23 f.wbk  

e98b2039d50f2482200d688766f9789f


RTF File doc AntiDebug AntiVM FormBook Malware download VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger exploit crash unpack itself Windows Exploit DNS crashed Downloader
1 4 7 5.0 M 26 ZeroCERT

12408 2021-09-15 09:23 buy.exe  

c162cbbb6353cb3b09bdc441fdd4c1b8


North Korea RAT PWS .NET framework Generic Malware DNS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
8.8 M 29 ZeroCERT

12409 2021-09-15 09:25 f13058cb1065b13600fcb4a4f48e8e...  

dc0b13c9d739e5bd085ed2e8a8a263ab


Malicious Library PE File OS Processor Check PE32 DLL VirusTotal Malware Buffer PE Check memory buffers extracted WMI Creates executable files AppData folder Tofsee ComputerName
2 2 1 1 4.8 M 40 ZeroCERT

12410 2021-09-15 09:25 wealthzx.exe  

ffd78db073dcc4169752342093c603ea


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
10.2 M 34 ZeroCERT

12411 2021-09-15 09:27 1233212333.exe  

c0fe83baeb1facb1a25a686166660383


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName DNS
1 12.2 M 39 ZeroCERT

12412 2021-09-15 09:28 vbc.exe  

1ec248cde51ae1e700565074014f02d0


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself ComputerName
3 6 1 9.0 M 21 ZeroCERT

12413 2021-09-15 09:30 plugmanzx.exe  

19665f929613c0e945ff13dd25c9362e


Generic Malware DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
1 1 13.6 M 34 ZeroCERT

12414 2021-09-15 09:30 tmt.exe  

b95fa0b61f4744cfb0ccd7dcb48270f8


North Korea RAT PWS .NET framework Generic Malware DNS SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
8.8 M 20 ZeroCERT

12415 2021-09-15 09:32 d.wbk  

cfd3682c2cf1f604af25f77e9ac3fc84


RTF File doc AntiDebug AntiVM FormBook Malware download VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger exploit crash unpack itself Windows Exploit DNS crashed
1 4 8 5.0 M 26 ZeroCERT

12416 2021-09-15 09:32 bluestwozx.exe  

ab66db9b6118f9156a0bd820642fa9cf


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 4 3 15.4 M 24 ZeroCERT

12417 2021-09-15 09:34 esembler.exe  

148fab089c36dcbd7cc58e0bdba881e4


RAT PWS .NET framework Generic Malware PE File OS Processor Check .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows DNS Cryptographic key
1 3.8 M 43 ZeroCERT

12418 2021-09-15 09:35 slFZvqw6JB8bsDt.exe  

03fa2aa90ad1ce098de68893d83f701d


RAT PWS .NET framework NPKI Generic Malware Malicious Packer UPX Malicious Library PE File OS Processor Check .NET EXE PE32 Malware download VirusTotal Malware IoC AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName
4 4 4 8.6 M 25 ZeroCERT

12419 2021-09-15 09:36 StubMonoDLL.exe  

f613cc950434bbccd7e48e584d60989a


RAT Generic Malware Malicious Packer Malicious Library PE File OS Processor Check .NET EXE PE32 VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself sandbox evasion Browser crashed
3.0 M 20 ZeroCERT

12420 2021-09-15 09:37 loadetc.exe  

2bd18b0ce7aa8dfaee0e922090aae138


AntiDebug AntiVM PE File PE32 Malware download VirusTotal Malware AutoRuns PDB Code Injection Malicious Traffic Check memory Creates executable files Windows utilities suspicious process WriteConsoleW Windows DNS Downloader
1 2 5 8.2 M 38 ZeroCERT