Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12886 2023-05-26 09:13 646ff8e66b17a.ps1  

7e02353fe6383628da722c7c895ef755


Generic Malware Antivirus PowerShell powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
4.4 ZeroCERT

12887 2023-05-25 18:21 up-do-dat-M2u7HcEuL9S7AFLW.exe  

6f66d806f252bb81ed8954dceed8cce9


njRAT Generic Malware UPX .NET EXE PE File PE32 VirusTotal Malware PDB Check memory Checks debugger unpack itself crashed
2.8 34 ZeroCERT

12888 2023-05-25 18:19 poweroff.exe  

4ab4f24b913575f5dbaf2f17a6b5a2b1


PWS .NET framework njRAT RAT UPX .NET EXE PE File PE32 VirusTotal Malware PDB MachineGuid Check memory Checks debugger unpack itself
2.8 33 ZeroCERT

12889 2023-05-25 17:53 vtshfowlzpky.exe  

2427dc12a5685106ea301efc43e99701


Generic Malware UPX Malicious Library Malicious Packer OS Processor Check PE64 PE File VirusTotal Malware crashed
1.0 M 21 ZeroCERT

12890 2023-05-25 17:51 INET_CACHE.exe  

4bbbad7edcd5cd1e3e8b298236a94ebb


Anti_VM .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself DNS
1 2.6 M 45 ZeroCERT

12891 2023-05-25 17:49 newamka2.1.exe  

21ffcbf147759f82745f07bfdb0662f4


NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL Malware download AveMaria NetWireRC VirusTotal Malware AutoRuns MachineGuid Check memory Creates executable files unpack itself AppData folder Windows RAT ComputerName DNS DDNS keylogger
5 4 5.8 M 37 ZeroCERT

12892 2023-05-25 17:48 PEP2.exe  

0b79fbf16b76bd0ff14e9d079e40e889


Emotet PWS .NET framework njRAT RAT Gen1 Generic Malware UPX Malicious Library MZP Format PE File PE32 .NET EXE OS Processor Check DLL PE64 VirusTotal Malware AutoRuns MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Check virtual network interfaces AppData folder Tofsee Windows ComputerName DNS crashed
13 13 5 7 8.2 M 39 ZeroCERT

12893 2023-05-25 17:44 clp5.exe  

a541e034129465229c0fe10ecfcb2703


UPX Malicious Library OS Processor Check PE64 PE File VirusTotal Malware
1.4 M 26 ZeroCERT

12894 2023-05-25 17:42 vbc.exe  

06168af4a9d358eab028fb62b550299f


UPX Antivirus .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself Windows Cryptographic key
2.2 M 52 ZeroCERT

12895 2023-05-25 17:40 black.pif  

35b9124a72b939bddecd642532c56d4f


Formbook Generic Malware Antivirus PWS[m] KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AgentTesla PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities Check virtual network interfaces suspicious process WriteConsoleW IP Check Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed keylogger
2 3 2 16.0 M 35 ZeroCERT

12896 2023-05-25 17:40 Setup_x32_x64.exe  

c51e82e2c7a0f3b68d02fc988f764f8f


UPX Malicious Library VMProtect OS Processor Check PE File PE32 VirusTotal Malware Telegram MachineGuid Malicious Traffic Check memory Creates executable files RWX flags setting unpack itself Tofsee ComputerName DNS
4 6 4 5.8 M 34 ZeroCERT

12897 2023-05-25 17:38 johnftp.pif  

24fc1b788089d81c274e16e075676e6d


PWS .NET framework Generic Malware Antivirus PWS[m] KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities suspicious process WriteConsoleW Windows Browser Email ComputerName Cryptographic key Software crashed
13.4 M 49 ZeroCERT

12898 2023-05-25 17:37 IEIEIEIEIE%23%23%23%23%23%23%2...  

1c963374f3c33e9136fb1bafc156938f


MS_RTF_Obfuscation_Objects RTF File doc Malware download Remcos VirusTotal Malware Malicious Traffic buffers extracted exploit crash unpack itself Windows Exploit DNS DDNS crashed
3 5 9 5.4 M 35 ZeroCERT

12899 2023-05-25 15:12 po-docs-may24.exe  

14d2501921d7cf94f36f5deb78c93982


Dbatloader UPX Malicious Library Admin Tool (Sysinternals etc ...) MZP Format PE File PE32 VirusTotal Malware RWX flags setting unpack itself Tofsee crashed
2 1 3.2 M 30 r0d

12900 2023-05-25 14:50 Iu3HbEA1IfVFPRf.exe  

dafbec53a5d8e7e9f419a67a1846bb2f


Generic Malware Antivirus DNS AntiDebug AntiVM .NET EXE PE File PE32 VirusTotal Malware powershell Buffer PE AutoRuns PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key DDNS
4 3 14.8 22 ZeroCERT