Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
44926 2024-06-07 23:30 apache_uninstallservice-win10....  

9c1c5aa0b87f0183713f5904656a1ef8


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

44927 2024-06-07 23:33 oa-importcert.cmd  

4d3f949bda6999f920d5338e785f75f2


Generic Malware Downloader task schedule Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network SMTP persistence AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key
5.0 guest

44928 2024-06-07 23:38 makecert2.cmd  

dc399dc9986b37e8e48fc2a61f9cfcac


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

44929 2024-06-07 23:39 OpenAudit-nmap-NetzScan.cmd  

62678f71bb1fb7f0803191f69ed73acc


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM WriteConsoleW
0.6 guest

44930 2024-06-07 23:46 oa-importcert.cmd  

4d3f949bda6999f920d5338e785f75f2


Generic Malware Downloader task schedule Antivirus Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP SMTP DNS Code injection Internet API persistence FTP KeyLogger P2P Hijack Network AntiDebug AntiVM powershell suspicious privilege Check memory Checks debugger Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process malicious URLs WriteConsoleW Windows ComputerName Cryptographic key
5.0 guest

44931 2024-06-07 23:56 OpenAudit-nmap-NetzScan.cmd  

62678f71bb1fb7f0803191f69ed73acc


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM WriteConsoleW
0.6 guest

44932 2024-06-07 23:56 OpenAuditPC-Scan.cmd  

14402d1cf83cf7c3fc19cd733cedcb9e


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

44933 2024-06-07 23:59 OpenAuditPC-Scan.cmd  

14402d1cf83cf7c3fc19cd733cedcb9e


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

44934 2024-06-08 00:15 open-audit-console.lnk  

6c610e0cea36418b10e25b6575e7c324


Generic Malware task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format Code Injection Creates shortcut suspicious process WriteConsoleW
2.0 guest

44935 2024-06-08 00:21 open-audit-console.lnk  

6c610e0cea36418b10e25b6575e7c324


Generic Malware task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format Code Injection Creates shortcut suspicious process WriteConsoleW
2.0 guest

44936 2024-06-08 00:26 terminalsessionprocesses.vbs  

527b0068fc86c4fd5ff97ad78d32cbd1


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
2.0 guest

44937 2024-06-08 00:28 openaudit-win7firewall-enabler...  

4d8d32c0abb989f4734a4cf69d8714c7


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

44938 2024-06-08 00:32 terminalsessionprocesses.vbs  

527b0068fc86c4fd5ff97ad78d32cbd1


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
2.0 guest

44939 2024-06-08 00:33 Openaudit-Clientscan.lnk  

afa017bc06e99f342bcabf241ef1a631


Generic Malware Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Format Creates shortcut unpack itself malicious URLs WriteConsoleW
1.8 guest

44940 2024-06-08 00:36 wmifiletypesearchexe.vbs  

b7f5a16836f71574484136e77415ca4b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
1.0 1 guest