No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2022-01-24 09:42 |
4603_1642883315_6505.exe 5105deed61232bfe4bc8fa9f710202a0RAT Generic Malware UPX Antivirus Malicious Packer TEST VMProtect PE File PE32 .NET EXE PE64 Browser Info Stealer FTP Client Info Stealer VirusTotal Malware powershell AutoRuns suspicious privilege MachineGuid Malicious Traffic Check memory Checks debugger buffers extracted WMI Creates shortcut Creates executable files RWX flags setting unpack itself Windows utilities Collect installed applications powershell.exe wrote Check virtual network interfaces suspicious process sandbox evasion installed browsers check Tofsee Windows Browser ComputerName RCE DNS Cryptographic key Software crashed |
2
|
5 | 1 | 16.8 | M | 21 | ZeroCERT | |||||||||||||||
|