Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12571 2023-06-05 16:51 w-9.exe  

2dbc44aae677e2661475da5b2a3aac2e


UPX PE File PE32 VirusTotal Malware WriteConsoleW
3.0 M 42 ZeroCERT

12572 2023-06-05 16:49 Setup.exe  

c28cc92a7c78b96bec58fa3e5398074a


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself
2.2 M 43 ZeroCERT

12573 2023-06-05 16:46 G_768916.zip  

53c9f14237d2ec66158868a25c2c6502


ZIP Format
ZeroCERT

12574 2023-06-05 16:43 DVolPro.dll  

30e1d0c1941167612a1da0bb79a03be8


UPX Malicious Library DLL PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself crashed
2.8 36 ZeroCERT

12575 2023-06-05 15:36 51216324738.pdf  

e44cdb9b41b9e644d0a7366029ae9ec0


PDF Suspicious Link PDF AntiDebug AntiVM MSOffice File PNG Format JPEG Format VirusTotal Malware Code Injection RWX flags setting unpack itself Windows utilities suspicious TLD Tofsee Windows DNS
2 21 1 1 5.2 M 30 ZeroCERT

12576 2023-06-05 13:45 ririririiririririririririiriri...  

a411c5f01d2a3c00973839711c3ab747


Loki MS_RTF_Obfuscation_Objects RTF File doc LokiBot Malware download VirusTotal Malware c&c Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed
2 2 12 1 5.0 M 31 ZeroCERT

12577 2023-06-05 08:04 setup.EXE  

426937c153dd506951c7f40a94094c48


Gen1 Emotet PWS .NET framework RAT njRAT backdoor UPX Malicious Library CAB PE64 PE File PNG Format OS Processor Check .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder WriteConsoleW installed browsers check Tofsee Windows Browser Email ComputerName Remote Code Execution DNS Cryptographic key DDNS Software crashed
1 6 4 10.6 M ZeroCERT

12578 2023-06-04 17:47 Sceatt.exe  

a1ed05e1152357a287ad4c4b4ddc300e


PWS .NET framework RAT RedLine Stealer Confuser .NET .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself DNS
1 2.6 M 52 ZeroCERT

12579 2023-06-04 17:45 7e8e3c8b54a3dd86e1b6afb3300169...  

c4b9d83a65b7a0b05d7d24d4abcb29ae


Suspicious_Script_Bin Generic Malware UPX Malicious Library AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Windows Browser ComputerName Remote Code Execution DNS Cryptographic key DDNS crashed
2 1 18.2 M 38 ZeroCERT

12580 2023-06-04 17:45 foto124.exe  

5179b8f5f0a4a2c88c1c9ab074f50e60


Redline Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
3 2 9 3 14.8 M 39 ZeroCERT

12581 2023-06-04 17:40 a2592d.exe  

3be6be65f8685715130d5be7ba9d2f50


UPX Malicious Library AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Remote Code Execution Cryptographic key
7.2 M 38 ZeroCERT

12582 2023-06-04 17:38 eee23xe.exe  

19cb6550343998faee16c4f604a25f56


Loki NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Malicious Traffic Check memory Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software crashed
1 2 5 1 10.0 M 53 ZeroCERT

12583 2023-06-04 17:38 secmorganzx.exe  

e5cd98442cbc3af8dbc877ecd99a58d2


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself Remote Code Execution DNS
1 2.8 M 48 ZeroCERT

12584 2023-06-04 17:37 fotod25.exe  

001ba557c3a6837ac5635bbf859ed645


Redline Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
5 2 11 3 14.8 M 39 ZeroCERT

12585 2023-06-04 17:37 foto124.exe  

1b28062bf3a3a5e2e681649e4a0d22dc


Redline Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE File PE32 OS Processor Check DLL Browser Info Stealer RedLine Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
3 2 9 3 13.8 M ZeroCERT