Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12856 2021-09-28 13:54 deck.exe  

0c475e87bf5b65bb5dc3d65f9d7c09b9


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName crashed
12.4 M 34 ZeroCERT

12857 2021-09-28 13:56 file.exe  

92e158b53761eed28e95649864220f59


RAT PWS .NET framework Generic Malware DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Buffer PE suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS crashed
2 1 12.6 M 34 ZeroCERT

12858 2021-09-28 13:56 kik.exe  

5dbc92f12615f939b715a2f6f0c6eb51


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
1 2 1 13.4 M 18 ZeroCERT

12859 2021-09-28 13:58 winpro.exe  

fa0b89043edf03a3e3c27f0ad56114ea


UPX PE File PE32 VirusTotal Malware RWX flags setting unpack itself Remote Code Execution DNS crashed
1 3.8 M 44 ZeroCERT

12860 2021-09-28 13:59 build.exe  

6bacb42179eb54d6afac2664cd0227d7


PWS Loki[b] Loki.m AgentTesla browser info stealer Malicious Library ScreenShot DGA DNS Socket Internet API Http API AntiDebug AntiVM PE File OS Processor Check PE32 Malware download Dridex Malware Microsoft AutoRuns PDB Code Injection Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities AppData folder malicious URLs suspicious TLD WriteConsoleW Tofsee Windows ComputerName Remote Code Execution DNS crashed
1 8 12 12.8 M ZeroCERT

12861 2021-09-28 14:00 apines1.exe  

1ca5f33ffb87f631cf17e4fcd06eafc1


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 M 48 ZeroCERT

12862 2021-09-28 14:01 vbc.exe  

99a3a6cca4b9fb67453930f721dfd151


Malicious Library PE File PE32 VirusTotal Malware PDB unpack itself
2.6 M 43 ZeroCERT

12863 2021-09-28 14:02 ikk.exe  

97665ac797f97f72b4955afb20da34e8


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName crashed
11.6 M 41 ZeroCERT

12864 2021-09-28 14:03 audio.exe  

e3f5f3da3e77109020dc85f26eb9e52e


RAT PWS .NET framework email stealer Generic Malware DNS Escalate priviledges KeyLogger Code injection Downloader persistence AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName DNS crashed
1 12.2 M 22 ZeroCERT

12865 2021-09-28 14:05 build2.exe  

7c48019f424bbd08de9d0c7d66e0ea7c


PWS Loki[b] Loki.m AgentTesla browser info stealer Malicious Library ScreenShot AntiDebug AntiVM PE File OS Processor Check PE32 VirusTotal Malware PDB Code Injection Checks debugger buffers extracted unpack itself Tofsee Remote Code Execution DNS crashed
2 3 7.0 M 52 ZeroCERT

12866 2021-09-28 14:05 raccon.exe  

576a11fa707efc78fd342f28c6fadebf


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution DNS
1 3.0 M 27 ZeroCERT

12867 2021-09-28 14:07 harshmanzx.exe  

dff3bf025dcd487a2f0fb22b4ccf8998


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself suspicious TLD DNS
1 3 2 8.4 M 22 ZeroCERT

12868 2021-09-28 14:09 388_HYwcIAQXs5xdq7q.exe  

001122f11ae95a3c00eb3e76541bc264


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName
3 6 1 9.6 M 25 ZeroCERT

12869 2021-09-28 14:11 wzii.exe  

e8eb1d835fd733f602eb17c120e14c68


PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW Windows ComputerName crashed
11.6 M 43 ZeroCERT

12870 2021-09-28 15:52 Final.txt.ps1  

558b36f8a32ae12313078e388acfaa87


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key
1 2 1 8.6 11 ZeroCERT