1 |
2025-04-21 11:41
|
bilvarw.exe 9d6c51f4f9e0132ea410b8db3c241be6 Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram Malicious Traffic Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199846773220
https://t.me/v00rd
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious 149.154.167.99 - mailcious
116.202.6.216
104.76.74.15 - mailcious
|
3
ET INFO TLS Handshake Failure SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO Observed Telegram Domain (t .me in TLS SNI)
|
|
4.2 |
M |
46 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2 |
2025-04-14 09:52
|
geaswAa.exe dc823d0f1e80400cd6ac7d8e5f68819e Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram Malicious Traffic Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199843252735
https://t.me/f07nd
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(104.75.33.105) - mailcious 149.154.167.99 - mailcious
5.75.215.128
202.43.50.213
|
3
ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
|
|
4.2 |
|
61 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
3 |
2025-03-24 13:35
|
advnrNo.exe 84408fe8f2675bd4b8eb6fae7dcaeffa Themida UPX PE File PE32 VirusTotal Malware Telegram Malicious Traffic Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Tofsee Windows ComputerName DNS crashed |
2
https://steamcommunity.com/profiles/76561199832267488
https://t.me/g_etcontent
|
5
t.me(149.154.167.99) -
steamcommunity.com(104.76.74.15) - 149.154.167.99 -
104.76.74.15 -
95.216.179.65 -
|
3
ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
|
|
8.6 |
|
45 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
4 |
2025-03-20 10:01
|
NWpNjnx.exe 177388c310e9cce7ca37bbab73edc032 Themida UPX PE File PE32 VirusTotal Malware Telegram Malicious Traffic Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Tofsee Windows ComputerName DNS crashed |
2
https://steamcommunity.com/profiles/76561199832267488
https://t.me/g_etcontent
|
5
t.me(149.154.167.99) -
steamcommunity.com(104.76.74.15) - 149.154.167.99 -
95.216.179.65 -
202.43.50.213 -
|
3
ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
|
|
8.6 |
|
41 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
5 |
2025-03-08 12:49
|
sqVWjvh.exe da8846245fb9ec49a3223f7731236c7f Vidar Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram Malicious Traffic Tofsee ComputerName DNS |
3
https://steamcommunity.com/profiles/76561199829660832 - rule_id: 44131
https://steamcommunity.com/profiles/76561199829660832
https://t.me/l793oy
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious 104.75.33.105 - mailcious
149.154.167.99 - mailcious
5.75.210.83 - mailcious
|
3
ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure
|
1
https://steamcommunity.com/profiles/76561199829660832
|
4.2 |
M |
52 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
6 |
2025-02-26 14:50
|
q3na5Mc.exe 4871c39a4a7c16a4547820b8c749a32c Client SW User Data Stealer LokiBot ftp Client info stealer Socket Http API ScreenShot PWS HTTP DNS Internet API AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted unpack itself malicious URLs ComputerName DNS crashed |
2
https://steamcommunity.com/profiles/76561199829660832
https://t.me/l793oy
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious 149.154.167.99 - mailcious
23.49.154.73 - mailcious
159.69.100.232
|
|
|
10.8 |
M |
45 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
7 |
2025-02-21 16:20
|
1.exe efc2de49c53a388807ef989c2f6efa46 Client SW User Data Stealer LokiBot Emotet ftp Client info stealer Malicious Library Malicious Packer UPX Socket Http API ScreenShot PWS HTTP DNS Internet API AntiDebug AntiVM PE File PE32 VirusTotal Malware Telegram Code Injection Malicious Traffic buffers extracted malicious URLs Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199828130190
https://t.me/g02f04
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious 149.154.167.99 - mailcious
23.49.154.73 - mailcious
95.217.24.123
|
3
ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure
|
|
8.8 |
M |
46 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
8 |
2025-02-19 11:44
|
pyjksf.exe d26d5412e2228fb671609e601f95fec6 Generic Malware Malicious Library UPX PE File PE32 OS Processor Check Malware Telegram PDB Malicious Traffic Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199825403037
https://t.me/b4cha00
|
5
t.me() -
steamcommunity.com() - 149.154.167.99 -
95.217.243.100 -
