Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13831 2021-10-20 15:51 biz-1433968740.xls  

4121502a64172a96d0e50adea4a49a5d


Downloader MSOffice File RWX flags setting unpack itself suspicious process Tofsee DNS
4 8 5 4.0 guest

13832 2021-10-20 16:03 DDoS attack Evidence.js  

7b0538a53e8abe965a532c1ea466ac67


Generic Malware Antivirus AntiDebug AntiVM VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process suspicious TLD WriteConsoleW Windows ComputerName DNS Cryptographic key
1 1 1 10.0 15 ZeroCERT

13833 2021-10-20 16:30 1019_7169909343268.doc  

4e062eb96bf086392a2a33f0f2dd7e69


VBA_macro Generic Malware MSOffice File Vulnerability VirusTotal Malware unpack itself
3.0 25 guest

13834 2021-10-20 16:35 1019_7169909343268.doc  

4e062eb96bf086392a2a33f0f2dd7e69


VBA_macro Generic Malware MSOffice File Vulnerability VirusTotal Malware unpack itself
3.0 25 guest

13835 2021-10-20 17:05 1019_7169909343268.doc  

4e062eb96bf086392a2a33f0f2dd7e69


VBA_macro Generic Malware MSOffice File VirusTotal Malware unpack itself
2.4 25 guest

13836 2021-10-20 17:08 1019_7169909343268.doc  

4e062eb96bf086392a2a33f0f2dd7e69


VBA_macro Generic Malware MSOffice File VirusTotal Malware unpack itself
2.4 25 guest

13837 2021-10-20 17:09 biz-1431840176.xls  

b0cca0af3bbafeae72288f34a065de04


Downloader MSOffice File Check memory unpack itself suspicious process suspicious TLD Tofsee DNS
1 8 4 4.2 guest

13838 2021-10-20 17:13 biz-1431840176.xls  

b0cca0af3bbafeae72288f34a065de04


Downloader KeyLogger ScreenShot AntiDebug AntiVM MSOffice File Code Injection unpack itself
2.0 guest

13839 2021-10-20 17:36 csrss.exe  

3d6ae742ec7b2d75583674e68eb36c83


Malicious Library UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.0 M 25 ZeroCERT

13840 2021-10-20 17:38 vbc.exe  

73fe142254abec3aeaef375f0564d40a


NSIS Malicious Library UPX PE File PE32 DLL FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Creates executable files unpack itself AppData folder
13 27 1 5.8 M 22 ZeroCERT

13841 2021-10-20 17:38 leApp14.exe  

a395af3db4f82f425bba5f5c27ef6a8e


RAT Generic Malware PE File PE32 .NET EXE VirusTotal Malware Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces Tofsee ComputerName
1 4 1 2.8 15 ZeroCERT

13842 2021-10-20 17:39 eresizebar.png  

a10f6a8bf27612bc7f83054b99ebbed3


Emotet Gen1 Malicious Library UPX PE File OS Processor Check PE32 Dridex TrickBot Malware Report suspicious privilege Malicious Traffic buffers extracted unpack itself Check virtual network interfaces suspicious process Kovter ComputerName DNS crashed
1 5 4 6.8 ZeroCERT

13843 2021-10-20 17:41 loader4.exe  

4f9a6937b1bb97f14cf0bac59fbde3a8


NSIS Malicious Library UPX PE File PE32 DLL Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software
1 1 6 1 11.0 M 28 ZeroCERT

13844 2021-10-20 17:41 vbc.exe  

9a092f3515d0d124eada8025f048dcb8


RAT PWS .NET framework Generic Malware PE File PE32 .NET EXE VirusTotal Malware Report Check memory Checks debugger unpack itself DNS
2 2 2.6 M 23 ZeroCERT

13845 2021-10-20 17:43 etooltipred.png  

e7893203387ae95e0444edc49d02d155


Emotet Gen1 Malicious Library UPX PE File OS Processor Check PE32 Dridex TrickBot Malware Report suspicious privilege Malicious Traffic buffers extracted unpack itself Check virtual network interfaces suspicious process Kovter ComputerName DNS crashed
1 6 5 6.8 ZeroCERT