No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-09-10 09:17 |
Mars.exe 0c9ccbdb84f67bdedec3e9bfd0809cf1RAT Generic Malware Malicious Packer Antivirus PE File PE64 VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files unpack itself powershell.exe wrote suspicious process sandbox evasion WriteConsoleW Tofsee Windows ComputerName Cryptographic key |
2
|
4 | 1 | 9.2 | M | 41 | ZeroCERT | |||||||||||||||
|
||||||||||||||||||||||||
2 | 2021-08-27 15:38 |
shef1.exe 842124b4ed12ad2f1bddb4360d69fdbbLazarus Family Generic Malware Themida Packer Anti_VM Malicious Library PE File .NET EXE PE32 VirusTotal Malware Malicious Traffic Check memory Checks debugger buffers extracted unpack itself Checks Bios Detects VMWare Check virtual network interfaces VMware anti-virtualization Tofsee Windows ComputerName Firmware DNS Cryptographic key crashed |
1
|
3 | 1 | 9.8 | M | 40 | ZeroCERT | |||||||||||||||
|