Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
12946 2021-09-29 16:28 1.dll  

25492a4aa466acceafbff245d285951d


UPX Malicious Library PE File OS Processor Check DLL PE32 VirusTotal Malware PDB Checks debugger unpack itself suspicious process
2.0 3 ZeroCERT

12947 2021-09-29 16:29 eresizebar.png  

38333394081277d2b69533f1376dbb9c


Emotet Gen1 UPX Malicious Library PE File OS Processor Check PE32 suspicious privilege buffers extracted unpack itself Check virtual network interfaces suspicious process ComputerName DNS crashed
5 6.0 ZeroCERT

12948 2021-09-29 17:18 Shipping Documents-BL#SE201000...  

8993ca9025df7cdfee64edc454377def


Generic Malware UPX PE File PE32 VirusTotal Malware Buffer PE suspicious privilege MachineGuid Check memory Checks debugger buffers extracted RWX flags setting unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check Tofsee Windows ComputerName DNS DDNS
1 6 2 8.4 M 42 r0d

12949 2021-09-30 09:16 OneDrive.exe  

69bd982f6a9e73a9576f4d1068bd4213


RAT Generic Malware Malicious Packer PE File .NET EXE PE32 Malware download njRAT VirusTotal Malware PDB suspicious privilege Check memory Checks debugger ICMP traffic unpack itself ComputerName
2 1 4.2 50 ZeroCERT

12950 2021-09-30 09:16 28347623.jpg  

481bd2e89355de9a8e2393eec9ee41d7


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.8 M 42 ZeroCERT

12951 2021-09-30 09:27 quasarnoins204cc.exe  

5bab799012d71881094f838df21f4255


RAT PWS .NET framework Generic Malware Malicious Library PE File OS Processor Check .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself
2.0 M 52 ZeroCERT

12952 2021-09-30 09:32 ABG.exe  

d51f8036b14a72ad278e0c0d1202ebbe


AgentTesla PWS .NET framework browser info stealer Generic Malware Google Chrome User Data Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection Downloader AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself suspicious process Windows DNS DDNS crashed keylogger
2 2 12.2 14 ZeroCERT

12953 2021-09-30 09:34 toolspab2.exe  

539cd7419efcd8142d20462511e931d3


Malicious Library AntiDebug AntiVM PE File OS Processor Check PE32 Malware PDB Code Injection Checks debugger buffers extracted unpack itself Remote Code Execution DNS
1 7.2 ZeroCERT

12954 2021-09-30 09:36 Zenar_protected.exe  

ab40d2395f7abeee43552ae6a750044d


Themida Packer PE64 PE File VirusTotal Malware unpack itself Windows crashed
2.6 27 ZeroCERT

12955 2021-09-30 09:37 vbc.exe  

01a73a74c0f01ff769fcd5fcaae92598


UPX PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself Remote Code Execution
2.2 38 ZeroCERT

12956 2021-09-30 09:38 vbc.exe  

2fb19e7e14e4adb6c338dbe3f8a91f13


Generic Malware Malicious Packer UPX PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself Remote Code Execution
2.8 43 ZeroCERT

12957 2021-09-30 09:55 raccon.exe  

82df7652b58044a29cf7b6097b11f9e4


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.4 25 ZeroCERT

12958 2021-09-30 09:59 AV.ps1  

33d960d4ad9c3c95a8397a8f1d7a151e


Generic Malware Antivirus AntiDebug AntiVM Malware download njRAT Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself WriteConsoleW ComputerName
2 1 8.4 ZeroCERT

12959 2021-09-30 10:00 PowerRun.exe  

71c7975385f73ae32b06f69dbe79290b


PowerShell MZ Generic Malware Malicious Library Antivirus PE File OS Processor Check PE32 suspicious privilege Check memory Checks debugger unpack itself sandbox evasion human activity check crashed
2.2 ZeroCERT

12960 2021-09-30 10:01 OneDriveV2.exe  

ae4019c955855d44d63992904e7f8a65


Generic Malware Malicious Packer PE File .NET EXE PE32 Malware download njRAT VirusTotal Malware PDB suspicious privilege Check memory Checks debugger ICMP traffic unpack itself ComputerName
2 1 4.2 46 ZeroCERT