Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13396 2021-10-12 09:51 SMKMBT-00000789-2021-10-90340....  

4169b7a2e71ecfb831565118b9b6a3bb


Generic Malware Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware Buffer PE suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW human activity check Windows ComputerName
2 12.6 24 ZeroCERT

13397 2021-10-12 09:54 vbc.exe  

cda5dff7abc114308bd9491cacb36e0d


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key crashed
11.0 M 34 ZeroCERT

13398 2021-10-12 09:55 LOGS.exe  

3f6f7c01dc86ddaabade6d6665967c0a


RAT AgentTesla(IN) Generic Malware Admin Tool (Sysinternals etc ...) Malicious Packer UPX Malicious Library DNS AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities Check virtual network interfaces suspicious process AppData folder WriteConsoleW human activity check Tofsee Windows ComputerName DNS Cryptographic key crashed
1 5 1 18.0 M 51 ZeroCERT

13399 2021-10-12 09:56 CCle.exe  

cd3ee914a93505c4826084e77c4bfe28


Malicious Library PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself Remote Code Execution
2.2 20 ZeroCERT

13400 2021-10-12 09:57 vbc.exe  

41bc8c583d9904897e2b504f127ced23


NSIS Malicious Library PE File PE32 DLL FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Creates executable files ICMP traffic unpack itself AppData folder
20 24 2 8.2 M 39 ZeroCERT

13401 2021-10-12 09:58 game.exe  

446d891b81bee0bfd287bd1f968c5ac3


Malicious Library PE File PE32 OS Processor Check PDB unpack itself Remote Code Execution
1.4 ZeroCERT

13402 2021-10-12 09:58 Swift_copy.cab  

1a6b2d478c45cb2244454829f79c7974


Escalate priviledges KeyLogger AntiDebug AntiVM VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself
2.2 19 ZeroCERT

13403 2021-10-12 10:01 profit.exe  

31c0c5e61f7616bd625cc9a1a3117e96


Themida Packer UPX Anti_VM PE File PE32 .NET EXE Browser Info Stealer Malware Malicious Traffic Check memory Checks debugger unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces suspicious TLD VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key crashed
2 5 1 9.2 M ZeroCERT

13404 2021-10-12 10:02 rundll32.exe  

958327f65e87da599ad05ad82897f730


RAT PWS .NET framework Gen1 Generic Malware Malicious Library Malicious Packer AntiDebug AntiVM PE File PE32 .NET EXE OS Processor Check DLL JPEG Format Browser Info Stealer Malware download Vidar VirusTotal Email Client Info Stealer Malware Phishing Cryptocurrency wallets Cryptocurrency suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW anti-virtualization VM Disk Size Check installed browsers check OskiStealer Stealer Windows Chrome Browser Email ComputerName Password
9 2 7 16.6 M 28 ZeroCERT

13405 2021-10-12 10:02 LZrg9QKDOYThFzj.exe  

1686f2ca568d14d7f2b177ee1c743f60


RAT PWS .NET framework Generic Malware SMTP KeyLogger AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted unpack itself Windows ComputerName crashed
10.0 M 28 ZeroCERT

13406 2021-10-12 10:04 audio.exe  

16b6795e99dfc883377cfeb6a650ab3f


PWS Loki[b] Loki.m RAT Generic Malware UPX AntiDebug AntiVM PE File PE32 OS Processor Check .NET EXE FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted ICMP traffic unpack itself Check virtual network interfaces Tofsee Windows Cryptographic key
13 27 3 9.0 M 25 ZeroCERT

13407 2021-10-12 10:04 Update.exe.rar  

a22ca06bb3a58d4ca2bca856434b96f3


Generic Malware Malicious Packer PE File PE32 VirusTotal Malware suspicious privilege unpack itself suspicious process AntiVM_Disk sandbox evasion WriteConsoleW shadowcopy delete Ransom Message Creates autorun.inf VM Disk Size Check Ransomware GameoverP2P Zeus Windows Trojan Banking crashed
8.8 M 55 ZeroCERT

13408 2021-10-12 10:05 sefile3.exe  

6bb7dc4a3db387ced8c05711f6bbfc8d


Generic Malware Malicious Library PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
2.2 M 43 ZeroCERT

13409 2021-10-12 10:07 vbc.exe  

0c699aa8699b1bccd7c223aaa47ffd0e


UPX Malicious Library PE File PE32 OS Processor Check VirusTotal Malware PDB unpack itself
1.8 M 26 ZeroCERT

13410 2021-10-12 10:07 csrss.exe  

e54d1bcdd9d7af8f91758cfa17be9224


Lokibot PWS Loki[b] Loki.m RAT .NET framework Generic Malware DNS Socket AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Windows Browser Email ComputerName Cryptographic key Software
1 2 7 1 14.0 M 29 ZeroCERT