No | Date | Request | Urls | Hosts | IDS | Rule | Score | Zero | VT | Player | Etc | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 2021-08-18 12:06 |
Proformar invioce.exe a311cef429085f54e95b32fd836c56b6AgentTesla RAT browser info stealer Generic Malware Google Chrome User Data Admin Tool (Sysinternals etc ...) Socket Sniff Audio Escalate priviledges KeyLogger Code injection Internet API Downloader persistence DGA DNS Create Service HTTP FTP ScreenShot H VirusTotal Malware Buffer PE AutoRuns suspicious privilege Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows utilities WriteConsoleW Windows Cryptographic key |
11.0 | 26 | ZeroCERT | |||||||||||||||||||
|