Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13006 2021-10-01 18:18 58.exe  

e2940574458fd1cc3235a22b30f48fdd


Malicious Library PE File PE32 VirusTotal Malware PDB unpack itself
2.2 M 27 ZeroCERT

13007 2021-10-01 18:18 file.exe  

5861a5c311151e853ce704c5268981d6


Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.6 M 38 ZeroCERT

13008 2021-10-01 18:20 RepinersBouillons_1kEU.exe  

9922c2a3df88961fe463013f74e5d999


Malicious Library PE File PE32 VirusTotal Malware PDB unpack itself
1.8 M 20 ZeroCERT

13009 2021-10-01 18:21 1110888466.exe  

1330be0f9459506cfd3d972082f3cb0e


Malicious Library AntiDebug AntiVM PE File OS Processor Check PE32 JPEG Format Browser Info Stealer FTP Client Info Stealer VirusTotal Malware Buffer PE PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications Check virtual network interfaces AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 3 15.6 M 21 ZeroCERT

13010 2021-10-01 18:23 vbc.exe  

e679e225d76dff7f96af4a858a89d492


Gen1 Malicious Library PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.6 M 32 ZeroCERT

13011 2021-10-01 18:23 adobe.exe  

548417c807756a84d075b3e3db1b2279


PWS .NET framework email stealer Generic Malware DNS Socket Escalate priviledges KeyLogger Code injection Downloader persistence AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName DNS crashed
1 12.8 M 25 ZeroCERT

13012 2021-10-01 18:25 photo.exe  

805eaea77ff2656f8f7b606c88bb6ddb


PWS .NET framework email stealer Generic Malware DNS Socket Escalate priviledges KeyLogger Code injection Downloader persistence AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI unpack itself Windows utilities suspicious process AntiVM_Disk WriteConsoleW VM Disk Size Check Windows ComputerName DNS crashed
1 12.6 M 19 ZeroCERT

13013 2021-10-01 18:27 WCleanerFile721.exe  

5e30cd05f19ca715123162afea3df154


RAT Generic Malware PE File .NET EXE PE32 VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Check virtual network interfaces DNS
3 10 6.0 M 21 ZeroCERT

13014 2021-10-01 18:30 lv.exe  

7999613726fe998b0c316a715d7801b0


Emotet Gen1 Gen2 Themida Packer Generic Malware Malicious Library Anti_VM UPX Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Hijack Network Internet API FTP ScreenShot Http API Steal credentia VirusTotal Malware AutoRuns Code Injection Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk WriteConsoleW VM Disk Size Check Windows crashed
1 7.2 M 31 ZeroCERT

13015 2021-10-01 22:21 etooltipred.png  

134f1f2775c50bb1da18c87ae2232f35


Emotet Gen1 Malicious Packer UPX Malicious Library PE File OS Processor Check PE32 Malware PDB suspicious privilege Malicious Traffic buffers extracted unpack itself Check virtual network interfaces suspicious process ComputerName DNS crashed
1 7 6.4 ZeroCERT

13016 2021-10-01 22:21 gscript.exe  

4a1e23e8a070b3482184b8adff7f7071


RAT Generic Malware Antivirus Malicious Packer PE64 PE File VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
7.6 22 ZeroCERT

13017 2021-10-01 22:22 ferrarr.exe  

151150f1623ec344306be5c20627f3e9


Malicious Library PE File PE32 PDB unpack itself Remote Code Execution
1.2 ZeroCERT

13018 2021-10-01 22:23 5.exe  

f04728ce0ea25c31c9546ba066e36fc1


RAT Generic Malware Antivirus Malicious Packer DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Internet API FTP ScreenShot Http API Steal credential Downloader P2P AntiDebug AntiVM PE File PE32 PE64 VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
8.2 42 ZeroCERT

13019 2021-10-01 22:25 eflyairplane.png  

5615996369711fc19507eb2dfaacf75c


Emotet Gen1 Malicious Packer UPX Malicious Library PE File OS Processor Check PE32 Malware PDB suspicious privilege MachineGuid Malicious Traffic buffers extracted ICMP traffic unpack itself Check virtual network interfaces suspicious process ComputerName DNS crashed
1 4 7.4 ZeroCERT

13020 2021-10-01 22:25 hy76tg.exe  

c1e0df4f2321e9375baee3a0a26fba64


NPKI Generic Malware Malicious Packer UPX Anti_VM Malicious Library Antivirus PE64 PE File .NET DLL DLL PE32 VirusTotal Malware powershell suspicious privilege MachineGuid Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote suspicious process AppData folder Windows ComputerName Cryptographic key crashed
9.0 35 ZeroCERT