Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
48496 2020-07-20 16:29 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48497 2020-07-20 16:24 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48498 2020-07-20 16:17 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 8 3 4.6

48499 2020-07-20 16:10 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48500 2020-07-20 15:53 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48501 2020-07-20 15:42 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
11 4 5.2

48502 2020-07-20 15:36 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Tofsee Windows Exploit DNS crashed
11 4 3 5.2

48503 2020-07-20 15:26 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
12 5 5.2

48504 2020-07-20 15:22 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48505 2020-07-20 15:14 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit DNS crashed
11 3 4.2

48506 2020-07-20 15:11 https://download.nullsoft.com/...  

3017f921a6c42a267842cc8bae9384c1


VirusTotal Malware AutoRuns suspicious privilege MachineGuid Code Injection Malicious Traffic Check memory Checks debugger buffers extracted Creates shortcut Creates executable files ICMP traffic exploit crash unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk sandbox evasion Firewall state off VM Disk Size Check human activity check installed browsers check Tofsee Ransomware Interception Windows Exploit Browser ComputerName DNS crashed
8 4 2 15.2

48507 2020-07-20 14:41 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting unpack itself Windows utilities malicious URLs Windows
88 21 4.4

48508 2020-07-20 14:33 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48509 2020-07-20 14:27 http://www.nalara1220.o-r.kr/  

c032bb944d6fba21799bd5a4df5b6122


Dridex Malware Code Injection Creates executable files RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Tofsee Windows Exploit DNS crashed
11 3 3 4.6

48510 2020-07-20 14:15 23d3382.hta  

d8c6560478cca57bb84a2c37228c44bf


Browser Info Stealer Malware Code Injection Malicious Traffic Check memory Checks debugger buffers extracted RWX flags setting exploit crash unpack itself Check virtual network interfaces malicious URLs installed browsers check Tofsee Exploit Browser ComputerName DNS crashed
3 2 2 8.8