Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12856 2023-05-26 19:36 Install_pass1234.7z  

9af61e3db077635a809314b1ed057938


PWS[m] Escalate priviledges KeyLogger AntiDebug AntiVM Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself IP Check Tofsee DNS
5 11 2 2 4.2 M ZeroCERT

12857 2023-05-26 19:28 jjjiijjjiijjjiijjji%23%23%23%2...  

e3b452029e1713145f0d95258fc64b3c


MS_RTF_Obfuscation_Objects RTF File doc Malware download Remcos VirusTotal Malware Malicious Traffic buffers extracted exploit crash Windows Exploit DNS DDNS crashed
3 7 8 1 4.8 M 28 ZeroCERT

12858 2023-05-26 18:19 swiss.exe  

9e57567ee21222fa361798821a9571aa


NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL Browser Info Stealer Malware download AveMaria NetWireRC VirusTotal Email Client Info Stealer Malware AutoRuns MachineGuid Check memory buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Interception Windows Browser RAT Email ComputerName DNS DDNS
5 4 9.4 M 35 ZeroCERT

12859 2023-05-26 18:19 plugmanzx.exe  

03dc66eb73f94113115e145a35599724


AgentTesla PWS .NET framework browser info stealer Google Chrome User Data Downloader Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Remcos VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows DNS DDNS keylogger
1 4 1 10.6 M 24 ZeroCERT

12860 2023-05-26 17:53 CT360.exe  

89f34702802ca7e99421d765d8404b8e


PE File PE32 VirusTotal Malware WMI ComputerName
3.4 M 38 ZeroCERT

12861 2023-05-26 17:51 jijijijiiiiji#################...  

211091ff25b68364c7973844af7a44d4


MS_RTF_Obfuscation_Objects RTF File doc LokiBot Malware download VirusTotal Malware c&c Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS crashed
2 3 13 5.4 M 34 ZeroCERT

12862 2023-05-26 17:51 mslink1.exe  

56f7220f0987dc74bc0d5bb27f3df3ca


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself
2.0 M 35 ZeroCERT

12863 2023-05-26 17:51 grammyzx.exe  

6f5596133ba51b66fa2467610e1084d8


PWS .NET framework SMTP PWS[m] KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
9.0 M 20 guest

12864 2023-05-26 17:50 IE_NET.exe  

9e925b69e3dbb48c606de897284d31ae


AgentTesla PWS .NET framework RAT browser info stealer Generic Malware Google Chrome User Data Downloader UPX Antivirus ScreenShot Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger AntiDebug AntiVM OS Processor Check Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AntiVM_Disk sandbox evasion VM Disk Size Check Windows Browser Email ComputerName DNS Cryptographic key DDNS keylogger
1 6 3 14.8 M 27 ZeroCERT

12865 2023-05-26 17:49 IE_NET.exe  

691533800613bff43f0e1845240bd42e


Loki Loki_b Loki_m PWS .NET framework Socket DNS PWS[m] AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Software
1 1 7 1 14.2 M 21 ZeroCERT

12866 2023-05-26 17:48 word.exe  

b9a5e05efb6100a069525b12b0d5bbab


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself crashed
2.0 M 21 ZeroCERT

12867 2023-05-26 17:46 jjjiijjjiijjjiijjji%23%23%23%2...  

e3b452029e1713145f0d95258fc64b3c


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware buffers extracted RWX flags setting exploit crash Exploit crashed
3.4 M 28 ZeroCERT

12868 2023-05-26 17:46 IE_NET.exe  

a02d63d3aa1793aca12ed3d79ac4870c


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware unpack itself
1.6 M 42 ZeroCERT

12869 2023-05-26 17:44 646ff88cd208a.zip  

9aecd71a5365d68f8b4956239956a45b


ZIP Format Malware download NetWireRC Malware Malicious Traffic RAT NetSupport
3 4 3 0.8 guest

12870 2023-05-26 16:16 Wire Confirmation copy_pdf.vbs  

3c3f290c26ea0dbf9df8b05bc5eb6c1b

VirusTotal Malware crashed
0.8 10 guest