Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14101 2021-10-27 10:30 guide-1763962901.xls  

fc554e84ff0d6cf63628d42218342cf7


Downloader MSOffice File RWX flags setting unpack itself suspicious process Tofsee
4 7 3 4.0 guest

14102 2021-10-27 10:31 davidhillzx.exe  

ec9fb1c161dfcfd1aaec47260aa825ff


RAT PWS .NET framework email stealer Generic Malware UPX ASPack Malicious Packer Malicious Library Antivirus DNS Code injection KeyLogger Escalate priviledges Downloader persistence AntiDebug AntiVM PE File OS Processor Check PE32 .NET EXE VirusTotal Malware powershell AutoRuns suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files unpack itself Windows utilities Disables Windows Security powershell.exe wrote Check virtual network interfaces suspicious process AppData folder AntiVM_Disk sandbox evasion WriteConsoleW VM Disk Size Check Tofsee Windows ComputerName DNS Cryptographic key crashed
2 3 1 17.8 41 ZeroCERT

14103 2021-10-27 10:43 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware
0.6 15 ZeroCERT

14104 2021-10-27 10:57 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14105 2021-10-27 11:01 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14106 2021-10-27 11:05 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14107 2021-10-27 11:12 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14108 2021-10-27 11:26 vbc.exe  

c30565830025332db48b9f38ddb2ab3f


PWS Loki[b] Loki.m .NET framework Generic Malware Socket DNS AntiDebug AntiVM PE File PE32 .NET EXE Browser Info Stealer LokiBot Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware c&c suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Browser Email ComputerName DNS Software crashed
1 1 6 1 13.8 M 21 guest

14109 2021-10-27 13:09 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14110 2021-10-27 13:14 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14111 2021-10-27 13:18 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14112 2021-10-27 13:24 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware
0.6 15 guest

14113 2021-10-27 13:28 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest

14114 2021-10-27 13:32 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware
0.6 15 guest

14115 2021-10-27 13:36 66890294103.pdf  

fc78d2cdb494fd18e3b59dbf2b5ded11


PDF Suspicious Link PDF VirusTotal Malware unpack itself Windows utilities Windows
2.0 15 guest