Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1951 2025-02-18 18:18 Info.plist  

56ebcffeaaad2fe9baec066cd278ca9c


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection unpack itself Windows utilities malicious URLs Windows DNS
1 4.8 guest

1952 2025-02-18 18:18 Info.plist  

56ebcffeaaad2fe9baec066cd278ca9c


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection unpack itself Windows utilities malicious URLs Windows DNS
1 4.8 guest

1953 2025-02-18 18:18 BTC-Flasher.exe  

4c9e0721e37503107c9fa2a53fecd716


njRAT backdoor Generic Malware Malicious Library Antivirus UPX PE File MSOffice File CAB PE32 OS Processor Check OS Name Check DLL VirusTotal Malware PDB suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check Windows ComputerName RCE DNS Cryptographic key
1 1 5.8 M 41 ZeroCERT

1954 2025-02-18 18:16 gradlew.bat  

632f7f6dcc28a13f168cc431061e0438


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence Anti_VM AntiDebug AntiVM ZIP Format OS Check memory buffers extracted RWX flags setting unpack itself Check virtual network interfaces malicious URLs WriteConsoleW Ransomware crashed
6 4.0 guest

1955 2025-02-18 18:16 gradlew.bat  

632f7f6dcc28a13f168cc431061e0438


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence Anti_VM AntiDebug AntiVM ZIP Format OS Check memory buffers extracted RWX flags setting unpack itself Check virtual network interfaces malicious URLs WriteConsoleW Ransomware crashed
6 4.0 guest

1956 2025-02-18 18:16 mkthooesfja.exe  

d934e572b7078873439fc889dc55fd27


PE File PE32 VirusTotal Malware unpack itself ComputerName DNS crashed
1 3.4 M 60 ZeroCERT

1957 2025-02-18 18:14 BetaCraft Launcher  

b64a80b34325c1fa6ce3a49ff8a89d95


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

1958 2025-02-18 18:14 BetaCraft Launcher  

b64a80b34325c1fa6ce3a49ff8a89d95


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

1959 2025-02-18 18:14 settings.gradle  

9c8e022315dce32d5e181eee0c2a7102


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

1960 2025-02-18 18:14 settings.gradle  

9c8e022315dce32d5e181eee0c2a7102


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

1961 2025-02-18 18:13 bioldgefsawe.exe  

64b7d7b5bf9a966e05abf7e854c2de74


PE File PE64 VirusTotal Cryptocurrency Miner Malware unpack itself DNS CoinMiner
2 1 1.8 M 57 ZeroCERT

1962 2025-02-18 18:10 USDTFlash.exe  

378be7ffe9155f83b933ed13e765a447


njRAT backdoor Generic Malware Malicious Library Antivirus UPX PE File MSOffice File CAB PE32 OS Processor Check OS Name Check DLL VirusTotal Malware PDB suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk suspicious TLD VM Disk Size Check Windows ComputerName RCE DNS Cryptographic key
1 1 6.2 M 41 ZeroCERT

1963 2025-02-18 18:07 build.gradle  

9e19a43480a7ac18bfc3165cc90a2bde


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

1964 2025-02-18 18:07 mnyksdrfkesa.exe  

ac049a7ec076fa12e5a9b043347d710e


PE File PE32 VirusTotal Malware unpack itself ComputerName crashed
2.8 M 57 ZeroCERT

1965 2025-02-18 18:06 build.gradle  

9e19a43480a7ac18bfc3165cc90a2bde


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest