Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44536 2024-05-28 09:47 applovin_exo_ic_play_circle_fi...  

93728177a4e72b4085403c4b6351fd01


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44537 2024-05-28 09:49 applovin_exo_ic_rewind.xml  

848904b2849c8ba0d3b780401ba616a7


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44538 2024-05-28 09:50 rooming.hta  

5f0dd9ef756c02785e681153c17ee786


Generic Malware Antivirus PowerShell powershell suspicious privilege Check memory Checks debugger Creates shortcut RWX flags setting unpack itself powershell.exe wrote Check virtual network interfaces suspicious process WriteConsoleW Tofsee Windows ComputerName DNS Cryptographic key
3 3 7.6 M ZeroCERT

44539 2024-05-28 09:50 applovin_exo_ic_play_circle_fi...  

93728177a4e72b4085403c4b6351fd01


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44540 2024-05-28 09:51 applovin_exo_ic_rewind.xml  

848904b2849c8ba0d3b780401ba616a7


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44541 2024-05-28 09:54 applovin_exo_ic_skip_next.xml  

4663384a093d8077e134a4eb66aa6c82


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44542 2024-05-28 09:54 applovin_exo_ic_skip_next.xml  

4663384a093d8077e134a4eb66aa6c82


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44543 2024-05-28 09:54 s.exe  

bc6d39d7372c8f38fcc60cf3ce2a48f1


Generic Malware Malicious Library Downloader Malicious Packer UPX PE File PE32 OS Processor Check VirusTotal Malware Check memory unpack itself crashed
2.0 M 51 ZeroCERT

44544 2024-05-28 09:55 applovin_exo_ic_settings.xml  

62e17c87882af2b994f9054d0b3fd4d9


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44545 2024-05-28 09:55 applovin_exo_ic_settings.xml  

62e17c87882af2b994f9054d0b3fd4d9


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44546 2024-05-28 09:56 Setup.exe  

ae47c12b9320e702a9ce243193494554


Generic Malware Malicious Library UPX AntiDebug AntiVM PE File PE32 FTP Client Info Stealer VirusTotal Malware Telegram MachineGuid Code Injection Malicious Traffic Check memory WMI unpack itself Windows utilities Collect installed applications suspicious process AppData folder sandbox evasion WriteConsoleW anti-virtualization installed browsers check Tofsee Windows Browser ComputerName DNS Software
2 5 3 10.8 M 18 ZeroCERT

44547 2024-05-28 09:57 3.exe  

dba41f91114792a95067817ad837f4ab


Generic Malware Malicious Library PE File PE32 VirusTotal Malware unpack itself
1.6 M 25 ZeroCERT

44548 2024-05-28 09:57 applovin_exo_ic_speed.xml  

38afc050777f4820124521f888a0561f


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

44549 2024-05-28 09:57 applovin_exo_ic_skip_previous....  

502d9d6e632de992a431618fcc3f6947


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

44550 2024-05-28 09:58 applovin_exo_ic_skip_previous....  

502d9d6e632de992a431618fcc3f6947


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest