No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-10-06 13:44 |
1906116528.exe 3ab2c790255aaeb328042c08a8ded716RAT Gen1 Generic Malware Malicious Library ASPack UPX Antivirus Anti_VM Malicious Packer Admin Tool (Sysinternals etc ...) DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Internet API FTP ScreenShot Http API St VirusTotal Malware powershell AutoRuns PDB suspicious privilege MachineGuid Code Injection Check memory Checks debugger Creates shortcut Creates executable files unpack itself Windows utilities powershell.exe wrote Check virtual network interfaces suspicious process AppData folder WriteConsoleW Windows ComputerName Remote Code Execution Cryptographic key crashed |
9.2 | M | 38 | ZeroCERT | ||||||||||||||||||
|