No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-08-27 16:08 |
vbc.exe 47fa27443cb1abe987ca9f653754b6d0Malicious Library DGA DNS Socket Create Service Sniff Audio Escalate priviledges KeyLogger Code injection HTTP Internet API FTP ScreenShot Http API Steal credential Downloader P2P AntiDebug AntiVM PE File PE32 FormBook Emotet Malware download VirusTotal Malware Buffer PE AutoRuns Code Injection Malicious Traffic buffers extracted Creates executable files RWX flags setting unpack itself Windows utilities suspicious process WriteConsoleW Tofsee Windows ComputerName DNS |
17
|
21 | 3 | 13.4 | M | 39 | ZeroCERT | |||||||||||||||
|
||||||||||||||||||||||||
2 | 2021-08-26 08:37 |
bill.exe 27ee757d743631d49dcb3c6d7c90dfbeAdmin Tool (Sysinternals etc ...) Malicious Library PE File PE32 Emotet VirusTotal Malware Buffer PE Code Injection buffers extracted RWX flags setting unpack itself Tofsee |
3
|
4 | 1 | 5.6 | 18 | ZeroCERT | ||||||||||||||||
|