Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13981 2021-10-23 09:51 vbc.exe  

e72e46f86b972fa7e171cc9104995bee


Malicious Library UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
1.6 23 ZeroCERT

13982 2021-10-23 09:51 new.exe  

66906a29cfa4ad3d5e928581bba0dda4


RAT PWS .NET framework Generic Malware Antivirus PE File PE32 .NET EXE VirusTotal Malware AutoRuns suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName Cryptographic key crashed
2 2 1 6.8 21 ZeroCERT

13983 2021-10-23 09:53 vbc.exe  

c58e48fe28f84e2359af820fb583bc82


PWS Loki[b] Loki.m .NET framework Generic Malware Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName Software
1 2 7 13.0 26 ZeroCERT

13984 2021-10-23 09:53 zwoag.exe  

7e7e20bac722de83b363c29ee7e4efbd


Themida Packer PE64 PE File VirusTotal Malware Windows crashed
2.4 37 ZeroCERT

13985 2021-10-23 09:57 sdd.dll  

de8b54a938ac18f15cad804d79a0e19d


Gen2 Gen1 Generic Malware Malicious Library UPX Antivirus PE File OS Processor Check PE32 DLL Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell Buffer PE PDB suspicious privilege MachineGuid Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself Windows utilities Collect installed applications powershell.exe wrote Check virtual network interfaces suspicious process AntiVM_Disk sandbox evasion WriteConsoleW anti-virtualization VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS Cryptographic key Software crashed
2 16.2 18 ZeroCERT

13986 2021-10-23 09:58 inv_0001233.wbk  

c53168d1494977e6433cc671f6f9aceb


RTF File doc LokiBot Malware download VirusTotal Malware c&c Malicious Traffic buffers extracted RWX flags setting exploit crash Windows Exploit DNS crashed Downloader
2 2 12 1 4.8 M 29 ZeroCERT

13987 2021-10-23 10:00 csrss.exe  

ca66da9aeea970c1476519b769af2cf7


Loki PWS Loki[b] Loki.m .NET framework Generic Malware Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName Software
2 2 7 1 14.2 26 ZeroCERT

13988 2021-10-23 10:14 vbc.exe  

940fb7ef71682b6110d7c2d37a92f5df


Malicious Library UPX PE File OS Processor Check PE32 VirusTotal Malware PDB unpack itself Remote Code Execution
2.0 26 ZeroCERT

13989 2021-10-23 10:15 139.exe  

398371c8cc3528881ea5d49f678a541e


Themida Packer Anti_VM UPX PE File PE32 .NET EXE Browser Info Stealer FTP Client Info Stealer suspicious privilege Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key Software crashed
1 9.4 26 ZeroCERT

13990 2021-10-23 10:15 vbc.exe  

f2b0b0c3a1df878a36acb0736b8e2ccf


RAT PWS .NET framework Generic Malware PE File PE32 .NET EXE VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted unpack itself
6.4 26 ZeroCERT

13991 2021-10-23 10:15 .wininit.exe  

1edc5ae8174533de1c038341b84685c5


PWS Loki[b] Loki.m RAT .NET framework Generic Malware Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download VirusTotal Malware c&c MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser
1 2 7 9.2 26 ZeroCERT

13992 2021-10-23 10:16 136.exe  

64420e27dd8930254ff853f4bbcfbbf4


RAT BitCoin Generic Malware ASPack Malicious Packer Malicious Library UPX Antivirus AntiDebug AntiVM PE File PE32 .NET EXE FTP Client Info Stealer VirusTotal Malware powershell suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications powershell.exe wrote Check virtual network interfaces suspicious process AppData folder sandbox evasion WriteConsoleW installed browsers check Tofsee Windows Browser ComputerName DNS Cryptographic key Software crashed
4 6 2 16.6 21 ZeroCERT

13993 2021-10-23 10:17 vbc.exe  

8449ee0cd73ae89d429ff7a6081fe0d9


Loki PWS Loki[b] Loki.m RAT .NET framework Generic Malware Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs installed browsers check Browser Email ComputerName Software
2 2 7 1 12.6 26 ZeroCERT

13994 2021-10-23 10:17 trulexzx.exe  

e2827700e9676ad0d4b734d5f4a221b3


RAT PWS .NET framework Generic Malware AntiDebug AntiVM PE File PE32 .NET EXE FormBook Malware download VirusTotal Malware suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself
7 15 2 8.2 30 ZeroCERT

13995 2021-10-23 10:19 140.exe  

0680fd1ef21a489b3812b4ef2f9a8f40


Lazarus Family Themida Packer Anti_VM Malicious Library UPX PE File PE32 .NET EXE Browser Info Stealer VirusTotal Malware suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Collect installed applications Detects VMWare Check virtual network interfaces VMware anti-virtualization installed browsers check Tofsee Windows Browser ComputerName Remote Code Execution Firmware DNS Cryptographic key crashed
2 3 1 10.6 33 ZeroCERT