Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
2041 2025-02-18 18:21 pythiksdaw.exe  

e5a9ac4c2f128b4dda9c41a56cb221b1


Generic Malware Malicious Library PE File PE64 FTP Client Info Stealer VirusTotal Email Client Info Stealer Malware Malicious Traffic Check memory buffers extracted unpack itself Tofsee Email Software
1 2 1 5.0 M 53 ZeroCERT

2042 2025-02-18 18:21 icon.icns  

dd555ff12fe4ecc24253344609786132


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2043 2025-02-18 18:21 icon.icns  

dd555ff12fe4ecc24253344609786132


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2044 2025-02-18 18:19 PkgInfo  

c162b5333eece2dcb4fe2665e5b66d5b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2045 2025-02-18 18:19 setup_108.msi  

ce3c1ccbf868868cb94d24893e398870


Generic Malware Malicious Library MSOffice File CAB OS Processor Check VirusTotal Malware suspicious privilege Check memory Checks debugger unpack itself AntiVM_Disk VM Disk Size Check ComputerName
1 2 2.6 M 27 ZeroCERT

2046 2025-02-18 18:19 PkgInfo  

c162b5333eece2dcb4fe2665e5b66d5b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2047 2025-02-18 18:18 Info.plist  

56ebcffeaaad2fe9baec066cd278ca9c


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection unpack itself Windows utilities malicious URLs Windows DNS
1 4.8 guest

2048 2025-02-18 18:18 Info.plist  

56ebcffeaaad2fe9baec066cd278ca9c


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection unpack itself Windows utilities malicious URLs Windows DNS
1 4.8 guest

2049 2025-02-18 18:18 BTC-Flasher.exe  

4c9e0721e37503107c9fa2a53fecd716


njRAT backdoor Generic Malware Malicious Library Antivirus UPX PE File MSOffice File CAB PE32 OS Processor Check OS Name Check DLL VirusTotal Malware PDB suspicious privilege Check memory Checks debugger buffers extracted Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check Windows ComputerName RCE DNS Cryptographic key
1 1 5.8 M 41 ZeroCERT

2050 2025-02-18 18:16 gradlew.bat  

632f7f6dcc28a13f168cc431061e0438


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence Anti_VM AntiDebug AntiVM ZIP Format OS Check memory buffers extracted RWX flags setting unpack itself Check virtual network interfaces malicious URLs WriteConsoleW Ransomware crashed
6 4.0 guest

2051 2025-02-18 18:16 gradlew.bat  

632f7f6dcc28a13f168cc431061e0438


Generic Malware Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence Anti_VM AntiDebug AntiVM ZIP Format OS Check memory buffers extracted RWX flags setting unpack itself Check virtual network interfaces malicious URLs WriteConsoleW Ransomware crashed
6 4.0 guest

2052 2025-02-18 18:16 mkthooesfja.exe  

d934e572b7078873439fc889dc55fd27


PE File PE32 VirusTotal Malware unpack itself ComputerName DNS crashed
1 3.4 M 60 ZeroCERT

2053 2025-02-18 18:14 BetaCraft Launcher  

b64a80b34325c1fa6ce3a49ff8a89d95


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2054 2025-02-18 18:14 BetaCraft Launcher  

b64a80b34325c1fa6ce3a49ff8a89d95


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest

2055 2025-02-18 18:14 settings.gradle  

9c8e022315dce32d5e181eee0c2a7102


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
1 5.2 guest