Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
14731 2023-03-09 17:42 LEMMIN.exe  

38aad33a1f0f90c4294abab2a85221eb


Malicious Library PE File PE64 VirusTotal Cryptocurrency Miner Malware Cryptocurrency DNS
2 1 1.4 M 31 ZeroCERT

14732 2023-03-09 17:41 bcd4b93a1a85c5ba45a4f7e5980db1...  

d5e7b6fe3bb68f1da7ec111231292f02


Emotet Gen2 UPX Malicious Library Malicious Packer OS Processor Check PE32 PE File DLL VirusTotal Malware Check memory buffers extracted WMI Creates executable files AppData folder Tofsee ComputerName crashed
3 2 1 1 5.2 M 43 ZeroCERT

14733 2023-03-09 17:41 dd_64.exe  

9029a43c6034a4f0b3408fd38936beb9


UPX Malicious Library OS Processor Check PE File PE64 VirusTotal Email Client Info Stealer Malware MachineGuid Malicious Traffic installed browsers check Tofsee Browser Advertising Email ComputerName DNS crashed
2 5 3 4.6 M 23 ZeroCERT

14734 2023-03-09 17:38 bcd4b93a1a85c5ba45a4f7e5980db1...  

e7f609df5c0fcdc581a69ed69aa3c4a1


Emotet Gen2 UPX Malicious Library Malicious Packer OS Processor Check PE32 PE File DLL VirusTotal Malware Check memory buffers extracted WMI Creates executable files AppData folder Tofsee ComputerName crashed
3 2 1 1 5.2 M 42 ZeroCERT

14735 2023-03-09 17:38 vbc.exe  

17764f0a8189a2f85bdbac3e1e820fb4


PWS .NET framework KeyLogger AntiDebug AntiVM .NET EXE PE32 PE File Browser Info Stealer VirusTotal Email Client Info Stealer Malware PDB Code Injection Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces IP Check Tofsee Windows Browser Email ComputerName crashed
1 2 1 10.4 M 33 ZeroCERT

14736 2023-03-09 17:36 bcd4b93a1a85c5ba45a4f7e5980db1...  

24527c1cb60027d91ddc051990ba55ca


Emotet Gen2 UPX Malicious Library Malicious Packer OS Processor Check PE32 PE File DLL VirusTotal Malware Check memory buffers extracted WMI Creates executable files unpack itself AppData folder Tofsee ComputerName crashed
3 2 1 1 4.8 M 36 ZeroCERT

14737 2023-03-09 17:36 bcd4b93a1a85c5ba45a4f7e5980db1...  

b5e1e946ebad560b876703e9675ca326


Emotet Gen2 UPX Malicious Library Malicious Packer OS Processor Check PE32 PE File DLL VirusTotal Malware Check memory buffers extracted WMI Creates executable files AppData folder Tofsee ComputerName crashed
3 2 1 2 5.2 M 43 ZeroCERT

14738 2023-03-09 17:34 bcd4b93a1a85c5ba45a4f7e5980db1...  

bf48a5cd9169a5826521a8a33b21adee


Emotet Gen2 UPX Malicious Library Malicious Packer OS Processor Check PE32 PE File DLL VirusTotal Malware Check memory buffers extracted WMI Creates executable files AppData folder Tofsee ComputerName crashed
3 2 1 1 5.2 M 42 ZeroCERT

14739 2023-03-09 17:33 CL.exe  

ed2a38021d3dcadca60d08163d1c7a31


RAT NPKI UPX OS Processor Check .NET EXE PE32 PE File VirusTotal Malware Cryptocurrency wallets Cryptocurrency AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder AntiVM_Disk WriteConsoleW VM Disk Size Check Ransomware Windows ComputerName
9.0 M 37 ZeroCERT

14740 2023-03-09 17:12 i3YFqH6uMO3o8pg2Cbx.zip  

5a72267343811d8fe7d72c1f96bac927

VirusTotal Malware Report ICMP traffic DNS
11 5 3.4 M 6 ZeroCERT

14741 2023-03-09 15:38 8f803ff90bee714e5d243cc3b3ad70...  

1e16074ff6afe068fd5f852ff66eb188


Gen1 UPX Malicious Packer PE File PE64 Remote Code Execution
0.2 ZeroCERT

14742 2023-03-09 15:38 c95d3e98bd8a782a492370ad69bf82...  

e95942eabc6c7e41201180d1a2219673


Gen1 UPX Malicious Packer PE32 PE File Remote Code Execution
0.2 ZeroCERT

14743 2023-03-09 15:38 7f55dece1d491b5fd45817b01b4266...  

d649e0919963e72952b7337c45d34d55


Gen1 UPX Malicious Packer PE32 PE File Check memory Remote Code Execution
0.4 ZeroCERT

14744 2023-03-09 14:47 Fix.exe  

d543b38b01f033815b048cd17cd658dd


UPX Malicious Library Admin Tool (Sysinternals etc ...) AntiDebug AntiVM OS Processor Check PE File PE64 JPEG Format MSOffice File VirusTotal Malware PDB Code Injection Check memory buffers extracted Creates executable files RWX flags setting exploit crash unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Windows Exploit Remote Code Execution DNS crashed
44 26 1 6.4 2 guest

14745 2023-03-09 13:57 INVOICE 589 03_23.doc  

b59808aba76dd0095aa06133382de9ed


Generic Malware VBA_macro Downloader Create Service DGA Socket ScreenShot DNS Internet API Code injection PWS[m] Hijack Network Sniff Audio HTTP Steal credential KeyLogger P2P Escalate priviledges persistence FTP Http API AntiDebug AntiVM MSOffice File Report unpack itself suspicious process malicious URLs sandbox evasion Tofsee ComputerName DNS
1 11 6 4.8 27 ZeroCERT