Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14671 2023-03-12 21:40 Preview.exe  

86257e16e9db1d0740183fa624805d5f


UPX Malicious Library MZP Format PE File
guest

14672 2023-03-12 21:37 DpEditor.exe  

d0267bb4717f5d69ed7d1e30e89e301d


Themida Packer Anti_VM PE File VirusTotal Malware
0.4 2 guest

14673 2023-03-12 11:12 build.exe  

918b9b4d245035565fd159b7202ed708


Loki_b Loki_m Gen1 Suspicious_Script_Bin Generic Malware UPX Malicious Library Malicious Packer DGA Socket ScreenShot DNS Internet API PWS[m] Http API Code injection AntiDebug AntiVM OS Processor Check PE32 PE File DLL Browser Info Stealer Malware download FTP Client Info Stealer Dridex VirusTotal Email Client Info Stealer Malware Cryptocurrency wallets Cryptocurrency Microsoft Telegram AutoRuns MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself Windows utilities Collect installed applications suspicious process AppData folder malicious URLs suspicious TLD sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser Email ComputerName Remote Code Execution DNS Software
6 11 17 1 20.4 M 27 ZeroCERT

14674 2023-03-12 11:11 yt0.exe  

9b47804d0627d4ffa417b7c077db791e


PWS .NET framework RAT Generic Malware UPX Antivirus SMTP PWS[m] KeyLogger AntiDebug AntiVM OS Processor Check .NET EXE PE32 PE File Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process IP Check Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 3 6 16.2 M 37 ZeroCERT

14675 2023-03-12 11:07 vbc.exe  

23e46ac3c8b6b48d9e13d62c8ec8fd8b


PWS .NET framework Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW Windows Browser Email ComputerName Cryptographic key Software crashed
14.0 M 38 ZeroCERT

14676 2023-03-12 11:06 kyj.exe  

1be680a39218aa5f77c4bfe3c24a8107


PWS .NET framework RAT Generic Malware UPX Antivirus SMTP PWS[m] KeyLogger AntiDebug AntiVM OS Processor Check .NET EXE PE32 PE File Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware powershell PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote Check virtual network interfaces suspicious process IP Check Windows Browser Email ComputerName DNS Cryptographic key DDNS Software crashed keylogger
2 3 6 16.2 M 36 ZeroCERT

14677 2023-03-12 11:05 vbc.exe  

a1dd43a9d43a94f384c3cbbec7c36a1d


Admin Tool (Sysinternals etc ...) SMTP KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware AutoRuns PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows Browser Email ComputerName Cryptographic key Software crashed
14.4 M 43 ZeroCERT

14678 2023-03-12 10:22 photo_004.exe  

f655a619448889c239ef41f4b068a5ef


UPX Malicious Library OS Processor Check PE32 PE File unpack itself Remote Code Execution
1.2 M ZeroCERT

14679 2023-03-12 10:20 photo_004.exe  

6a06a13a83adb68d3b6e59560911ebca


UPX Malicious Library OS Processor Check PE32 PE File unpack itself Remote Code Execution
1.2 ZeroCERT

14680 2023-03-12 10:18 loader_p1_dll_64_n1_x64_inf.dl...  

1821abde4a17d5c775e197217ca2a1d6


UPX OS Processor Check DLL PE64 PE File VirusTotal Malware PDB Checks debugger crashed
1.6 13 ZeroCERT

14681 2023-03-12 10:18 10032b.exe  

488720af6f69c898d6d6395031aa85c3


UPX Malicious Library OS Processor Check PE32 PE File VirusTotal Malware unpack itself Remote Code Execution
2.4 52 ZeroCERT

14682 2023-03-12 10:18 ape2.exe  

bc2bec9810f53c3b1ca1220d05b0fea7


Malicious Library PE32 PE File VirusTotal Malware PDB
1 1.4 M 22 ZeroCERT

14683 2023-03-12 10:15 umciavi64.exe  

f2e85a7b8620fac7c035704e4168f942


Gen2 Malicious Library PE32 PE File VirusTotal Malware
1.2 M 19 ZeroCERT

14684 2023-03-12 10:15 photo_004.exe  

ae28959ef2fe4fd7eb141320972a6fb5


UPX Malicious Library OS Processor Check PE32 PE File unpack itself Remote Code Execution
1.2 ZeroCERT

14685 2023-03-12 10:13 Vejlensisk90.vbs  

5794e47d892a3cab512697ca7dc223f4


Generic Malware Antivirus Remcos VirusTotal Malware powershell suspicious privilege Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut unpack itself Windows utilities suspicious process anti-virtualization Windows ComputerName DNS Cryptographic key crashed
3 4 1 9.0 4 ZeroCERT