Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1066 2020-07-28 14:16 UniSignCRSV3Setup.exe  

3bc8fa98ea99c1d05756ab42799a8ba0


VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files unpack itself Checks Bios Detects VirtualBox Detects VMWare AppData folder malicious URLs AntiVM_Disk sandbox evasion VMware anti-virtualization VM Disk Size Check Windows ComputerName crashed
10.4 5

1067 2020-07-28 14:18 TouchEn_nxKey_32bit.exe  

38e9393d6d801a71019d0bac4d77da4a


AutoRuns suspicious privilege Code Injection Check memory Creates executable files unpack itself Windows utilities Auto service AppData folder malicious URLs sandbox evasion Windows Remote Code Execution
8.8

1068 2020-07-28 14:28 TouchEn_nxKey_32bit.exe  

38e9393d6d801a71019d0bac4d77da4a


VirusTotal Malware AutoRuns suspicious privilege Code Injection Check memory Creates executable files unpack itself Windows utilities Auto service AppData folder malicious URLs sandbox evasion Windows Remote Code Execution
9.2 2

1069 2020-07-28 14:28 UniSignCRSV3Setup.exe  

3bc8fa98ea99c1d05756ab42799a8ba0


Check memory Creates executable files unpack itself AntiVM_Disk VM Disk Size Check ComputerName
2.8

1070 2020-07-28 15:02 UniSignCRSV3Setup.exe  

3bc8fa98ea99c1d05756ab42799a8ba0


VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files unpack itself Checks Bios Detects VirtualBox Detects VMWare AppData folder malicious URLs AntiVM_Disk sandbox evasion VMware anti-virtualization VM Disk Size Check Windows ComputerName crashed
10.4 5

1071 2020-07-28 15:03 python-2.7.18.amd64.msi  

a425c758d38f8e28b56f4724b499239a


suspicious privilege Check memory Checks debugger Creates shortcut unpack itself AntiVM_Disk VM Disk Size Check Ransomware ComputerName
2.8

1072 2020-07-28 15:10 python-2.7.18.amd64.msi  

a425c758d38f8e28b56f4724b499239a


suspicious privilege MachineGuid Check memory Checks debugger Creates shortcut unpack itself malicious URLs AntiVM_Disk VM Disk Size Check human activity check installed browsers check Ransomware Browser ComputerName
4.4

1073 2020-07-28 15:11 UniSignCRSV3Setup.exe  

3bc8fa98ea99c1d05756ab42799a8ba0


VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files unpack itself Checks Bios Detects VirtualBox Detects VMWare AppData folder malicious URLs AntiVM_Disk sandbox evasion VMware anti-virtualization VM Disk Size Check Windows ComputerName crashed
10.4 5

1074 2020-07-28 15:14 astx_setup.exe  

e766db22a97ac40e4e8c926f272250ab


VirusTotal Malware AutoRuns Check memory Checks debugger Creates executable files unpack itself Windows utilities AppData folder malicious URLs AntiVM_Disk sandbox evasion WriteConsoleW Firewall state off VM Disk Size Check Ransomware Windows ComputerName
8.2 1

1075 2020-07-28 15:22 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting unpack itself Windows utilities Windows DNS
6 2 3.6

1076 2020-07-28 16:15 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files unpack itself Windows utilities Windows DNS
6 2 3.2

1077 2020-07-28 16:22 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting unpack itself Windows utilities Windows DNS
6 2 3.6

1078 2020-07-28 16:25 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files unpack itself Windows utilities Windows DNS
6 2 3.2

1079 2020-07-28 16:29 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files unpack itself Windows utilities Windows DNS
6 2 3.2

1080 2020-07-28 16:32 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files RWX flags setting unpack itself Windows utilities Windows
6 4 3.0