No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-09-24 17:07 |
escrow.exe 4568267da235d998580cfd9d8b828715UPX Admin Tool (Sysinternals etc ...) Malicious Library DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Internet API FTP ScreenShot Http API Steal credential Downloader P2P AntiDebug AntiVM PE File PE32 Emotet VirusTotal Malware Buffer PE AutoRuns Code Injection buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Windows ComputerName crashed |
3
|
6 | 1 | 10.6 | M | 33 | ZeroCERT | |||||||||||||||
|
||||||||||||||||||||||||
2 | 2021-09-24 09:03 |
imagess.exe 546b3cc7640a0c3105f6674fd9e2debfUPX Malicious Library PE File PE32 VirusTotal Malware RWX flags setting unpack itself Tofsee crashed |
2 | 2 | 2.2 | 27 | ZeroCERT | |||||||||||||||||
|