Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
3361 2024-06-08 02:05 admin_config.js  

7aeb9d957d35eff708c605f3c8117ae6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs crashed
1.4 guest

3362 2024-06-08 02:04 export_file.html  

ba18e54410f8138a68ae1e581c241032


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3.8 guest

3363 2024-06-08 02:02 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW DNS
1.6 guest

3364 2024-06-08 02:02 PopupMenu.js  

b7e1851d03c8ccc2389d75113ab4ea21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

3365 2024-06-08 01:59 PopupMenu.js  

b7e1851d03c8ccc2389d75113ab4ea21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

3366 2024-06-08 01:56 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW DNS
1.6 guest

3367 2024-06-08 01:55 index.html  

0227cfd904e99656279202032b98d4a7


AntiDebug AntiVM StartPage MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3.8 guest

3368 2024-06-08 01:52 export_file.html  

ba18e54410f8138a68ae1e581c241032


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

3369 2024-06-08 01:44 openaudit-clientscan-setup.exe  

2a94bd23e9d3665a0b465535cf3cbb8f


Generic Malware Downloader task schedule Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug Checks debugger unpack itself AppData folder malicious URLs
2.4 4 guest

3370 2024-06-08 01:43 audit_log.html  

cfc4dd7a77f4dd5fa271fc822560302e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

3371 2024-06-08 01:40 audit_log.html  

cfc4dd7a77f4dd5fa271fc822560302e


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3.8 guest

3372 2024-06-08 01:39 openaudit-clientscan-setup.exe  

2a94bd23e9d3665a0b465535cf3cbb8f


Generic Malware task schedule Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File Checks debugger unpack itself AppData folder malicious URLs
2.4 4 guest

3373 2024-06-08 01:31 index.html  

0227cfd904e99656279202032b98d4a7


AntiDebug AntiVM StartPage MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
2 3.8 guest

3374 2024-06-08 01:15 audit.vbs  

15d55b48219e0b14efa29f7d9c8fe885


[C] All Process task schedule Downloader Antivirus [C] OS Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P Anti_VM AntiDebug AntiVM WMI malicious URLs ComputerName
1.8 3 guest

3375 2024-06-08 01:08 oaclientside.cmd  

008780c9a914156a8190fbfb852fb9c3


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest