Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14221 2023-04-10 09:42 cred64.dll  

846d00634429d1dfd48cbdbc24e8b8e3


Ave Maria WARZONE RAT UPX Malicious Library OS Processor Check DLL PE64 PE File VirusTotal Malware PDB Checks debugger installed browsers check Browser ComputerName crashed
2.4 M 47 ZeroCERT

14222 2023-04-10 09:40 ax.png.ps1  

d04c40b337e256cc052a125ab25b1ae4


Formbook Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.4 3 ZeroCERT

14223 2023-04-10 09:39 lega.exe  

d21ed39f2754e2d9f681828a60d0c3c0


Gen1 Emotet UPX Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) CAB PE32 PE File OS Processor Check DLL Browser Info Stealer Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Tofsee Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed Downloader
5 7 14 1 16.0 M ZeroCERT

14224 2023-04-10 09:38 RegSvcs.exe  

8380e9d71cd1fb157301b87e8fb0c911


Loki_b PWS .NET framework RAT UPX .NET EXE PE32 PE File Malware download Malware PDB MachineGuid Malicious Traffic Check memory Checks debugger WMI unpack itself Check virtual network interfaces AntiVM_Disk anti-virtualization IP Check VM Disk Size Check ComputerName Remote Code Execution Trojan DNS
3 3 6 6.0 ZeroCERT

14225 2023-04-10 09:36 ChromeFIX_error.exe  

8ae47c8391af6dab310f21335c7b3673


RedLine stealer[m] UPX Malicious Library AntiDebug AntiVM OS Processor Check PE32 PE File VirusTotal Malware Buffer PE Code Injection Check memory Checks debugger buffers extracted unpack itself Windows DNS Cryptographic key crashed
1 8.8 M 38 ZeroCERT

14226 2023-04-10 09:35 cred64.dll  

4458e8114c5e302f791c868ef0e54cd0


Ave Maria WARZONE RAT UPX Malicious Library OS Processor Check DLL PE64 PE File VirusTotal Malware PDB Checks debugger installed browsers check Browser ComputerName crashed
2.4 M 54 ZeroCERT

14227 2023-04-10 09:34 clip64.dll  

73df88d68a4f5e066784d462788cf695


UPX Malicious Library Admin Tool (Sysinternals etc ...) OS Processor Check DLL PE32 PE File VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 58 ZeroCERT

14228 2023-04-10 09:33 tk.txt.ps1  

6f9f7f9061fbf67cfafb13d02796231e


Generic Malware Antivirus VirusTotal Malware powershell Malicious Traffic Check memory WMI ICMP traffic unpack itself Check virtual network interfaces Tofsee Windows ComputerName Cryptographic key
1 4 1 5.2 6 ZeroCERT

14229 2023-04-10 09:33 oneetx.exe  

6809ca52cdc1bfffe3496efd3e2409b5


Malicious Library PE32 PE File VirusTotal Malware PDB unpack itself
2.2 M 55 ZeroCERT

14230 2023-04-10 09:32 fotocr17.exe  

5227881f0c4282a39a83b797a0299392


Gen1 Emotet UPX Malicious Library CAB PE32 PE File PDB Remote Code Execution
0.8 M ZeroCERT

14231 2023-04-10 09:32 clip64.dll  

940af61872686e1bf02772033d5c544d


UPX Malicious Library Admin Tool (Sysinternals etc ...) OS Processor Check DLL PE32 PE File VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 61 ZeroCERT

14232 2023-04-10 09:31 foto0154.exe  

3565091a7c8d8606dd54a6d9a28de337


Gen1 Emotet UPX Malicious Library CAB PE32 PE File Browser Info Stealer FTP Client Info Stealer AutoRuns PDB suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
2 8.2 M ZeroCERT

14233 2023-04-10 09:31 photo_112.exe  

a67bb51b119a575bc5fbac95df8429c7


Gen1 Emotet UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer CAB PE32 PE File OS Processor Check DLL Browser Info Stealer Malware download Amadey FTP Client Info Stealer Malware AutoRuns PDB suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Disables Windows Security Collect installed applications suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Update Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
2 2 6 15.4 M ZeroCERT

14234 2023-04-10 09:30 foto0154.exe  

1fdd7be5eb45c613ba6239edb83ab7ea


Gen1 Emotet UPX Malicious Library CAB PE32 PE File Browser Info Stealer FTP Client Info Stealer AutoRuns PDB suspicious privilege Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Collect installed applications AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser ComputerName Remote Code Execution DNS Cryptographic key Software crashed
1 8.2 M ZeroCERT

14235 2023-04-10 09:27 clip64.dll  

4061d8dd5006b99d06fa208c0063dfcf


UPX Malicious Library Admin Tool (Sysinternals etc ...) OS Processor Check DLL PE32 PE File VirusTotal Malware PDB Checks debugger unpack itself
2.0 M 61 ZeroCERT