Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3121 2025-01-23 06:16 Windows-PowerShell_PowerShell_...  

de802b4cdea5d7b7a7feeea24c08de7e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3122 2025-01-23 06:16 Varonis_VrnsCifsQueueReport_51...  

b97d8df7b2eb28852fbe8c59ca54cccc


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3123 2025-01-23 06:16 Windows-PowerShell_PowerShell_...  

b9e484713f9c46fffbe56d284d89a94b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3124 2025-01-23 06:14 Varonis_VrnsCifsQueueReport_51...  

9e2b8846c34bbae5353af24078dedc3e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3125 2025-01-23 06:14 Varonis_VrnsSvcFW_900.map  

a0da0733bc3d9751f9230bf5e8e92ae8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3126 2025-01-23 06:13 Varonis_VrnsCifsQueue_5220.map  

fd5999d71505a7cce88f2378f5e332c5


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3127 2025-01-23 06:13 Varonis_VrnsCifsQueueReport_51...  

b97d8df7b2eb28852fbe8c59ca54cccc


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3128 2025-01-23 06:12 Varonis_VrnsMon_5434.map  

67c6d373e5e4bcfb7ba31e5b70b89660


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.8 guest

3129 2025-01-23 06:11 Varonis_VrnsCifsQueue_5214.map  

355298eeef69a8e0934ef886c4a66ce8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3130 2025-01-23 06:09 Varonis_VrnsCifsQueue_5213.map  

22e8b86d864bb361a7afcdc94568eb4f


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3131 2025-01-23 06:09 Varonis_VrnsCifsQueueReport_51...  

9e2b8846c34bbae5353af24078dedc3e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3132 2025-01-23 06:09 Varonis_VrnsCifsQueue_5172.map  

eac18296ea6a01ae4ee2a160d0c45f7e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3133 2025-01-23 06:08 Varonis_VrnsCifsQueue_5176.map  

a36b108c5dbbd4355b8002b0147f7496


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3134 2025-01-23 06:06 Varonis_VrnsCifsQueue_5220.map  

fd5999d71505a7cce88f2378f5e332c5


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3135 2025-01-23 06:06 Varonis_VrnsCifsQueue_5214.map  

355298eeef69a8e0934ef886c4a66ce8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest