Summary: 2025/04/24 18:43

First reported date: 2012/03/06
Inquiry period : 2025/03/25 18:43 ~ 2025/04/24 18:43 (1 months), 6 search results

전 기간대비 67% 높은 트렌드를 보이고 있습니다.
전 기간대비 상승한 Top5 연관 키워드는
DLL 입니다.
악성코드 유형 ShadowPad 도 새롭게 확인됩니다.
공격기술 Campaign apt 도 새롭게 확인됩니다.
기타 g0njxa actor lure DeepSeek TookPS 등 신규 키워드도 확인됩니다.

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1DLL 6 ▲ 4 (67%)
2g0njxa 1 ▲ new
3Malware 1 - 0 (0%)
4actor 1 ▲ new
5lure 1 ▲ new
6DeepSeek 1 ▲ new
7TookPS 1 ▲ new
8Do 1 ▲ new
9CharlesLydgate 1 ▲ new
10xAdvSec 1 ▲ new
11Campaign 1 ▲ new
12hexe 1 ▲ new
13Malicious 1 ▲ new
14msimg 1 ▲ new
15File 1 ▲ new
16IoC 1 ▲ new
17ShadowPad 1 ▲ new
18delete 1 ▲ new
19apt 1 ▲ new
20flaxtyphoon 1 ▲ new
21Hash 1 ▲ new
22Parents 1 ▲ new
23Execution 1 ▲ new
24Same 1 ▲ new
25Password 1 ▲ new
26Bat 1 ▲ new
27httpstcorSZDzbLcCL 1 ▲ new
28httpstcobTb 1 ▲ new
29Zip 1 ▲ new
30sample 1 ▲ new
31please 1 ▲ new
32httpstcookaMxLx 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
ShadowPad
1 (100%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Campaign
1 (50%)
apt
1 (50%)
Country & Company
Country & Company

This is a country or company that is an issue.


No data.

Additional information

No Title Date
1StaryDobry ruins New Year’s Eve, delivering miner instead of presents - Malware.News2025.02.18
2StaryDobry ruins New Year’s Eve, delivering miner instead of presents - Malware.News2025.02.18
3Qbot is Back.Connect - Malware.News2025.01.20
4Qbot is Back.Connect - Malware.News2025.01.20
5Qbot is Back.Connect - Malware.News2025.01.20
View only the last 5
Level Description
warning File has been identified by 21 AntiVirus engines on VirusTotal as malicious
watch Creates known Upatre files
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates executable files on the filesystem
notice Drops an executable to the user AppData folder
notice One or more potentially interesting buffers were extracted
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
notice Resolves a suspicious Top Level Domain (TLD)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Queries for the computername
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path
info Uses Windows APIs to generate a cryptographic key
Network ET DNS Query to a *.top domain - Likely Hostile
No data
No URL CC ASN Co Reporter Date
1https://osdugalic.edu.rs/Fhmcvdf.vdf
dll encrypted PureLogs stealer
RS RSUnited Internet Ltd.dani55772025.04.23
2https://osdugalic.edu.rs/Txhkx.mp4
dll encrypted PureLogs stealer
RS RSUnited Internet Ltd.dani55772025.04.23
3http://176.65.144.205/example.dll
dll opendir
DE DENDA0E2025.04.21
4http://176.65.144.205/implant.dll
dll opendir
DE DENDA0E2025.04.21
5http://196.251.118.210/d/rref.dll
dll opendir
ZA ZAxneeloNDA0E2025.04.21
View only the last 5
Beta Service, If you select keyword, you can check detailed information.