Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2023-06-08 09:21 combo.exe  

f693e2f2661b6e5824ccd29e5ba58bb6


PWS .NET framework RAT Downloader Create Service DGA Socket DNS Code injection HTTP PWS[m] Sniff Audio Steal credential Http API P2P Internet API Escalate priviledges FTP KeyLogger ScreenShot AntiDebug AntiVM .NET EXE PE File PE32 Browser Info Stealer Malware download FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Report Cryptocurrency wallets Cryptocurrency Telegram AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Windows utilities Collect installed applications Check virtual network interfaces suspicious process AppData folder WriteConsoleW IP Check Tofsee Ransomware WhiteSnake Stealer Windows Browser Email ComputerName DNS Software
8 17 6 14.8 M 49 ZeroCERT

2 2023-05-03 09:00 IMG_5435.exe  

3121ecc67e64fdf65b2b3c9f5966ed11


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware MachineGuid Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
2 1 2.6 44 guest

3 2023-05-02 09:19 IMG_5435.exe  

3121ecc67e64fdf65b2b3c9f5966ed11


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces Tofsee
1 6 1 3.8 44 ZeroCERT

4 2023-04-03 16:45 build69.exe  

cb1ca4cee1049ab33d16bf76eb56a24f


PWS .NET framework RAT .NET EXE PE32 PE File VirusTotal Malware Check memory Checks debugger unpack itself ComputerName
2.2 M 42 ZeroCERT

5 2023-03-29 17:42 buildjack.exe  

10f57aeea7d69c1fd26302daea446d8d


PWS .NET framework RAT .NET EXE PE32 PE File Browser Info Stealer VirusTotal Malware Cryptocurrency wallets Cryptocurrency Telegram Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces IP Check Tofsee Browser ComputerName DNS
1 4 5 5.2 M 45 ZeroCERT

  • First
  • 1
  • Last
  • Total : 5cnts