Reports containing the tag Windows

VioletWorm - game.exe

A PyInstaller-packed Python loader that patches AMSI and ETW, checks for sandboxes, then drops an obfuscated .NET dropper which deploys a Venom/AsyncRAT-lineage remote access trojan. The RAT persists through startup, registry and scheduled tasks, and supports keylogging, screen and webcam capture, credential theft, file encryption and USB spreading.

Updated 7 September 2026
Difficulty Easy
Platform Windows

WannaCry - invoice_greenanimals.pdf.exe

The WannaCry-family executable checks a hardcoded kill-switch domain and, if unresolved, encrypts user files, deletes backups, and propagates laterally via SMB while establishing persistence through Windows services and registry modifications. It disables recovery options, uses anti-debugging and service-disguise techniques for stealth, and aggressively scans the internal network to maximize disruption and data loss.

Updated 15 February 2026
Difficulty Medium
Platform Windows

VenomRAT - ClientAny.exe

A 32-bit C# VenomRAT-style Trojan persists in AppData and decrypts an AES-256 config (RSA-signed) before connecting to a certificate-pinned C2 over TLS. It logs keystrokes, enumerates system info, downloads plugins, and continuously runs anti-analysis checks plus a process-killer to evade inspection.

Updated 15 November 2025
Difficulty Easy
Platform Windows