Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14251 2023-03-25 01:03 Info.plist  

9a4fdf46def57336ff67c5b08bbde1dd


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

14252 2023-03-25 01:02 document.wflow  

d5494c2ee15638c49616a2643d9cbc44


AntiDebug AntiVM MSOffice File Code Injection exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.4 BRY

14253 2023-03-25 01:02 Preview.png  

f916f325e5d39fec8ff93922d43002d5


Downloader Create Service DGA Socket ScreenShot DNS Internet API Code injection PWS[m] Hijack Network Sniff Audio HTTP Steal credential KeyLogger P2P Escalate priviledges persistence FTP Http API AntiDebug AntiVM PNG Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 BRY

14254 2023-03-25 01:02 Preview.png  

f916f325e5d39fec8ff93922d43002d5


Downloader Create Service DGA Socket ScreenShot DNS Internet API Code injection PWS[m] Hijack Network Sniff Audio HTTP Steal credential KeyLogger P2P Escalate priviledges persistence FTP Http API AntiDebug AntiVM PNG Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 BRY

14255 2023-03-25 01:00 Preview.png  

f916f325e5d39fec8ff93922d43002d5


AntiDebug AntiVM PNG Format MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 BRY

14256 2023-03-24 18:21 Scantle.exe  

8e7ec9167dd8c5b9444e4ba17e849fdc


RedLine stealer[m] PWS .NET framework RAT RedLine Stealer Confuser .NET SMTP PWS[m] AntiDebug AntiVM .NET EXE PE32 PE File VirusTotal Malware Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself Windows DNS Cryptographic key
1 8.2 M 55 ZeroCERT

14257 2023-03-24 18:20 30..................30...........  

f3f27539efc7350df9dc444676687f9b


MS_RTF_Obfuscation_Objects RTF File doc Malware download VirusTotal Malware Malicious Traffic RWX flags setting exploit crash Windows Exploit DNS crashed Downloader
1 1 7 4.6 M 31 ZeroCERT

14258 2023-03-24 18:19 ndt5tk.exe  

9ce5895cf7087cd578519a76e9eadb7c


UPX Malicious Library PWS[m] AntiDebug AntiVM OS Processor Check PE32 PE File VirusTotal Malware Buffer PE Code Injection Check memory Checks debugger buffers extracted unpack itself ComputerName crashed
7.6 M 32 ZeroCERT

14259 2023-03-24 18:18 rc.exe  

50e9958bb2a5b6ae6ed8da1b1d97a5bb


UPX Malicious Library AntiDebug AntiVM OS Processor Check PE32 PE File GIF Format Browser Info Stealer VirusTotal Malware suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger WMI Creates shortcut Creates executable files ICMP traffic unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check installed browsers check Windows Browser ComputerName
3 2 10.2 M 32 ZeroCERT

14260 2023-03-24 18:17 20...............................  

3d64a167c2f313bac10c89b3d591be13


MS_RTF_Obfuscation_Objects RTF File doc VirusTotal Malware RWX flags setting
2.6 M 30 ZeroCERT

14261 2023-03-24 18:15 1.vbs  

0302835269c55903e8af7326a27ca898


Generic Malware Antivirus VirusTotal Malware powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key
5.8 M 2 ZeroCERT

14262 2023-03-24 18:15 vbc.exe  

1207e0b55db1b38405c49fc57209fc38


PWS .NET framework RAT UPX .NET EXE PE32 PE File VirusTotal Malware PDB Check memory Checks debugger unpack itself DNS crashed
1 3.2 M 33 ZeroCERT

14263 2023-03-24 18:13 vbc.exe  

1651e40eaf343b2e9ceaea5f1aef2fae


NPKI RAT UPX PE64 PE File VirusTotal Malware Check memory Checks debugger unpack itself
1.6 M 29 ZeroCERT

14264 2023-03-24 18:12 huilang.exe  

f1ec2cf6256a7c8543586065a07da47a


UPX PE32 PE File Malware download VirusTotal Open Directory Malware AutoRuns Malicious Traffic Check memory Creates executable files RWX flags setting AppData folder AntiVM_Disk sandbox evasion VM Disk Size Check Windows Exploit Browser DNS
1 8 9.4 M 56 ZeroCERT

14265 2023-03-24 18:12 creal.exe  

2120b49043ad53c0a73cbf60bc110f8e


Gen1 Emotet Generic Malware UPX Malicious Library Anti_VM Malicious Packer Admin Tool (Sysinternals etc ...) OS Processor Check PE64 PE File DLL ZIP Format VirusTotal Malware Check memory Creates executable files
2.2 M 34 ZeroCERT