Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1FTP 2 ▲ new
2access 2 ▲ new
3Sale 2 ▲ new
4United States 2 ▲ new
5Alleged 1 ▲ new
6Report 1 ▲ new
7target 1 ▲ new
8US 1 ▲ new
9Corporation 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


No data.

Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


No data.

Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
United States
2 (66.7%)
US
1 (33.3%)

Additional information

No Title Date
1Microsoft: Hacked Solarwinds FTP Software Lacked Basic Anti-Exploit Mitigation - Securityweek2021.09.03
210 Tips to Protect Your Company’s Data in 2021 - Security Boulevard2021.01.22
3Google Keeps Support for FTP in Chrome - securityweek.com2020.04.15
4Google reenables FTP support in Chrome due to pandemic - Bleeping Computer2020.04.14
5Google Has Started Removing FTP Support From Chrome - Bleeping Computer2019.08.16
View only the last 5
No Request Hash(md5) Report No Date
1http://www.cipd.org/globalasse...
Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File PNG Format JPEG Format
4e58a191b515eed2a9894dc8698bc5c0590782025.04.18
2 layout.bin
Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File
72c582ab7db10af86a90608f98e5e614590582025.04.17
3 os.dat
Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File
af1d8d9435cb10fe2f4b4215eaf6bec4590592025.04.17
4 setup.bmp
Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM BMP Format MSOffice File
f1874e4041a511771e01e079227ca8ca590602025.04.17
5 SETUP.INI
Downloader Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P AntiDebug AntiVM MSOffice File
ac9d9386a57420db9299eb1be1fa82de590622025.04.17
View only the last 5
Level Description
watch Resumed a suspended thread in a remote process potentially indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Performs some HTTP requests
notice Potentially malicious URLs were found in the process memory dump
notice Uses Windows utilities for basic Windows functionality
notice Yara rule detected in process memory
Network ET INFO TLS Handshake Failure
Network SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
No data
No URL CC ASN Co Reporter Date
1http://185.225.17.58/arm7
bash curl ftp tftp wget
RO ROMivoCloud SRLAsh_XSS_12025.01.26
Beta Service, If you select keyword, you can check detailed information.