Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1306 2020-08-03 09:19 http://www.nalara1220.o-r.kr  

c032bb944d6fba21799bd5a4df5b6122


Code Injection Creates executable files unpack itself Windows utilities malicious URLs Windows DNS
6 2 3.6

1307 2020-08-03 09:44 node-v12.18.0-x64.msi  

e3f6617be3157b28ffee007e5d2790d2


Buffer PE suspicious privilege Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs AntiVM_Disk VM Disk Size Check ComputerName DNS
2 1 5.0

1308 2020-08-03 14:02 .dbshell  

7b7030422b5d86e33b3b8a994aa029d1


Email Client Info Stealer suspicious privilege Check memory Checks debugger Creates shortcut unpack itself malicious URLs AntiVM_Disk VM Disk Size Check human activity check installed browsers check Browser Email ComputerName DNS
2 1 5.8

1309 2020-08-03 14:21 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1310 2020-08-03 15:11 node-v12.18.0-x64.msi  

e3f6617be3157b28ffee007e5d2790d2


Buffer PE suspicious privilege Check memory Checks debugger buffers extracted unpack itself Check virtual network interfaces malicious URLs AntiVM_Disk VM Disk Size Check ComputerName DNS
2 1 5.0

1311 2020-08-03 15:13 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit crashed
1 4 3.6

1312 2020-08-03 15:29 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities malicious URLs Windows
2.2

1313 2020-08-03 15:37 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities malicious URLs Windows
2.2

1314 2020-08-03 15:43 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities malicious URLs Windows
2.2

1315 2020-08-03 15:47 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting exploit crash unpack itself Windows utilities Windows Exploit crashed
1 4 3.2

1316 2020-08-03 15:51 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting unpack itself Windows utilities Windows
1 2.2

1317 2020-08-03 15:51 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1318 2020-08-03 15:59 http://www.nalara12200.o-r.kr  


Malware Code Injection Malicious Traffic unpack itself Windows utilities malicious URLs Windows DNS
1 1 4.0

1319 2020-08-03 16:01 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting exploit crash unpack itself Windows utilities malicious URLs Windows Exploit crashed
1 4 3.6

1320 2020-08-03 16:10 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8