Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1 2023-09-06 17:04 plugmanzx.exe  

830d847bc734ebb8b375da6c9eb64a24


Client SW User Data Stealer Backdoor RemcosRAT browser info stealer Google Chrome User Data Downloader .NET framework(MSIL) PWS ScreenShot Create Service Socket Escalate priviledges Sniff Audio DNS Internet API KeyLogger AntiDebug AntiVM PE File .NET EXE Browser Info Stealer Remcos VirusTotal Email Client Info Stealer Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself AntiVM_Disk sandbox evasion VM Disk Size Check installed browsers check Windows Browser Email ComputerName DNS DDNS keylogger
1 4 2 12.8 M 24 ZeroCERT

2 2023-09-06 17:03 HKA6kdXx7NGuWbk.exe  

81abca731625a26c26b7831db81c0e1e


Generic Malware .NET framework(MSIL) Antivirus PWS DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell Buffer PE PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key DDNS
2 2 15.0 M 15 ZeroCERT

  • First
  • 1
  • Last
  • Total : 2cnts