No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-09-15 12:17 |
NCV~00983763673938FTS.exe 221a9d3316a9019e58e8b38f3730d499Generic Malware Admin Tool (Sysinternals etc ...) PE File .NET EXE PE32 VirusTotal Malware Check memory Checks debugger unpack itself crashed |
1.8 | 20 | ZeroCERT | |||||||||||||||||||
|
||||||||||||||||||||||||
2 | 2021-09-14 10:21 |
BTRU_0498763892I3HJ.exe 6c095aa22ec999e590500d62c00cdcc2Generic Malware Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM PE File .NET EXE PE32 VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW human activity check Windows ComputerName DNS Cryptographic key DDNS |
2 | 1 | 15.6 | 27 | ZeroCERT | |||||||||||||||||
|