Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3256 2024-06-08 04:21 audit_config.js  

8844362d35d4da5ab4dbad038f9a226f


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs crashed
1.4 guest

3257 2024-06-08 04:20 audit_cmd.js  

9b3f2bc442accabeaf421ab5f15229ad


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

3258 2024-06-08 04:18 async_alerts.js  

09e2e0e7aa88ad413b5319d8268a1d1d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

3259 2024-06-08 04:18 async_alerts.js  

09e2e0e7aa88ad413b5319d8268a1d1d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs DNS crashed
2.0 guest

3260 2024-06-08 04:18 export_file.html  

ba18e54410f8138a68ae1e581c241032


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

3261 2024-06-08 04:17 ajax.js  

abde971f007c55f8747734b91684e174


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

3262 2024-06-08 04:15 oa-importcert.cmd  

4d3f949bda6999f920d5338e785f75f2


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP SMTP DNS Code injection Internet API persistence FTP KeyLogger P2P Hijack Network AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key
5.0 guest

3263 2024-06-08 04:13 PopupMenu.js  

b7e1851d03c8ccc2389d75113ab4ea21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

3264 2024-06-08 04:12 openaudit-clientscan-setup.exe  

2a94bd23e9d3665a0b465535cf3cbb8f


Downloader Malicious Library UPX Http API ScreenShot Escalate priviledges PWS persistence KeyLogger Create Service Socket DGA Steal credential Sniff Audio HTTP DNS Code injection Internet API FTP P2P AntiDebug AntiVM PE File PE32 MZP Format OS Processor C Checks debugger unpack itself malicious URLs
2.0 4 guest

3265 2024-06-08 04:12 admin_config.js  

7aeb9d957d35eff708c605f3c8117ae6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

3266 2024-06-08 04:12 audit_cmd.js  

9b3f2bc442accabeaf421ab5f15229ad


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

3267 2024-06-08 04:11 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

3268 2024-06-08 04:10 admin_config.js  

7aeb9d957d35eff708c605f3c8117ae6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs crashed
1.4 guest

3269 2024-06-08 04:10 ajax.js  

abde971f007c55f8747734b91684e174


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

3270 2024-06-08 04:10 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest