Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12901 2023-05-25 13:18 d.hta  

c808f7c2c8b88c92abf095f10afae803


Formbook RAT JPEG Format Check memory RWX flags setting unpack itself Check virtual network interfaces Tofsee ComputerName
2 2 2.2 ZeroCERT

12902 2023-05-25 11:07 GuessableInapti.js  

c2951dc43814c87f30815f802c3d27e7


Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
7 5.6 ZeroCERT

12903 2023-05-25 10:59 d.hta  

c808f7c2c8b88c92abf095f10afae803


Formbook RAT unpack itself crashed
0.6 ZeroCERT

12904 2023-05-25 10:53 apt37.lnk  

7095811df4cb1ee4135ce605af7f163f


Generic Malware Downloader Antivirus Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot Hide_URL PDF AntiDebug AntiVM GIF Format .NET DLL DLL PE Fil VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger heapspray Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder sandbox evasion WriteConsoleW installed browsers check Windows Browser ComputerName Cryptographic key
1 2 13.8 27 ZeroCERT

12905 2023-05-25 10:53 PMTRD.bat  

5f9e0afb3503d909984b3b30d038bdc5


Generic Malware Downloader Antivirus Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot Hide_URL AntiDebug AntiVM .NET DLL DLL PE File PE32 powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Windows ComputerName Cryptographic key
1 2 9.8 ZeroCERT

12906 2023-05-25 10:47 exosporeEloper.js  

30b9760a9d321a493485d3478333b8ba


Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
6 5.6 ZeroCERT

12907 2023-05-25 10:45 exocoetidae.js  

6fb012a2b6d44621cd97ec623362180f


Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
6 5.6 ZeroCERT

12908 2023-05-25 10:45 envenomation.js  

c33d868374d8dc29858a094689ce231c


Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself suspicious process Windows ComputerName Cryptographic key
5 5.6 ZeroCERT

12909 2023-05-25 10:45 pessonal pic.png.lnk  

1afc64e248b3e6e675fa31d516f0ee63


Generic Malware AntiDebug AntiVM GIF Format VirusTotal Malware Code Injection Check memory Creates shortcut RWX flags setting unpack itself suspicious process Tofsee Interception
1 2 2 4.0 12 ZeroCERT

12910 2023-05-25 10:21 Personal.zip  

05eb7152bc79936bea431a4d8c97fb7b


ZIP Format VirusTotal Malware Tofsee
1 2 2 0.6 M 11 guest

12911 2023-05-25 09:41 dwm.exe  

69599d9e3f0215c8322482c5787119c4


Formbook PWS[m] AntiDebug AntiVM .NET EXE PE File PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
7 7 2 6 9.8 M 33 ZeroCERT

12912 2023-05-25 09:38 k2.exe  

fdb8081ac26d8de3f7582b2616bcf3e8


PWS .NET framework RAT .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself ComputerName DNS
1 2.8 M 29 ZeroCERT

12913 2023-05-25 09:36 vulcancontrol.exe  

4482bb2674adc80b247a13e6901d6945


UPX Malicious Library Malicious Packer PE64 PE File VirusTotal Malware
1.0 7 ZeroCERT

12914 2023-05-25 09:36 macilak2.1.exe  

1923b005546de11d38b39e4d3874c045


NSIS UPX Malicious Library PE File PE32 DLL Malware download AveMaria NetWireRC VirusTotal Malware AutoRuns MachineGuid Check memory Creates executable files unpack itself AppData folder human activity check Windows RAT ComputerName DNS DDNS keylogger
2 4 5.6 M 34 ZeroCERT

12915 2023-05-25 09:33 CK_CACHE.exe  

f3c3805d41ca881e16a9998f0bfc2444


UPX .NET EXE PE File PE32 VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.2 M 44 ZeroCERT