top title background image
Malware  Trends
flash

Detection Sample Info Download Report Classification & Info Graph
Malicious
https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Fapc01.safelinks.protection.outlook.com.mcas.ms%2F%3Furl%3Dhttps%253A%252F%252Fmyapps.microsoft.com%252Fsignin%252F08558f59-9161-41fc-88b3-f0434087a79c%253FtenantId%253D258ac4e4-146a-411e-9dc8-79a9e12fd6da%26data%3D05%257C01%257Cgary.fabrizio1%2540Service.wipro.com%257C8a0e1c61209e469846ba08dbe05e2370%257C258ac4e4146a411e9dc879a9e12fd6da%257C0%257C0%257C638350467206547446%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C3000%257C%257C%257C%26sdata%3Dp0jrjFUb%252Fusi2RID%252FGIlCE82AM9dEDuVAB4PHdDC1%252F4%253D%26reserved%3D0%26McasTsid%3D20893&McasCSRF=a0328b22f805eebb5f9c68ee3df482ea7a84065b3bbced70493927bf9ce1f085
2024-04-26 05:11:13 +02:00
Info
Class
Malicious
https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Fapc01.safelinks.protection.outlook.com.mcas.ms%2F%3Furl%3Dhttps%253A%252F%252Fwittywebevents.wipro.com%252Femail-analytics%252Fapi%252Ft%252Fl%253FobjId%253D637c92a3e4b00b92caee94cc%26data%3D05%257C02%257Cgary.fabrizio1%2540wipro.com%257Cb8fe953db5914d2bac8108dc65645f6b%257C258ac4e4146a411e9dc879a9e12fd6da%257C0%257C0%257C638496729264132835%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C0%257C%257C%257C%26sdata%3DX8fjcrb6FJIv3A6MeNVFttkEvMY37x2gBwDUYM2DULg%253D%26reserved%3D0%26McasTsid%3D20893&McasCSRF=a0328b22f805eebb5f9c68ee3df482ea7a84065b3bbced70493927bf9ce1f085
2024-04-26 04:58:44 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
  • Snort
Lokibot, PureLog Stealer
AV: 32%
gunzipped.exe
2024-04-26 04:56:08 +02:00
Info
Class
Malicious
  • Yara
Okiru
AV: 23%
no Icon
RJ93lr3oq2.elf
2024-04-26 04:56:07 +02:00
Info
Class
Malicious
  • Yara
Gafgyt
AV: 29%
no Icon
93dYAEq6GA.elf
2024-04-26 04:56:07 +02:00
Info
Class
Clean
http://i.ms00.net/subscribe?server_action=Unsubscribe&list=ABACI&sublist=*&msgid=1621616770.49009&email_address=lrobinson%40healthplan.com
2024-04-26 04:46:28 +02:00
Info
Malicious
  • Yara
  • Snort
Lokibot, PureLog Stealer
AV: 1%
SCB#89940578.exe
2024-04-26 04:41:06 +02:00
Info
Class
Malicious
https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Fapc01.safelinks.protection.outlook.com.mcas.ms%2F%3Furl%3Dhttps%253A%252F%252Fwittywebevents.wipro.com%252Femail-analytics%252Fapi%252Ft%252Fl%253FobjId%253D637c92a3e4b00b92caee94cc%26data%3D05%257C02%257Cgary.fabrizio1%2540wipro.com%257Cb8fe953db5914d2bac8108dc65645f6b%257C258ac4e4146a411e9dc879a9e12fd6da%257C0%257C0%257C638496729264132835%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C0%257C%257C%257C%26sdata%3DX8fjcrb6FJIv3A6MeNVFttkEvMY37x2gBwDUYM2DULg%253D%26reserved%3D0%26McasTsid%3D20893&McasCSRF=a0328b22f805eebb5f9c68ee3df482ea7a84065b3bbced70493927bf9ce1f085
2024-04-26 04:36:49 +02:00
Info
Class
Clean
https://docs.google.com/spreadsheets/d/1qiQHi_eW_ieX8FKKwfGKjkoErnhSxrQVYugKn-b7cEI/edit?usp=sharing
2024-04-26 04:31:04 +02:00
Info
Clean
https://us01.z.antigena.com/l/NM2_H3ohNaRsbxY0Qdv4tcu-YkhvHclHJbkSoc2ofvnMoIHuAqgUgrAiSg6Qt7i_rqr0mH7jxNDC-4wXqfiErs_yPWHYm7jFHUscHWs9ox23Spe7sX5rsyG-tlvnffVksBE56tpP-FnJ95DM1PM4f~SVGHa_7-CMkyDVecw2k-PpHpNa6Af-X_pKWmPU12NzCwOpVCzGlpztUuyezOwCoREkOTvhFUxaVzborvShlz4dJNuPvPO3c6qgQFd2xCKN7yXxSb7s
2024-04-26 04:16:34 +02:00
Info
Malicious
Mol2sxTjLw.exe
2024-04-26 04:06:16 +02:00
Info
Class
Suspicious
no Icon
R2n8x3VrH8
2024-04-26 03:59:29 +02:00
Info
Class
Clean
http://apresolve.spotify.com
2024-04-26 03:58:17 +02:00
Info
Malicious
https://newtipsguide.com
2024-04-26 03:55:13 +02:00
Info
Malicious
04-25-Inv-Doc-339.pdf
2024-04-26 03:42:05 +02:00
Info
Class
Clean
https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483
2024-04-26 03:28:56 +02:00
Info
Malicious
  • Sigma
HTMLPhisher
AV: 1%
https://cdp1.tracking.e360.salesforce.com/click?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ0ZW5hbnRfaWQiOiJhMzYwL3Byb2QvNTBhMGYyODg2ZTg4NDA3Y2I1ODUwYmRjOWQwZGIxZTUiLCJjcmVhdGlvbl90aW1lIjoxNzE0MDg4MzE4LCJtZXNzYWdlX2lkIjoiMGd4dnAwdGZzeWpiNm4yamRiMDRuYWd5IzcyNWE1YTc5LTgxYzQtNGM0Yy1iNmI1LTdmMTY0MTM2ZTE2NCIsImNoYW5uZWxfdHlwZSI6ImVtYWlsIiwiZXhwIjoxNzQ1NjI0MzE4LCJyZWRpcmVjdF91cmwiOiJodHRwczovL3ZtLmJyYWRlbnRvbmNjLmluZm8vP2VvdmlldWJyJnFyYz1yZW5lZS5zY2h3YXJ0ekBxci5jb20uYXUiLCJpbmRpdmlkdWFsX2lkIjoiODdiZTY3MTdlZjJmMThjYzI3YmMyMWQ4OTJhY2Q2NzAifQ.iusDS7mld4iiq9DDY82R1MJ9ToHxmMDW3SMbDENZOZQ
2024-04-26 03:25:27 +02:00
Class
no
Graph
Malicious
  • Yara
  • Sigma
AgentTesla
AV: 46%
Payment Swift.doc
2024-04-26 03:04:59 +02:00
Info
Class
Malicious
https://marinatitle.com
2024-04-26 03:04:54 +02:00
Info
Malicious
  • Yara
AV: 60%
week6.rtf
2024-04-26 02:49:59 +02:00
Info
Windows: InjectsWrites Registry keysDrops PE FilesHas more than one ProcessHas Email attachmentDisassembly is available
Android: Receives SMS Sends SMS Reboot Native CMD
Common: Generates Internet Traffic Generates HTTP Network Traffic Expired Sample Creates malicious files Contains malware configuration(s)
Customization Show ID column