No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2023-03-28 08:21 |
wwa.exe 53622e61772d39cd6868b89aaabb8249RAT Gen1 email stealer Downloader UPX Malicious Packer Malicious Library Socket ScreenShot DNS Code injection PWS[m] Sniff Audio KeyLogger Escalate priviledges persistence AntiDebug AntiVM .NET EXE PE32 PE File OS Processor Check DLL Browser Info Stealer Malware download AveMaria NetWireRC VirusTotal Email Client Info Stealer Malware AutoRuns MachineGuid Code Injection Check memory Checks debugger buffers extracted WMI Creates executable files unpack itself AppData folder malicious URLs AntiVM_Disk VM Disk Size Check installed browsers check Windows Browser RAT Email ComputerName DNS |
3 | 2 | 13.0 | 47 | ZeroCERT | |||||||||||||||||
|