No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2024-04-08 18:28 |
Bnyoyenjf.exe 406f5e63243a13ea32988862ef5cbbe9.NET framework(MSIL) PE File .NET EXE PE32 |
0.4 | M | ZeroCERT | |||||||||||||||||||
|
||||||||||||||||||||||||
2 | 2023-04-02 08:54 |
ntvdm64.exe 5d27d7c444aa9ac075cf892d70357e54PE64 PE File VirusTotal Malware Creates executable files unpack itself |
2.4 | 9 | ZeroCERT | |||||||||||||||||||
|
||||||||||||||||||||||||
3 | 2022-06-07 13:59 |
key.exe 3dd44adbbc24e8702454e60907871b35RAT PE File PE64 VirusTotal Malware MachineGuid Malicious Traffic Check memory Checks debugger unpack itself Check virtual network interfaces |
1
|
2 | 3.2 | M | 30 | ZeroCERT | ||||||||||||||||
|
||||||||||||||||||||||||
4 | 2022-03-22 19:43 |
Jvas.exe 423fd5596706f9d5e29b73ad9a4a6380PWS .NET framework UPX PE32 .NET EXE PE File AutoRuns suspicious privilege Check memory Checks debugger unpack itself Windows utilities Windows DNS Cryptographic key |
1 | 5.2 | M | ZeroCERT | ||||||||||||||||||
|