No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-10-13 11:19 |
S~0339837653_03987653367838763... b1f6ec33a7a1ce75919cef261b95cdaePWS .NET framework Generic Malware DNS AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted unpack itself Windows utilities suspicious process WriteConsoleW human activity check Windows ComputerName DNS DDNS |
2 | 1 | 16.0 | 22 | ZeroCERT | |||||||||||||||||
|
||||||||||||||||||||||||
2 | 2021-10-07 11:49 |
DMWN_04995676543-567654466543.... ad56b381a24fd7faefbba99bce158b68Generic Malware Admin Tool (Sysinternals etc ...) DNS AntiDebug AntiVM PE File PE32 .NET EXE VirusTotal Malware Buffer PE AutoRuns suspicious privilege MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities suspicious process AppData folder WriteConsoleW human activity check Windows ComputerName DNS DDNS |
2 | 1 | 15.8 | 22 | ZeroCERT | |||||||||||||||||
|