No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2023-07-05 11:03 |
mazx.exe 60822680920de27aed07c2352674f05cFormbook Generic Malware .NET framework(MSIL) Antivirus AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware powershell PDB suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key |
10.2 | 48 | r0d | |||||||||||||||||||
|
||||||||||||||||||||||||
2 | 2023-07-04 17:50 |
mazx.exe 60822680920de27aed07c2352674f05cFormbook AgentTesla Generic Malware .NET framework(MSIL) Antivirus AntiDebug AntiVM PE File .NET EXE PE32 FormBook Malware download VirusTotal Malware PDB suspicious privilege Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut unpack itself suspicious process WriteConsoleW Windows ComputerName Cryptographic key |
1
|
3 | 1 | 10.4 | M | 40 | ZeroCERT | |||||||||||||||
|