Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14071 2023-04-03 16:45 build69.exe  

cb1ca4cee1049ab33d16bf76eb56a24f


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.2 M 42 ZeroCERT

14072 2023-04-03 16:45 clip.dll  

1f45186b6549a60a00f5a300b60d70fa


UPX Malicious Library Admin Tool (Sysinternals etc ...) OS Processor Check DLL PE32 PE File VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 55 ZeroCERT

14073 2023-04-03 13:43 rubber.exe  

afac69dd87bbf4bd13adb1180cfd486f


UPX Malicious Library Malicious Packer PE32 PE File VirusTotal Malware WriteConsoleW DNS crashed
1 4.4 20 ZeroCERT

14074 2023-04-03 13:42 pop.exe  

523613a7b9dfa398cbd5ebd2dd0f4f38


PE64 PE File VirusTotal Malware
0.8 26 ZeroCERT

14075 2023-04-03 08:49 fotocr12.exe  

c1d020b73ceac78a6206c7203996683c


Gen1 Emotet UPX Malicious Library CAB PE32 PE File Browser Info Stealer FTP Client Info Stealer AutoRuns PDB suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Disables Windows Security Collect installed applications AntiVM_Disk VM Disk Size Check installed browsers check Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 10.4 M ZeroCERT

14076 2023-04-03 08:47 oskg25  

ab28d926012b7cf54ea99eafe85e580b


Gen2 Gen1 UPX Malicious Library Malicious Packer PE64 PE File VirusTotal Malware PDB Remote Code Execution
1.2 M 27 ZeroCERT

14077 2023-04-03 08:45 foto0189.exe  

f40b9e44108344b258417dd2c1056490


Gen1 Emotet UPX Malicious Library CAB PE32 PE File Browser Info Stealer FTP Client Info Stealer AutoRuns PDB suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 8.2 ZeroCERT

14078 2023-04-03 08:30 ORDER_230401.vbs  

3c707a7b93f50858c1d0f550e75bf37b

Malware download Wshrat NetWireRC VirusTotal Malware VBScript AutoRuns WMI wscript.exe payload download AntiVM_Disk VM Disk Size Check Windows Houdini ComputerName DNS DDNS Dropper
1 2 4 10.0 29 ZeroCERT

14079 2023-04-03 08:29 launcher.vbs  

57681dd10fdf68cfd0ec1ef066440d47


Generic Malware Antivirus Hide_URL PowerShell VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Check virtual network interfaces suspicious process WriteConsoleW Windows ComputerName Cryptographic key
2 7.8 31 ZeroCERT

14080 2023-04-03 08:27 ntredirect.dll  

61131c939b98075c07e189830ff2879d


DLL PE32 PE File unpack itself DNS
1 1.6 M ZeroCERT

14081 2023-04-03 08:26 clickme.lnk  

dc1bb1e2409b4344609d8a176b3fd55d


Antivirus GIF Format VirusTotal Malware Creates shortcut unpack itself WriteConsoleW
1.6 11 ZeroCERT

14082 2023-04-03 08:26 photo_007.exe  

cd863c532d8b7fb02cfe7ad045c9d032


Gen1 Emotet UPX Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) CAB PE32 PE File OS Processor Check DLL Browser Info Stealer Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
5 2 6 16.0 M ZeroCERT

14083 2023-04-03 08:24 777.exe  

44f50973ac66fd83be9411d6ab53446f


Malicious Library PE32 PE File Check memory RWX flags setting unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check Browser DNS
1 4.0 M ZeroCERT

14084 2023-04-03 08:22 sarkof2.1.exe  

796099660c004943c505c3bfaa6da30f


UPX Malicious Library PE32 PE File OS Processor Check Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Check virtual network interfaces AppData folder Tofsee Windows Browser Email ComputerName Cryptographic key Software crashed keylogger
2 2 11.6 M 44 ZeroCERT

14085 2023-04-03 08:22 aspectator.exe  

0b038f819481ba63e9adfd623c824eb4


UPX Malicious Library OS Processor Check PE32 PE File unpack itself Remote Code Execution
1.0 M ZeroCERT