Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45106 2024-06-08 05:04 makecert2.cmd  

dc399dc9986b37e8e48fc2a61f9cfcac


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

45107 2024-06-08 05:04 wmifiletypesearchexe.vbs  

b7f5a16836f71574484136e77415ca4b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM unpack itself malicious URLs ComputerName crashed
1.6 guest

45108 2024-06-08 05:05 terminalsessionprocesses.vbs  

527b0068fc86c4fd5ff97ad78d32cbd1


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
2.0 guest

45109 2024-06-08 05:05 OpenAudit-nmap-NetzScan.cmd  

62678f71bb1fb7f0803191f69ed73acc


task schedule Downloader Create Service Http API ScreenShot Escalate priviledges PWS Code injection Internet API KeyLogger Socket DGA Steal credential Sniff Audio HTTP DNS FTP P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

45110 2024-06-08 05:06 oaclientside.cmd  

008780c9a914156a8190fbfb852fb9c3


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

45111 2024-06-08 05:08 firewall-win10-open-oa.cmd  

c14d829053bc52e0df45f97cfa6913ac


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Firewall state off Windows
1.6 guest

45112 2024-06-08 05:10 admin_config.js  

7aeb9d957d35eff708c605f3c8117ae6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs DNS crashed
1.6 guest

45113 2024-06-08 05:10 PopupMenu.js  

b7e1851d03c8ccc2389d75113ab4ea21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File malicious URLs crashed
1.0 guest

45114 2024-06-08 05:10 Openaudit-Clientscan.lnk  

afa017bc06e99f342bcabf241ef1a631


Generic Malware task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Lnk Format GIF Creates shortcut unpack itself malicious URLs WriteConsoleW
1.8 guest

45115 2024-06-08 05:10 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P persistence AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

45116 2024-06-08 05:10 ajax.js  

abde971f007c55f8747734b91684e174


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

45117 2024-06-08 05:11 export_file.html  

ba18e54410f8138a68ae1e581c241032


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.8 guest

45118 2024-06-08 05:11 async_alerts.js  

09e2e0e7aa88ad413b5319d8268a1d1d


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

45119 2024-06-08 05:11 index.html  

0227cfd904e99656279202032b98d4a7


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM StartPage Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
2 4.2 guest

45120 2024-06-08 05:12 audit_cmd.js  

9b3f2bc442accabeaf421ab5f15229ad


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest