Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12421 2021-09-15 09:39 Invoice1.docx  

9021afcfefe0fd391eacd306de705448


Word 2007 file format(docx) Vulnerability VirusTotal Malware unpack itself
3 2 3.0 M 23 ZeroCERT

12422 2021-09-15 09:40 testen.exe  

e4a200fc3da152d2b8c48f6e19b8ec97


RAT PWS .NET framework BitCoin Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself Check virtual network interfaces Windows Cryptographic key
9.2 M 40 ZeroCERT

12423 2021-09-15 09:41 bluezx.exe  

021ffe1bcf154accf3b947f301c9b676


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed
2 5 3 17.0 M 28 ZeroCERT

12424 2021-09-15 09:42 vmnet.exe  

e07ce1ac09be171289b93538009c471c


RAT Generic Malware Antivirus PE64 PE File VirusTotal Malware powershell suspicious privilege MachineGuid Check memory Checks debugger WMI Creates shortcut ICMP traffic unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
4 6.4 M 39 ZeroCERT

12425 2021-09-15 09:43 raccon.exe  

dea12cd62b3999b22534da85f839e6c3


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.0 M 28 ZeroCERT

12426 2021-09-15 09:44 win32.exe  

f0f4b5aa6183bbc5265f26e47aaeb579


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself ComputerName
1 8.2 M 22 ZeroCERT

12427 2021-09-15 09:45 ashleyzx.exe  

25bed2de415ddf039da98d134f99c226


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself
2 5 1 9.0 M 37 ZeroCERT

12428 2021-09-15 09:48 123456.exe  

80875b1e913ff7c71ce5e32810f9ddda


RAT PWS .NET framework Generic Malware Malicious Packer PE File OS Processor Check .NET EXE PE32 VirusTotal Malware AutoRuns PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk suspicious TLD WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName DNS
4 5 2 3 9.4 M 43 ZeroCERT

12429 2021-09-15 09:50 angelzx.exe  

9bdcd248d7d3333d2ea92620b44c427e


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName DNS crashed
1 10.6 M 26 ZeroCERT

12430 2021-09-15 09:57 diagram-170.doc  

62f8ccb8d886cf7762527c6492723f45


VBA_macro Generic Malware MSOffice File RWX flags setting unpack itself
5 5 1.6 guest

12431 2021-09-15 09:57 diagram-171.doc  

bfa9d4b7bcf5820e663d338e9921d1f8


VBA_macro Generic Malware MSOffice File unpack itself
5 5 1.2 guest

12432 2021-09-15 10:13 0914_718257604903.doc  

7cbc4c74870212cf418af8417001c23b


VBA_macro Generic Malware MSOffice File GIF Format VirusTotal Malware Malicious Traffic Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Check virtual network interfaces suspicious TLD IP Check ComputerName
2 4 1 8.2 M 8 guest

12433 2021-09-15 10:13 0914_4534346255302.doc  

db8169d3473f0079a1850b2d5d5f7861


VBA_macro Generic Malware MSOffice File unpack itself
1.6 guest

12434 2021-09-15 10:20 0914_4534346255302.doc  

db8169d3473f0079a1850b2d5d5f7861


hancitor VBA_macro Generic Malware MSOffice File GIF Format Malware Malicious Traffic Checks debugger buffers extracted Creates shortcut Creates executable files RWX flags setting unpack itself Check virtual network interfaces IP Check ComputerName
2 4 1 1 7.4 M ZeroCERT

12435 2021-09-15 10:24 000856KL2021.pdf.exe  

4700856b989963a3319e864ffa5adbff


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
10.2 32 ZeroCERT