00000015.00000003.391274838.0000000007C61000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.343016197.00000000040FF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.343016197.00000000040FF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000003.276619656.0000000008226000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000015.00000002.464002231.00000000040BF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.464002231.00000000040BF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.439095104.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.439095104.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.457726338.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.457726338.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000003.280202235.00000000041F9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000011.00000000.336914407.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000000.336914407.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.342398829.0000000004070000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.342398829.0000000004070000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.463441760.0000000004030000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.463441760.0000000004030000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.458487817.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.458487817.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.444831530.00000000037F1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.444831530.00000000037F1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.466534836.0000000007C60000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000015.00000002.466534836.0000000007C60000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen | - 0x5d42a:$s1: file:///
- 0x5d386:$s2: {11111-22222-10009-11112}
- 0x5d3ba:$s3: {11111-22222-50001-00000}
- 0x5a080:$s4: get_Module
- 0x5a19c:$s5: Reverse
- 0x5b89f:$s6: BlockCopy
- 0x5bf21:$s7: ReadByte
- 0x5d43e:$s8: 4C 00 6F 00 63 00 61 00 74 00 69 00 6F 00 6E 00 00 0B 46 00 69 00 6E 00 64 00 20 00 00 13 52 00 65 00 73 00 6F 00 75 00 72 00 63 00 65 00 41 00 00 11 56 00 69 00 72 00 74 00 75 00 61 00 6C 00 ...
|
00000012.00000002.445090863.00000000038CF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.445090863.00000000038CF000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.342152559.0000000004021000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.342152559.0000000004021000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.448199916.00000000074B0000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000012.00000002.448199916.00000000074B0000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen | - 0x5d42a:$s1: file:///
- 0x5d386:$s2: {11111-22222-10009-11112}
- 0x5d3ba:$s3: {11111-22222-50001-00000}
- 0x5a080:$s4: get_Module
- 0x5a19c:$s5: Reverse
- 0x5b89f:$s6: BlockCopy
- 0x5bf21:$s7: ReadByte
- 0x5d43e:$s8: 4C 00 6F 00 63 00 61 00 74 00 69 00 6F 00 6E 00 00 0B 46 00 69 00 6E 00 64 00 20 00 00 13 52 00 65 00 73 00 6F 00 75 00 72 00 63 00 65 00 41 00 00 11 56 00 69 00 72 00 74 00 75 00 61 00 6C 00 ...
|
00000023.00000000.440160932.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.440160932.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000015.00000003.395977770.00000000041B9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000011.00000002.441757056.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000002.441757056.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000023.00000002.461376169.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000002.461376169.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.439743779.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.439743779.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.352376984.0000000008220000.00000004.08000000.00040000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000000.00000002.352376984.0000000008220000.00000004.08000000.00040000.00000000.sdmp | MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen | - 0x5d42a:$s1: file:///
- 0x5d386:$s2: {11111-22222-10009-11112}
- 0x5d3ba:$s3: {11111-22222-50001-00000}
- 0x5a080:$s4: get_Module
- 0x5a19c:$s5: Reverse
- 0x5b89f:$s6: BlockCopy
- 0x5bf21:$s7: ReadByte
- 0x5d43e:$s8: 4C 00 6F 00 63 00 61 00 74 00 69 00 6F 00 6E 00 00 0B 46 00 69 00 6E 00 64 00 20 00 00 13 52 00 65 00 73 00 6F 00 75 00 72 00 63 00 65 00 41 00 00 11 56 00 69 00 72 00 74 00 75 00 61 00 6C 00 ...
|
00000025.00000002.515244386.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000002.515244386.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.461894221.000000000302E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000011.00000000.337477695.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000000.337477695.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000011.00000000.337195399.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000000.337195399.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.463052631.0000000003FE1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000015.00000002.463052631.0000000003FE1000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.444046902.000000000283E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000011.00000000.337854647.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000000.337854647.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.458149795.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.458149795.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.444909008.0000000003840000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000012.00000002.444909008.0000000003840000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.459235290.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000000.459235290.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.438645429.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000000.438645429.0000000000402000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_AgentTesla_2 | Yara detected AgentTesla | Joe Security | |
00000000.00000002.341099204.000000000306E000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000012.00000003.369603767.00000000074B9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000012.00000003.374621966.00000000039C9000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
00000011.00000002.442994108.0000000003111000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000011.00000002.442994108.0000000003111000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
00000011.00000002.442994108.0000000003111000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000025.00000002.517983992.0000000002A31000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000025.00000002.517983992.0000000002A31000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
00000025.00000002.517983992.0000000002A31000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
00000023.00000002.462835712.0000000002F41000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
00000023.00000002.462835712.0000000002F41000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
00000023.00000002.462835712.0000000002F41000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Process Memory Space: love.exe PID: 6232 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: love.exe PID: 6232 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 4528 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 4528 | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 4528 | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Process Memory Space: Grjwvl.exe PID: 6984 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: Grjwvl.exe PID: 6984 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: Grjwvl.exe PID: 5632 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: Grjwvl.exe PID: 5632 | JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 5096 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 5096 | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 5096 | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 1296 | JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 1296 | JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | |
Process Memory Space: InstallUtil.exe PID: 1296 | JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | |
Click to see the 82 entries |