Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12646 2021-09-22 22:14 yes.exe  

e3cbb2e3f1de0e9161429b42fcb12e59


Generic Malware Anti_VM PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Windows Firmware DNS Cryptographic key crashed
1 7.6 M 19 ZeroCERT

12647 2021-09-22 22:14 vbc.exe  

6e1476a40e4f1b65294f5ff5df9f99d7


RAT PWS .NET framework Generic Malware UPX AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself ComputerName
9 19 2 8.6 M 17 ZeroCERT

12648 2021-09-22 22:16 vbc.exe  

a96ab325cb199f7130a1496e377cdb58


Loki PWS Loki[b] Loki.m RAT .NET framework Generic Malware DNS Socket AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName Software
1 2 7 1 12.8 M 18 ZeroCERT

12649 2021-09-22 22:16 vbc.exe  

415ec37f083919417aefd51bdfaa3831


UPX PE File PE32 VirusTotal Malware Remote Code Execution
1.0 M 22 ZeroCERT

12650 2021-09-22 22:18 8d6d7.exe  

cb9a037aaff7548550a2923c73d6b612


Malicious Library PE File PE32 VirusTotal Malware PDB unpack itself
1.8 M 28 ZeroCERT

12651 2021-09-22 22:18 download2.php  

6e96da1afcb4f380b8a198f096ab70ab

VirusTotal Malware
1.0 M 30 ZeroCERT

12652 2021-09-22 22:20 8.exe  

54e127a42f86ce2577e926a8c178bcca


Generic Malware Themida Packer Anti_VM Malicious Library PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Firmware Cryptographic key Software crashed
1 4 1 11.2 M 42 ZeroCERT

12653 2021-09-22 22:21 5.exe  

5c03d52d98f6c01ea66e09f5993aebc2


RAT Generic Malware PE File .NET EXE PE32 PE64 OS Processor Check PNG Format Browser Info Stealer FTP Client Info Stealer VirusTotal Malware AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
2 7 4 15.6 M 35 ZeroCERT

12654 2021-09-22 22:23 vbc.exe  

1b4d9985eae2737b8cc344aef840ec85


RAT PWS .NET framework Generic Malware UPX Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
1 2 1 1 12.2 M 39 ZeroCERT

12655 2021-09-22 22:23 lv.exe  

b8ce3bfde204d00436c9af5d970a8d9b


Gen1 Gen2 Themida Packer Generic Malware Malicious Library Anti_VM Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credential Downloade VirusTotal Malware Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs Windows crashed
1 6.0 M 35 ZeroCERT

12656 2021-09-22 22:25 hussanzx.exe  

88f75a26375befa941b2b57d7e302c32


PWS Loki[b] Loki.m RAT .NET framework Generic Malware DNS Socket AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Software crashed
1 1 6 1 16.8 M 27 ZeroCERT

12657 2021-09-22 22:25 rsoft.exe  

31ce4f326c616ad189f2b03bdee1e20d


PE File PE32 VirusTotal Malware MachineGuid Malicious Traffic buffers extracted unpack itself Checks Bios Detects VirtualBox Detects VMWare VMware anti-virtualization Tofsee Windows Firmware DNS crashed
2 3 1 8.8 M 31 ZeroCERT

12658 2021-09-22 22:27 navitas_employee_survey.hta  

537363b3738a8e0726ae15e6bc4fc314

VirusTotal Malware Check memory unpack itself
2 2 1.8 M 25 ZeroCERT

12659 2021-09-22 22:28 WORD.exe  

a2f81b2021d159eaf2c7bcac2dfbeacb


RAT Generic Malware Antivirus DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW human activity check Tofsee Windows ComputerName DNS Cryptographic key DDNS crashed
1 5 2 17.4 M 23 ZeroCERT

12660 2021-09-22 22:29 863387648.exe  

8df6d5b6ce4864ae629684b7566ebaa7


RAT Generic Malware Malicious Packer Antivirus PE64 PE File VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 48 ZeroCERT