Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1321 2020-08-03 16:12 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1322 2020-08-03 16:16 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1323 2020-08-03 16:23 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities malicious URLs Windows
2.2

1324 2020-08-03 16:26 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1325 2020-08-03 16:26 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting unpack itself Windows utilities Windows
1 2.2

1326 2020-08-03 16:29 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1327 2020-08-03 16:29 .ICEauthority  

6b2b5093099a571f41b44ba1cc2beaa4


Email Client Info Stealer suspicious privilege Checks debugger Creates shortcut unpack itself malicious URLs human activity check installed browsers check Browser Email ComputerName crashed
4.4

1328 2020-08-03 16:34 .ICEauthority  

6b2b5093099a571f41b44ba1cc2beaa4


Email Client Info Stealer suspicious privilege Check memory Checks debugger Creates shortcut unpack itself malicious URLs AntiVM_Disk VM Disk Size Check human activity check installed browsers check Browser Email ComputerName DNS
2 1 6.2

1329 2020-08-03 16:39 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1330 2020-08-03 16:39 invoiceAEWU447057001.doc  

9dc6c15bd5cadbea76473ca0a61270d0


Vulnerability VirusTotal Malware unpack itself
2.8 M 37

1331 2020-08-03 16:41 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1332 2020-08-03 16:43 http://www.nalara12200.o-r.kr  


Code Injection RWX flags setting unpack itself Windows utilities Windows
2.2

1333 2020-08-03 16:49 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1334 2020-08-03 16:50 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities Windows
1.8

1335 2020-08-03 16:53 http://www.nalara12200.o-r.kr  


Code Injection unpack itself Windows utilities malicious URLs Windows
2.2