No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2024-11-13 14:11 |
clr.exe a736e23ae291f6d3a848fdb1aaa7348fGeneric Malware UPX Malicious Library PE File PE32 VirusTotal Malware AutoRuns suspicious privilege Check memory WMI Creates executable files Windows utilities WriteConsoleW Windows ComputerName |
6.8 | 55 | ZeroCERT | |||||||||||||||||||
|
||||||||||||||||||||||||
2 | 2022-05-16 12:44 |
mshta.exe b28ddf547716c0cdee99d4e5f261704dRAT PWS .NET framework UPX Antivirus Malicious Packer Malicious Library PE32 OS Processor Check .NET EXE PE File VirusTotal Malware AutoRuns suspicious privilege Check memory Checks debugger Creates executable files unpack itself Windows utilities suspicious process AppData folder Windows ComputerName Remote Code Execution |
6.0 | M | 35 | ZeroCERT | ||||||||||||||||||
|