Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
13246 2021-10-07 17:02 Clipper.exe  

a76095f2d5727733b3ca4bd8a51349a2


RAT PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
10.0 r0d

13247 2021-10-07 17:06 softokn3.dll  

a2ee53de9167bf0d6c019303b7ca84e5


PE File PE32 OS Processor Check DLL PDB
0.2 M guest

13248 2021-10-07 17:06 mozglue.dll  

8f73c08a9660691143661bf7332c3c27


Malicious Packer PE File PE32 OS Processor Check DLL PDB
0.4 M guest

13249 2021-10-07 17:06 sqlite3.dll  

e477a96c8f2b18d6b5c27bde49c990bf


PE File PE32 DLL
guest

13250 2021-10-07 17:06 freebl3.dll  

ef2834ac4ee7d6724f255beaf527e635


PE File PE32 OS Processor Check DLL PDB
0.2 M guest

13251 2021-10-07 17:07 vcruntime140.dll  

7587bf9cb4147022cd5681b015183046


Gen1 Malicious Library PE File PE32 OS Processor Check DLL PDB
0.2 M guest

13252 2021-10-07 17:07 msvcp140.dll  

109f0f02fd37c84bfc7508d4227d7ed5


Gen1 PE File PE32 OS Processor Check DLL PDB
0.4 M guest

13253 2021-10-07 17:07 nss3.dll  

bfac4e3c5908856ba17d41edcd455a51


Malicious Packer Malicious Library PE File PE32 OS Processor Check DLL PDB
0.2 M guest

13254 2021-10-07 17:09 Clipper.exe  

a76095f2d5727733b3ca4bd8a51349a2


RAT PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
9.4 r0d

13255 2021-10-07 17:12 Clipper.exe  

a76095f2d5727733b3ca4bd8a51349a2


RAT PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
9.4 M r0d

13256 2021-10-07 17:16 secret_conversations.html  

e57fdf1dad4fabac8ad020453f07cdbb


AntiDebug AntiVM MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 2 2 3.8 guest

13257 2021-10-07 17:16 Clipper.exe  

a76095f2d5727733b3ca4bd8a51349a2


RAT PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
9.4 M r0d

13258 2021-10-07 17:21 Clipper.exe  

a76095f2d5727733b3ca4bd8a51349a2


RAT PWS .NET framework Generic Malware Antivirus AntiDebug AntiVM PE File PE32 .NET EXE powershell suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
11.0 M r0d

13259 2021-10-07 17:26 secret_conversations.html  

e57fdf1dad4fabac8ad020453f07cdbb


AntiDebug AntiVM MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 2 2 3.8 guest

13260 2021-10-07 17:29 secret_conversations.html  

e57fdf1dad4fabac8ad020453f07cdbb


AntiDebug AntiVM MSOffice File JPEG Format Code Injection RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
1 2 2 3.8 guest