Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13576 2021-10-14 16:55 UFC~0398763535603876534536789....  

c1bd58337e98aec86544e0dd33924e61


PWS .NET framework Generic Malware UPX DNS AntiDebug AntiVM PE File PE32 OS Processor Check .NET EXE Malware download Nanocore VirusTotal Malware c&c Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
2 2 13.2 10 ZeroCERT

13577 2021-10-14 16:57 WT_03986354356-39876354533.exe  

ca49afc18eb80ac0e4c784b3d093767d


PWS .NET framework Generic Malware DNS AntiDebug AntiVM PE File PE32 .NET EXE Malware download Nanocore VirusTotal Malware c&c Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS
2 2 13.2 16 ZeroCERT

13578 2021-10-14 17:19 dow.exe  

481cc004b81afcb1ec10bb9985cc402b


Malicious Packer Malicious Library PE64 PE File VirusTotal Malware Code Injection buffers extracted
3.0 M 33 ZeroCERT

13579 2021-10-14 17:20 vbc.exe  

70d177abc7455c709ae9710630b9ea49


Loki NSIS UPX Malicious Library PE File PE32 OS Processor Check DLL Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software
1 2 10 1 10.4 M 29 ZeroCERT

13580 2021-10-14 17:22 ETH2.exe  

13003cbfb6d2adfeea85952f8172c4f7


PE64 PE File VirusTotal Malware
1.2 M 25 ZeroCERT

13581 2021-10-14 17:23 vbc.exe  

8777020a37b6797241a489a707b9784b


Generic Malware UPX PE File PE32 VirusTotal Malware Check memory RWX flags setting unpack itself Remote Code Execution crashed
2.2 M 22 ZeroCERT

13582 2021-10-14 17:24 6666.exe  

f8d8071d3e0163eb4e816ec49d0b2e8e


NPKI Malicious Library PE64 PE File VirusTotal Cryptocurrency Miner Malware Cryptocurrency
2 1 1.6 M 31 ZeroCERT

13583 2021-10-14 17:24 bloodteam.exe  

2d82ec0905de054cd685e6a52e2d9442


Generic Malware Antivirus Malicious Packer Malicious Library PE File PE32 PE64 VirusTotal Cryptocurrency Miner Malware Cryptocurrency powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself powershell.exe wrote Check virtual network interfaces suspicious process suspicious TLD WriteConsoleW Windows ComputerName Cryptographic key Downloader
4 3 10.0 M 38 ZeroCERT

13584 2021-10-14 17:26 ali.exe  

bf15384858eb653a37c2c52cfb8093bf


NPKI PE64 PE File VirusTotal Malware DNS
1 1.8 M 29 ZeroCERT

13585 2021-10-14 17:26 c78zdj.jpg  

cb1c5d7a7e086e67e22abe9eab31db50


Gen2 Gen1 Malicious Library PE File PE32 DLL VirusTotal Malware PDB unpack itself DNS crashed
1 1.8 M 8 ZeroCERT

13586 2021-10-14 17:28 sold.exe  

3c46298cfa8e5755a58aee34d65cb397


PE64 PE File VirusTotal Malware
1.6 M 41 ZeroCERT

13587 2021-10-14 17:29 VolumeConverter.dll  

fc505773010d767cc1eca83c1df804cb


Generic Malware PE File PE32 .NET DLL DLL VirusTotal Malware PDB
1.0 M 19 ZeroCERT

13588 2021-10-14 17:29 mine.exe  

f64ccb9df2b5df5287485f13c727d9dd


Malicious Packer VMProtect UPX Malicious Library PE64 PE File VirusTotal Malware Code Injection Malicious Traffic buffers extracted unpack itself Tofsee Remote Code Execution
1 5 1 1 5.0 M 35 ZeroCERT

13589 2021-10-14 17:31 acqlzg075.jpg  

6a33a581f8b986ae4cf315c4c912d864


Gen2 Gen1 Malicious Library PE File PE32 DLL VirusTotal Malware PDB Check memory unpack itself crashed
1.4 M 9 ZeroCERT

13590 2021-10-14 17:31 monero-bandit.exe  

342ef4f2941187bdc7f66d148be0ff75


Malicious Packer Malicious Library PE64 PE File VirusTotal Cryptocurrency Miner Malware Cryptocurrency Code Injection buffers extracted
2 1 3.2 M 41 ZeroCERT