Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12466 2023-06-09 11:06 64.exe  

67dfc7730a6d14715de7b28db5f23c0b


Hide_EXE Malicious Library UPX Malicious Packer PE File PE32 OS Processor Check DLL VirusTotal Malware AutoRuns Check memory Creates executable files Windows utilities suspicious process AppData folder suspicious TLD sandbox evasion WriteConsoleW Windows Remote Code Execution DNS
2 1 6.4 65 ZeroCERT

12467 2023-06-09 11:05 xmrig.exe  

1e7094119ed8a4415c7549c19d771a71


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 PE64 OS Processor Check VirusTotal Malware AutoRuns Check memory Creates executable files Windows utilities Auto service suspicious process AppData folder suspicious TLD WriteConsoleW Windows Remote Code Execution DNS
3 1 9.2 56 ZeroCERT

12468 2023-06-09 10:03 default-browser-agent.exe  

828dda50caa47e37c427142e216c373f


PE64 PE File Malware download VirusTotal Cryptocurrency Miner Malware Phishing Cryptocurrency Malicious Traffic unpack itself Windows DNS CoinMiner
1 8 6 1 2.8 M 23 ZeroCERT

12469 2023-06-09 09:25 mobsync.exe  

828dda50caa47e37c427142e216c373f


PE64 PE File Malware download VirusTotal Cryptocurrency Miner Malware Phishing Cryptocurrency Malicious Traffic unpack itself Windows DNS CoinMiner
1 8 6 2.8 23 ZeroCERT

12470 2023-06-09 09:16 dxpserver.exe  

bfcffc1ba90629e540fd23ad570db1d5


RAT PE64 PE File VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces
1 2 3.8 M 20 ZeroCERT

12471 2023-06-09 09:02 5943.js  

76f6a06e23970b7eb45cabba0418a5d2


Generic Malware Antivirus AntiDebug AntiVM PowerShell ZIP Format powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 9.0 ZeroCERT

12472 2023-06-09 07:57 netTime.exe  

19197b3174a5f441696e23f7e8b8c33a


PWS .NET framework RAT Generic Malware UPX Malicious Packer Antivirus OS Processor Check PE64 PE File suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself suspicious process Windows ComputerName Remote Code Execution Cryptographic key
4.6 ZeroCERT

12473 2023-06-09 07:36 cleanmgr.exe  

f503da8eee4e7cd822239110b488b08b


AgentTesla RAT browser info stealer Google Chrome User Data Downloader Confuser .NET Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger ScreenShot AntiDebug AntiVM .NET EXE PE File PE32 PE64 Remcos Malware PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW Windows DNS DDNS
2 5 7 11.0 M ZeroCERT

12474 2023-06-09 07:33 fbfbfbfbfbfbfbfbfbfbfbfbffbf%2...  

7e59937dcacd711b717c66c93b90e398


MS_RTF_Obfuscation_Objects RTF File doc Malware download Remcos Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS DDNS crashed
3 6 9 4.4 M ZeroCERT

12475 2023-06-08 19:29 hkcmd.exe  

d2a06a7386680bc248d79c2974f9b0cf


UPX Malicious Library PE File PE32 DLL PNG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.4 M 22 ZeroCERT

12476 2023-06-08 19:26 systemwp.php  

e48ed194f54c5df7938c9575c7e84261


ZIP Format
ZeroCERT

12477 2023-06-08 19:06 icicicicicicicicicicicicicic%2...  

f5879c1be334d16e12d50db0fd3c233f


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
2 2 6 4.6 31 ZeroCERT

12478 2023-06-08 19:05 icicicicicicicicicicicicicic%2...  

f5879c1be334d16e12d50db0fd3c233f


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself Windows Exploit DNS crashed
2 2 6 4.6 31 ZeroCERT

12479 2023-06-08 18:11 cleanmgr.exe  

e3c28f839ac6e19f1512e10394d213f9


UPX Malicious Library PE File PE32 JPEG Format DLL VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.6 10 ZeroCERT

12480 2023-06-08 18:09 hkcmd.exe  

e6f5dfc983297d72ec27f94a2b695b03


PWS .NET framework RAT .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger unpack itself suspicious process
5.8 M 35 ZeroCERT