Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3211 2024-06-08 05:06 oaclientside.cmd  

008780c9a914156a8190fbfb852fb9c3


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

3212 2024-06-08 05:05 OpenAudit-nmap-NetzScan.cmd  

62678f71bb1fb7f0803191f69ed73acc


task schedule Downloader Create Service Http API ScreenShot Escalate priviledges PWS Code injection Internet API KeyLogger Socket DGA Steal credential Sniff Audio HTTP DNS FTP P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

3213 2024-06-08 05:05 terminalsessionprocesses.vbs  

527b0068fc86c4fd5ff97ad78d32cbd1


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
2.0 guest

3214 2024-06-08 05:04 wmifiletypesearchexe.vbs  

b7f5a16836f71574484136e77415ca4b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs ComputerName crashed
1.6 guest

3215 2024-06-08 05:04 makecert2.cmd  

dc399dc9986b37e8e48fc2a61f9cfcac


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3216 2024-06-08 05:02 open-audit-console.lnk  

6c610e0cea36418b10e25b6575e7c324


Generic Malware task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format Code Injection Creates shortcut suspicious process WriteConsoleW
2.0 guest

3217 2024-06-08 05:01 firewall-win10-open-oa.cmd  

c14d829053bc52e0df45f97cfa6913ac


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Firewall state off Windows
1.6 guest

3218 2024-06-08 05:01 stopservices.cmd  

ca1880f2d6fb1b32595c049c9d7dc1db


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3219 2024-06-08 05:00 OpenAuditPC-Scan.cmd  

14402d1cf83cf7c3fc19cd733cedcb9e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

3220 2024-06-08 05:00 audit.vbs  

15d55b48219e0b14efa29f7d9c8fe885


[C] All Process task schedule Downloader Antivirus [C] OS Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P Anti_VM AntiDebug AntiVM WMI malicious URLs ComputerName
1.8 guest

3221 2024-06-08 04:59 apache_uninstallservice-win10....  

9c1c5aa0b87f0183713f5904656a1ef8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3222 2024-06-08 04:59 apache_installservice-win10.cm...  

5c308e4bc6c970a6b3fa3db951b6ac1e


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3223 2024-06-08 04:57 stopservices.cmd  

ca1880f2d6fb1b32595c049c9d7dc1db


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3224 2024-06-08 04:56 mysql_installservice-win10.cmd  

c3f725b9691259bd095bff47aa0ab077


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

3225 2024-06-08 04:55 vbrunas.vbs  

0c8b0a86c4471f075663aa5b6227d5bb


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs crashed
1.4 guest