Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12586 2023-06-04 17:33 File_pass1234.7z  

63e2ad5f5f1466a924b0c77048dcc60a


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself
2.0 M 9 guest

12587 2023-06-03 17:31 hkcmd.exe  

53d4ab9c429de02b7efc94d7be3e6059


AgentTesla RAT browser info stealer Google Chrome User Data Downloader Confuser .NET Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger AntiDebug AntiVM PE64 PE File Remcos VirusTotal Malware PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Windows DNS DDNS
2 5 7 11.2 M 29 ZeroCERT

12588 2023-06-03 17:31 document_C560_Jun_2.js  

3a6a29b0cfe1132fba17d10f096e4104

VirusTotal Malware crashed
0.6 3 ZeroCERT

12589 2023-06-03 17:31 document_C540_Jun_2.js  

6c6de7c1260f8b8dc6bc8505cac4288a

VirusTotal Malware unpack itself crashed
1.0 6 ZeroCERT

12590 2023-06-03 17:29 obizx.doc  

bb05581c977504151945ce548b13daf8


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash IP Check Tofsee Windows Exploit DNS crashed
2 4 6 4.8 M 28 ZeroCERT

12591 2023-06-03 17:29 hkcmd.exe  

616f84ed1a058d9b51efa2eb6007dd4e


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 M 49 ZeroCERT

12592 2023-06-03 17:27 H2.exe  

200f70cceffbcc69815d125f1ca40fd8


AgentTesla RAT browser info stealer Google Chrome User Data Downloader Confuser .NET Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger AntiDebug AntiVM PE64 PE File Remcos VirusTotal Malware PDB MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself DNS DDNS
1 4 3 8.6 M 37 ZeroCERT

12593 2023-06-03 17:27 setup.exe  

8072726bf6f29230d619ec971b3d2a29


UPX Malicious Library AntiDebug AntiVM OS Processor Check PE File PE32 Browser Info Stealer RedLine Malware download FTP Client Info Stealer VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Collect installed applications installed browsers check Stealer Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 3 12.2 M 42 ZeroCERT

12594 2023-06-03 17:25 teambzx.doc  

8a5c3b0f57f61e18ff31ae4903f479fa


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash IP Check Tofsee Windows Exploit DNS crashed
3 7 7 5.6 M 33 ZeroCERT

12595 2023-06-03 17:25 iuiiiuiuiuiuiuiuiui%23%23%23%2...  

ff889dabeb89be61eb1ece635fb12ec2


MS_RTF_Obfuscation_Objects RTF File doc LokiBot Malware download VirusTotal Malware c&c Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
2 2 12 5.2 M 20 ZeroCERT

12596 2023-06-03 17:23 hkcmd.exe  

ab22e6f54ff1b1f6862780ca9a7dddaa


Loki Loki_b Loki_m Formbook Socket DNS PWS[m] AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious process malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 1 7 1 13.8 M 25 ZeroCERT

12597 2023-06-03 17:22 mimimimimimimi%23%23%23%23%23%...  

f4b2703a921facad2c48fdecca12ae21


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware RWX flags setting exploit crash Exploit crashed
3.0 M 28 ZeroCERT

12598 2023-06-02 18:55 Password_2022_Installer.rar  

255ec60f26fc08b0b1a3ef793ad33bfb


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM Malware download Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself Lumma Stealer DNS
1 1 2 3.8 ZeroCERT

12599 2023-06-02 18:51 Password_2022_Installer.rar  

255ec60f26fc08b0b1a3ef793ad33bfb


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM suspicious privilege Check memory Checks debugger unpack itself
1.6 ZeroCERT

12600 2023-06-02 18:46 rh2605.exe  

ed5185618f3583ea107d1aa500e729f6

ZeroCERT