Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CryptBot | A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2. | No Attribution |
|
AV Detection |
---|
Source: |
Avira: |
Source: |
ReversingLabs: |
Source: |
ReversingLabs: |
Source: |
Integrated Neural Analysis Model: |
Source: |
Joe Sandbox ML: |
Source: |
Code function: |
14_2_001015B0 | |
Source: |
Code function: |
14_2_6C9B14B0 |
Source: |
Binary or memory string: |
memstr_c48ac3c6-f |
Source: |
Static PE information: |
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior |
Source: |
Code function: |
14_2_001081E0 | |
Source: |
Code function: |
14_2_6CA2AEC0 | |
Source: |
Code function: |
14_2_6CA2AF70 | |
Source: |
Code function: |
14_2_6CA2AF70 | |
Source: |
Code function: |
14_2_6C9D0860 | |
Source: |
Code function: |
14_2_6C9DA9E0 | |
Source: |
Code function: |
14_2_6C9DA9E0 | |
Source: |
Code function: |
14_2_6C9DA970 | |
Source: |
Code function: |
14_2_6C9CEB10 | |
Source: |
Code function: |
14_2_6CA584A0 | |
Source: |
Code function: |
14_2_6C9D4453 | |
Source: |
Code function: |
14_2_6C9DA580 | |
Source: |
Code function: |
14_2_6C9DA5F0 | |
Source: |
Code function: |
14_2_6C9DA5F0 | |
Source: |
Code function: |
14_2_6C9DC510 | |
Source: |
Code function: |
14_2_6C9DE6E0 | |
Source: |
Code function: |
14_2_6C9DE6E0 | |
Source: |
Code function: |
14_2_6CA50730 | |
Source: |
Code function: |
14_2_6C9D0740 | |
Source: |
Code function: |
14_2_6CA2C040 | |
Source: |
Code function: |
14_2_6CA2C1A0 | |
Source: |
Code function: |
14_2_6CA0A1E0 | |
Source: |
Code function: |
14_2_6C9D0260 | |
Source: |
Code function: |
14_2_6CA84360 | |
Source: |
Code function: |
14_2_6CA2BD10 | |
Source: |
Code function: |
14_2_6CA27D10 | |
Source: |
Code function: |
14_2_6CA23840 | |
Source: |
Code function: |
14_2_6C9DD974 | |
Source: |
Code function: |
14_2_6C9EBBDB | |
Source: |
Code function: |
14_2_6C9EBBD7 | |
Source: |
Code function: |
14_2_6CA09B60 | |
Source: |
Code function: |
14_2_6CA2B4D0 | |
Source: |
Code function: |
14_2_6C9DD504 | |
Source: |
Code function: |
14_2_6CA23690 | |
Source: |
Code function: |
14_2_6CA29600 | |
Source: |
Code function: |
14_2_6C9DD674 | |
Source: |
Code function: |
14_2_6C9DD7F4 | |
Source: |
Code function: |
14_2_6C9CB1D0 | |
Source: |
Code function: |
14_2_6CA53140 | |
Source: |
Code function: |
14_2_6C9DD2A0 | |
Source: |
Code function: |
14_2_6CA47350 |
Source: |
Memory has grown: |
Networking |
---|
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |