Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3136 2025-01-23 06:04 Varonis_VrnsCifsQueue_5140.map  

2d7cdef30d507d95c16c0ed76e9324b4


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3137 2025-01-23 06:04 Varonis_VrnsCifsQueue_5213.map  

22e8b86d864bb361a7afcdc94568eb4f


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3138 2025-01-23 06:04 Varonis_VrnsCifsQueue_5138.map  

47949b735bfd6a481fbf2ed091bf8293


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3139 2025-01-23 06:03 Varonis_VrnsCifsQueue_5172.map  

eac18296ea6a01ae4ee2a160d0c45f7e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3140 2025-01-23 06:02 Varonis_VrnsCifsQueue_5176.map  

a36b108c5dbbd4355b8002b0147f7496


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3141 2025-01-23 06:01 Varonis_VrnsCifsQueue_5129.map  

f857fc7be8b2fb98dbfcf585df605b0d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3142 2025-01-23 05:59 System_User32_1074.map  

433ee05879541b60b125e2f591bf9763


Generic Malware Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3143 2025-01-23 05:59 Varonis_VrnsCifsQueue_5140.map  

2d7cdef30d507d95c16c0ed76e9324b4


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3144 2025-01-23 05:59 System_TermDD_56.map  

0f91a887f0ba23de1d84cb869e38ec04


Generic Malware Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3145 2025-01-23 05:57 Varonis_VrnsCifsQueue_5138.map  

47949b735bfd6a481fbf2ed091bf8293


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3146 2025-01-23 05:57 System_Service-Control-Manager...  

b18e8eba0c0ed5419a9829abf407c3ce


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3147 2025-01-23 05:56 Varonis_VrnsCifsQueue_5129.map  

f857fc7be8b2fb98dbfcf585df605b0d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3148 2025-01-23 05:55 System_Service-Control-Manager...  

f65a3319cb3b5508668743617bbd2f41


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest

3149 2025-01-23 05:54 System_User32_1074.map  

433ee05879541b60b125e2f591bf9763


Generic Malware Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
3.6 guest

3150 2025-01-23 05:54 System_Service-Control-Manager...  

1062314700e60918e1441584083663b1


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting unpack itself Windows utilities malicious URLs Windows DNS
4.2 guest