Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
10501 2023-08-17 18:19 ghostzx.exe  

52299a26c9143bd246e0b9daf6d0788c


AntiDebug AntiVM PE File .NET EXE PE32 PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted ICMP traffic unpack itself suspicious TLD
7 10 9.6 ZeroCERT

10502 2023-08-17 16:09 4ce5f00cf44673e80fcdb462b15f1a...  

c9e6e4d394d7452b79351028c4da0cac


Generic Malware PE File DLL PE64 VirusTotal Malware
1.2 M 40 yjw

10503 2023-08-17 16:01 pass1234_setup.7z  

8155b0ec79e7e80cdab9b7fbdfac1a4c


Escalate priviledges PWS KeyLogger AntiDebug AntiVM Malware suspicious privilege Malicious Traffic Check memory Checks debugger Creates executable files unpack itself suspicious TLD IP Check DNS
19 41 8 6.2 M ZeroCERT

10504 2023-08-17 13:07 com.apple.Music.2F1000D3-C3AD-...  

4352c7f009793bfbc6c4f82b41bf679d


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.2 guest

10505 2023-08-17 13:07 com.apple.dock.2F1000D3-C3AD-5...  

17e0d781c46e575d7cd1a65102b096b5


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

10506 2023-08-17 13:06 com.apple.imservice.SMS.2F1000...  

0b90b856a619d0c9c78143ad7630ae5c


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.8 guest

10507 2023-08-17 13:05 ._com.apple.settings.storage.2...  

ffb4d8eb9973259e382c7815301b9990


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

10508 2023-08-17 13:05 ._com.apple.dock.extra.2F1000D...  

9cfb3c75a7c454e60c65e1ed3a167859


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.2 guest

10509 2023-08-17 13:04 ._com.apple.Music.2F1000D3-C3A...  

244d40f935ec27eb26baf2e3845527a2


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.8 guest

10510 2023-08-17 13:02 ._com.apple.FaceTime.2F1000D3-...  

5e7039aa34d83640d808b521e80bd878


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

10511 2023-08-17 13:02 ._com.apple.airport.agent.2F10...  

4a1530a562779132a67e47595dbf30f2


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.2 guest

10512 2023-08-17 13:01 com.apple.airport.agent.2F1000...  

1489e7501970702e2a673ba1267c311e


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.8 guest

10513 2023-08-17 13:00 ._com.apple.dock.2F1000D3-C3AD...  

68975764dc250f31d5021c5c587d6840


AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
3.8 guest

10514 2023-08-17 12:59 ._com.apple.ManagedClient.2F10...  

41114c4265d6c9fd9768d0c05e2b7cae


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.2 guest

10515 2023-08-17 12:57 ._com.apple.loginwindow.2F1000...  

c243a170c90563ade13243dad8da5ded


Downloader Create Service Socket P2P DGA Steal credential Http API Escalate priviledges PWS Hijack Network Sniff Audio HTTP DNS ScreenShot Code injection Internet API persistence FTP KeyLogger AntiDebug AntiVM MSOffice File Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit DNS crashed
4.8 guest