Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13036 2023-05-24 10:32 publicsuffixes.gz  

1846069883f33a8375ab714eb3927194

guest

13037 2023-05-24 09:17 IP_NETWORK.exe  

2eb1882f1a3ffcaadee754631a63c148


Loki Loki_b Loki_m PWS .NET framework Socket DNS PWS[m] AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c PDB suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName DNS Software
1 1 6 1 13.0 M 27 ZeroCERT

13038 2023-05-24 09:15 SAW_BYDESCONNET.exe  

09716fd4d7ab6e6577fc038e56bec7d2


UPX Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) Antivirus OS Processor Check MZP Format PE File PE32 VirusTotal Malware unpack itself suspicious process Remote Code Execution
2.8 M 33 ZeroCERT

13039 2023-05-24 09:14 3eef203fb515bda85f514e168abb59...  

04baaac6f3c193fb50667bc8059af2b5


UPX Malicious Library OS Processor Check PE File PE32 VirusTotal Malware PDB unpack itself
2.2 M 52 ZeroCERT

13040 2023-05-24 09:14 a03.exe  

02eceb12980e60c1496eb6b9a02d3483


Raccoon Stealer Gen1 Gen2 Malicious Library Malicious Packer VMProtect UPX AntiDebug AntiVM PE File PE32 OS Processor Check DLL PNG Format JPEG Format Browser Info Stealer Malware download VirusTotal Malware RecordBreaker Buffer PE AutoRuns MachineGuid Code Injection Malicious Traffic Check memory buffers extracted Creates executable files ICMP traffic RWX flags setting unpack itself Windows utilities Collect installed applications AppData folder WriteConsoleW installed browsers check Tofsee Stealer Windows Browser DNS
10 5 8 15.6 M 42 ZeroCERT

13041 2023-05-24 09:12 ray.exe  

d29f7f2967179adb21e755ef4e2fb713


PWS .NET framework Admin Tool (Sysinternals etc ...) KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed
1 2 1 12.4 M 44 ZeroCERT

13042 2023-05-24 08:29 https://horriblysparkling.com  

9dc68036e68ff9d02505e6a47f185b87


Downloader Create Service DGA Socket DNS Hijack Network Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges persistence FTP KeyLogger ScreenShot AntiDebug AntiVM PNG Format JPEG Format MSOffice File VirusTotal Malware Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
1 3 2 4.6 guest

13043 2023-05-23 17:33 wdagad.exe  

79931719ae9c21e1d8c5f1a419e85f71


RAT Generic Malware Downloader UPX Malicious Library MPRESS Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot AntiDebug AntiVM OS Processor Check P VirusTotal Malware PDB Code Injection Creates executable files unpack itself AppData folder Remote Code Execution crashed
5.2 M 29 ZeroCERT

13044 2023-05-23 17:31 vbc.exe  

73a8a9702255cbfe07e92e81ccec6dca


NSIS UPX Malicious Library Downloader PE File PE32 DLL Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Check virtual network interfaces AppData folder IP Check Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
1 4 2 11.6 M 40 ZeroCERT

13045 2023-05-23 17:31 003079999209.pdf.scr  

0957864375a690abcea81ce440d762f8


Suspicious_Script_Bin Generic Malware UPX Malicious Library Antivirus DNS AntiDebug AntiVM OS Processor Check PE File PE32 VirusTotal Malware Buffer PE AutoRuns PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files ICMP traffic unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder sandbox evasion WriteConsoleW human activity check Windows ComputerName Remote Code Execution DNS DDNS
4 3 20.2 37 ZeroCERT

13046 2023-05-23 17:28 csrss.exe  

ef9d99538803de5140aa18eeb3b958b3


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check DLL PE64 PNG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder anti-virtualization DNS crashed
1 4.2 M 21 ZeroCERT

13047 2023-05-23 17:26 aDTUAh4aJrmzMHA.exe  

ae3300545a8b7b614d5d974e70769052


RAT UPX SMTP KeyLogger AntiDebug AntiVM OS Processor Check .NET EXE PE File PE32 Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee Windows Browser Email ComputerName DNS Cryptographic key Software crashed keylogger
3 2 15.0 M 52 ZeroCERT

13048 2023-05-23 17:26 vbc.exe  

864ffb0d2b8f9e7ddabd50be7409046b


Generic Malware UPX Malicious Library Malicious Packer PE File PE32 OS Processor Check DLL PE64 PNG Format VirusTotal Malware Check memory Creates executable files unpack itself AppData folder
2.6 M 17 ZeroCERT

13049 2023-05-23 17:25 ChatGPT-4.exe  

dce55bbdd6eed9c8208b7e2581566ff0


Gen1 Generic Malware UPX Malicious Library Malicious Packer ASPack Anti_VM OS Processor Check PE64 PE File DLL VirusTotal Malware Check memory Creates executable files unpack itself
3.4 M 45 ZeroCERT

13050 2023-05-23 17:25 papizx.exe  

e2f5006e1aaef2772f0593ca9e63d13b


AgentTesla PWS .NET framework browser info stealer Google Chrome User Data Downloader Create Service Socket DNS PWS[m] Sniff Audio Internet API Escalate priviledges KeyLogger AntiDebug AntiVM .NET EXE PE File PE32 Remcos VirusTotal Malware AutoRuns PDB Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows DNS keylogger
1 3 1 10.4 M 42 ZeroCERT