top title background image
Malware  Trends
flash

Detection Sample Info Download Report Classification & Info Graph
Suspicious
no Icon
"C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exe" -Nologo -Noninteractive -NoProfile -ExecutionPolicy Bypass; Get-DeliveryOptimizationStatus | where-object {($_.Sourceurl -CLike 'http://localhost:8005*') -AND (($_.FileSize -ge '52428800') -or ($_.BytesFromPeers -ne '0') -or (($_.BytesFromCacheServer -ne '0') -and ($_.BytesFromCacheServer -ne $null)))} | select-object -Property BytesFromHttp, FileId, BytesFromPeers,Status,BytesFromCacheServer,SourceURL | ConvertTo-Xml -as string -NoTypeInformation
2024-04-09 23:12:43 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 55%
wxtOggNiOz.exe
2024-04-09 23:11:17 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 84%
7zeKicTvU6.exe
2024-04-09 23:11:17 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 84%
0Jh5phP1Nx.exe
2024-04-09 23:11:17 +02:00
Info
Class
Clean
https://ky3p.markit.com/vendor/redirect?input=%2Fhome%2Findex.html%23%2Fevent%2F351%2F
2024-04-09 23:09:57 +02:00
Info
Clean
http://nireos.com
2024-04-09 23:08:41 +02:00
Info
Malicious
  • Yara
BlackMoon
AV: 53%
tZSp0zeyBq.exe
2024-04-09 23:08:21 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
  • Snort
BlackMoon
AV: 89%
X5F9Geek7L.exe
2024-04-09 23:08:21 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 53%
9EycRE7Q08.exe
2024-04-09 23:08:21 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 50%
flym64ca6i.exe
2024-04-09 23:08:21 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
  • Snort
BlackMoon
AV: 92%
NVZADVHptk.exe
2024-04-09 23:08:16 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 53%
iqzje23tB6.exe
2024-04-09 23:07:16 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 89%
43Dnh0Vt7j.exe
2024-04-09 23:07:15 +02:00
Info
Class
Malicious
AV: None
http://tnfarmbureau.org
2024-04-09 23:05:15 +02:00
Info
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 84%
Q31OElPV4F.exe
2024-04-09 23:04:20 +02:00
Info
Class
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 84%
OO81I5RQqm.exe
2024-04-09 23:04:20 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 55%
PpCa8N8GZd.exe
2024-04-09 23:04:19 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 50%
bL1FRTUQyC.exe
2024-04-09 23:04:19 +02:00
Class
Malicious
  • Yara
  • Sigma
BlackMoon
AV: 89%
d2c6dwuz1l.exe
2024-04-09 23:03:14 +02:00
Info
Class
Malicious
  • Yara
BlackMoon
AV: 55%
ybEOb2wN6v.exe
2024-04-09 23:01:19 +02:00
Info
Class
Windows: InjectsWrites Registry keysDrops PE FilesHas more than one ProcessHas Email attachmentDisassembly is available
Android: Receives SMS Sends SMS Reboot Native CMD
Common: Generates Internet Traffic Generates HTTP Network Traffic Expired Sample Creates malicious files Contains malware configuration(s)
Customization Show ID column