No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-10-06 13:57 |
507913557.exe 99f51633e0f6419c6310a9e08d3626a1Generic Malware Malicious Library Antivirus PE64 PE File GIF Format VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut Creates executable files ICMP traffic unpack itself Windows utilities powershell.exe wrote suspicious process AntiVM_Disk sandbox evasion WriteConsoleW Firewall state off VM Disk Size Check Tofsee Windows ComputerName Cryptographic key |
2
|
4 | 2 | 10.8 | M | 38 | ZeroCERT | |||||||||||||||
|