Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12796 2023-05-29 23:08 http://123.175.114.112:54069/M...  


Downloader Create Service DGA Socket DNS Hijack Network Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges persistence FTP KeyLogger ScreenShot AntiDebug AntiVM PNG Format MSOffice File JPEG Format VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 2 6.4 guest

12797 2023-05-29 22:05 File_pass1234.7z  

0d6f6b6bd8f63cb7ea5854d7fb265cb4


AntiDebug AntiVM VirusTotal Email Client Info Stealer Malware suspicious privilege Checks debugger Creates shortcut unpack itself installed browsers check Browser Email ComputerName
3.8 M 6 guest

12798 2023-05-29 20:42 2.exe  

294fab1523dc3b50cbcc120e67946a5b


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware DNS
1 3.4 M 56 guest

12799 2023-05-29 18:22 blessed.exe  

4ddfcaf4794dc757f9f4806af87b233d


Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName Cryptographic key Software crashed
10.0 M 34 ZeroCERT

12800 2023-05-29 18:22 ddd.xlsb  

0e65c589e0c6edffb3b305e7595a271b


ZIP Format Excel Binary Workbook file format(xlsb) VirusTotal Malware unpack itself DNS
1.8 3 ZeroCERT

12801 2023-05-29 18:21 https://blitzz.com.ar/wp-conte...  

0d6f6b6bd8f63cb7ea5854d7fb265cb4


Downloader Create Service DGA Socket DNS Hijack Network Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges persistence FTP KeyLogger ScreenShot AntiDebug AntiVM PNG Format MSOffice File JPEG Format VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 2 4.8 M 6 guest

12802 2023-05-29 18:20 %23%23%23%23%23%23%23%23%23%23...  

2649a0cdd385220ace4898e1f3f5b377


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic buffers extracted RWX flags setting exploit crash Windows Exploit DNS crashed
1 1 6 5.6 35 ZeroCERT

12803 2023-05-29 13:57 redline.exe  

2d0d9f29bca70bdde306f8b5188117ce


PWS .NET framework RAT UPX Confuser .NET OS Processor Check .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware suspicious privilege Check memory Checks debugger buffers extracted unpack itself Collect installed applications installed browsers check Windows Browser ComputerName DNS Cryptographic key Software crashed
1 6.2 M 53 ZeroCERT

12804 2023-05-29 13:55 OGQ5YTll.exe  

33aafdcbbee5896be71abe19e26000db


RAT Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows Browser Email ComputerName Cryptographic key Software crashed
9.6 M 53 ZeroCERT

12805 2023-05-29 13:52 toolspub2.exe  

3a66a27b79651f7c45a136a08a44a571


UPX Malicious Library AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Code Injection Checks debugger buffers extracted unpack itself
6.6 M 54 ZeroCERT

12806 2023-05-29 13:50 YzlhMGI2.doc  

c3681f1d0664c277cec547bd6f1824ef


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash IP Check Tofsee Windows Exploit DNS crashed
2 3 6 5.0 M 38 ZeroCERT

12807 2023-05-29 13:49 OGQ5YTll.doc  

c460a03f63c3c77e60c5af1f792ac6d2


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic exploit crash unpack itself IP Check Tofsee Windows Exploit DNS crashed
2 5 6 5.0 M 36 ZeroCERT

12808 2023-05-29 13:48 Y2Q0MzM1.exe  

53ddfea8b518d5dcb6e1db29b8405187


Gen1 Emotet PWS .NET framework RAT RedLine Stealer UPX Malicious Library Admin Tool (Sysinternals etc ...) Confuser .NET Malicious Packer SMTP Code injection HTTP PWS[m] Http API Internet API AntiDebug AntiVM CAB PE File PE32 OS Processor Check DLL .NE Browser Info Stealer Malware download Amadey FTP Client Info Stealer VirusTotal Malware AutoRuns PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
5 3 7 3 21.8 M 47 ZeroCERT

12809 2023-05-29 13:48 dWssvZasqwFFAcZ.dll  

40baa5d920652df72ba2f3c9df27ffe1


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself
1.8 M 27 ZeroCERT

12810 2023-05-29 13:46 NmI5NGQx.exe  

ff56e0a4736897e92bd468d862fd9249


Gen1 Emotet PWS .NET framework RAT RedLine Stealer UltraVNC UPX Malicious Library Confuser .NET CAB PE File PE32 .NET EXE OS Processor Check VirusTotal Malware AutoRuns PDB Check memory Checks debugger Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check Windows Remote Code Execution DNS Cryptographic key
1 6.4 M 56 ZeroCERT