Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3106 2025-01-23 06:26 Application_MSSQLSERVER_15457....  

877a1f9ba7dcd670a960c474de6e033a


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3107 2025-01-23 06:25 Application_MSSQLSERVER_15457....  

877a1f9ba7dcd670a960c474de6e033a


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3108 2025-01-23 06:25 !!!!README.md  

d29ecd4233ef8075c1aacd944268f1e9


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3109 2025-01-23 06:23 !!!!README.md  

d29ecd4233ef8075c1aacd944268f1e9


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3110 2025-01-23 06:23 Windows-PowerShell_PowerShell_...  

b5caea4b8d6aeb6512c89a0d627c1580


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3111 2025-01-23 06:22 Windows-PowerShell_PowerShell_...  

a2c4e7a3f51ca62a4d4790a89fd3a38e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3112 2025-01-23 06:21 Windows-PowerShell_PowerShell_...  

de802b4cdea5d7b7a7feeea24c08de7e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3113 2025-01-23 06:20 Windows-PowerShell_PowerShell_...  

b9e484713f9c46fffbe56d284d89a94b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3114 2025-01-23 06:20 Windows-PowerShell_PowerShell_...  

b5caea4b8d6aeb6512c89a0d627c1580


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3115 2025-01-23 06:19 Varonis_VrnsSvcFW_900.map  

a0da0733bc3d9751f9230bf5e8e92ae8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3116 2025-01-23 06:18 Windows-PowerShell_PowerShell_...  

a2c4e7a3f51ca62a4d4790a89fd3a38e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3117 2025-01-23 06:18 Varonis_VrnsMon_5434.map  

67c6d373e5e4bcfb7ba31e5b70b89660


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3118 2025-01-23 06:16 Windows-PowerShell_PowerShell_...  

de802b4cdea5d7b7a7feeea24c08de7e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3119 2025-01-23 06:16 Varonis_VrnsCifsQueueReport_51...  

b97d8df7b2eb28852fbe8c59ca54cccc


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3120 2025-01-23 06:16 Windows-PowerShell_PowerShell_...  

b9e484713f9c46fffbe56d284d89a94b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest