Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1http 5 ▲ 1 (20%)
2Kimsuky 1 ▲ new
3DPRK 1 ▲ new
4vstAdphpnewpacomlineampwpnaaa 1 ▲ new
5North Korea 1 ▲ new
6Related 1 ▲ new
7PaloNetworkFilesJL 1 ▲ new
8httpstcoTpRg 1 ▲ new
9same 1 ▲ new
10error 1 ▲ new
11Next 1 - 0 (0%)
12stage 1 - 0 (0%)
13archive 1 ▲ new
14Password 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


No data.

Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
Kimsuky
1 (100%)
Attack technique
Technique

This is an attack technique that is becoming an issue.


No data.

Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
DPRK
1 (50%)
North Korea
1 (50%)

Additional information

No Title Date
128th April – Threat Intelligence Report - Malware.News2025.04.28
2Navigating Through The Fog - Malware.News2025.04.28
3Huawei Set to Test Powerful AI Chip to Rival Nvidia’s, WSJ Says - Bloomberg Technology2025.04.28
4Gamers Beware! New Attack Targets Gamers to Deploy AgeoStealer Malware - Malware.News2025.04.26
5Threat Hunting: For what, when, and how? - Malware.News2025.04.26
View only the last 5
No Title Date
1HTTP/3 is everywhere but nowhere - Malware.News2025.03.13
2HTTP/3 is everywhere but nowhere - Malware.News2025.03.13
3HTTP/3 is everywhere but nowhere - Malware.News2025.03.13
4HTTP/3 is everywhere but nowhere - Malware.News2025.03.13
5HTTP/3 is everywhere but nowhere - Malware.News2025.03.13
View only the last 5
Level Description
danger File has been identified by 33 AntiVirus engines on VirusTotal as malicious
watch Attempts to stop active services
watch Creates known SpyNet files
watch Resumed a suspended thread in a remote process potentially indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Drops a binary and executes it
notice Drops an executable to the user AppData folder
notice Executes one or more WMI queries
notice The binary likely contains encrypted or compressed data indicative of a packer
notice Uses Windows utilities for basic Windows functionality
notice Yara rule detected in process memory
info Checks amount of memory in system
info Command line console output was observed
info One or more processes crashed
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
No data
No data
Beta Service, If you select keyword, you can check detailed information.