23.49.154.73 -
|
3
ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure
|
|
3.2 |
|
|
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
9 |
2025-02-10 16:18
|
Bjkm5hE.exe 0f2e0a4daa819b94536f513d8bb3bfe2 Vidar Themida UPX PE File PE32 VirusTotal Malware Telegram Malicious Traffic Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Tofsee Windows ComputerName DNS crashed |
1
https://steamcommunity.com/profiles/76561199824159981 - rule_id: 43856
|
5
t.me(149.154.167.99) - mailcious steamcommunity.com(104.76.74.15) - mailcious 104.75.33.105 - mailcious 149.154.167.99 - mailcious 95.217.25.45 - mailcious
|
3
ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
|
1
https://steamcommunity.com/profiles/76561199824159981
|
8.6 |
M |
44 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
10 |
2025-02-06 10:09
|
jrirkfiweid.exe 2049c2a57cf70a27ed25d1a851d55bc3 Vidar Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram PDB Malicious Traffic Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199824159981 - rule_id: 43856 https://steamcommunity.com/profiles/76561199824159981
|
5
t.me(149.154.167.99) - steamcommunity.com(104.75.33.105) - 104.75.33.105 - 149.154.167.99 - 95.217.25.45 -
|
3
ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure
|
1
https://steamcommunity.com/profiles/76561199824159981
|
4.4 |
|
53 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
11 |
2025-02-05 11:22
|
cjrimgid.exe 807dadd8710a7b570ed237fd7cd1aa4b Generic Malware Malicious Library UPX PE File PE32 OS Processor Check VirusTotal Malware Telegram PDB Malicious Traffic Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199824159981
https://t.me/sok33tn
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(104.74.170.104) - mailcious 149.154.167.99 - mailcious
104.74.170.104 - mailcious
95.217.25.45
|
3
ET INFO TLS Handshake Failure SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO Observed Telegram Domain (t .me in TLS SNI)
|
|
4.4 |
M |
49 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
12 |
2025-01-23 06:51
|
jmkykhjksefkyt.exe 65cc23e7237f3cff2d206a269793772e Generic Malware Malicious Library Antivirus UPX PE File PE32 OS Processor Check Malware Malicious Traffic ComputerName DNS |
1
https://steamcommunity.com/profiles/76561199819539662
|
5
t.me(149.154.167.99) - mailcious steamcommunity.com(23.49.154.73) - mailcious 149.154.167.99 - mailcious 95.217.240.67 - 202.43.50.213
|
|
|
3.0 |
M |
|
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
13 |
2025-01-13 16:08
|
random.exe 38a3db1b2362bfb8e0e0537f4299796a Themida UPX PE File PE32 VirusTotal Malware Telegram Malicious Traffic Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Tofsee Windows ComputerName DNS crashed |
2
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl https://steamcommunity.com/profiles/76561199816275252
|
5
t.me(149.154.167.99) - steamcommunity.com(23.49.154.73) - 149.154.167.99 - 104.76.74.15 - 49.12.115.0 -
|
3
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI)
|
|
7.8 |
|
35 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
14 |
2024-12-16 19:27
|
3EUEYgl.exe 3b8b3018e3283830627249d26305419d Themida UPX PE32 PE File VirusTotal Malware Telegram Malicious Traffic Checks debugger unpack itself Checks Bios Detects VMWare VMware anti-virtualization Tofsee Windows ComputerName DNS crashed |
2
https://steamcommunity.com/profiles/76561199807592927
https://t.me/detct0r
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(104.76.74.15) - mailcious 149.154.167.99 - mailcious
104.74.170.104 - mailcious
65.109.242.111
|
3
ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) ET INFO TLS Handshake Failure
|
|
9.6 |
|
58 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
15 |
2024-12-15 17:31
|
TPB-1.exe 760370c2aa2829b5fec688d12da0535f Generic Malware Malicious Library UPX PE32 PE File OS Processor Check VirusTotal Malware Telegram Malicious Traffic unpack itself Tofsee ComputerName DNS |
2
https://steamcommunity.com/profiles/76561199804377619
https://t.me/m3wm0w
|
5
t.me(149.154.167.99) - mailcious
steamcommunity.com(104.76.74.15) - mailcious 149.154.167.99 - mailcious
104.76.74.15 - mailcious
37.27.43.98
|
3
ET INFO TLS Handshake Failure ET INFO Observed Telegram Domain (t .me in TLS SNI) SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
|
|
6.0 |
|
54 |
ZeroCERT
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|