Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
45151 2024-06-08 05:23 stopservices.cmd  

ca1880f2d6fb1b32595c049c9d7dc1db


Downloader task schedule Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

45152 2024-06-08 05:23 mysql_installservice-win10.cmd  

c3f725b9691259bd095bff47aa0ab077


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P Hijack Network AntiDebug AntiVM Windows utilities WriteConsoleW Windows
1.0 guest

45153 2024-06-08 05:24 audit.vbs  

15d55b48219e0b14efa29f7d9c8fe885


[C] All Process task schedule Downloader Antivirus [C] OS Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P Anti_VM AntiDebug AntiVM WMI malicious URLs ComputerName
1.4 guest

45154 2024-06-08 05:24 wmifiletypesearchexe.vbs  

b7f5a16836f71574484136e77415ca4b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs ComputerName
1.0 guest

45155 2024-06-08 05:25 PopupMenu.js  

b7e1851d03c8ccc2389d75113ab4ea21


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

45156 2024-06-08 05:25 admin_config.js  

7aeb9d957d35eff708c605f3c8117ae6


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs crashed
1.0 guest

45157 2024-06-08 05:25 audit_mysql_query.js  

fb19223c47d5c7074fd72c85cc60dda8


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

45158 2024-06-08 05:25 offline.cmd  

558c011f11e9172d07fe2db3d2d47e71


task schedule Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM WriteConsoleW
0.6 guest

45159 2024-06-08 05:25 oaclientside.cmd  

008780c9a914156a8190fbfb852fb9c3


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API FTP KeyLogger P2P AntiDebug AntiVM unpack itself WriteConsoleW
1.0 guest

45160 2024-06-08 05:26 openaudit-clientscan-setup.exe  

2a94bd23e9d3665a0b465535cf3cbb8f


Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM PE File PE32 MZP Format OS Processor C Checks debugger unpack itself malicious URLs
2.0 guest

45161 2024-06-08 05:26 audit_sched.js  

490e105efd842b5ff901d8399022e00b


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

45162 2024-06-08 05:26 audit_log.html  

cfc4dd7a77f4dd5fa271fc822560302e


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM Code Injection unpack itself Windows utilities malicious URLs Tofsee Windows DNS
2 2.8 guest

45163 2024-06-08 05:26 ajax.js  

abde971f007c55f8747734b91684e174


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest

45164 2024-06-08 05:26 jquery-bgiframe.js  

a868cdfcb65ff0bb01f30b5a4f56d080


Downloader Create Service Http API ScreenShot Escalate priviledges Steal credential PWS Code injection Internet API KeyLogger AntiDebug AntiVM crashed
0.6 guest

45165 2024-06-08 05:26 include.js  

22baec7a2a86d615172bd87a6f5b8651


Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM malicious URLs
0.8 guest