0.2.4t4y4r89UZ.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.3.csrss.exe.65540e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.2.4t4y4r89UZ.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.2.csrss.exe.5ca4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.4t4y4r89UZ.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.3.4t4y4r89UZ.exe.5e2bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.3.csrss.exe.655bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.4t4y4r89UZ.exe.55e4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.2.csrss.exe.9ad2e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.5caa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.3.4t4y4r89UZ.exe.5e99a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.5ca4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.3.4t4y4r89UZ.exe.5e29a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.5caa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.3.csrss.exe.6559a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.9ab080.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.3.4t4y4r89UZ.exe.5e240e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.2.csrss.exe.5ca4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.2.4t4y4r89UZ.exe.5574f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.3.csrss.exe.655bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.3.csrss.exe.655bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.9ad2e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.3.csrss.exe.6559a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
10.2.4t4y4r89UZ.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.5ca4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.2.csrss.exe.400000.3.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
10.2.4t4y4r89UZ.exe.4fd0e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.3.csrss.exe.65540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.2.csrss.exe.5700e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
10.2.4t4y4r89UZ.exe.557a8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
42.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.5700e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.2.csrss.exe.5700e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
10.2.4t4y4r89UZ.exe.4fd0e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.2.csrss.exe.5caa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.3.4t4y4r89UZ.exe.5e9bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
50.2.csrss.exe.5caa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.2.csrss.exe.5700e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.3.4t4y4r89UZ.exe.5e940e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.2.4t4y4r89UZ.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
42.2.csrss.exe.5700e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.4t4y4r89UZ.exe.400000.3.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
16.3.csrss.exe.6559a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.5700e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
50.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.5ca4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.2.csrss.exe.400000.3.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.3.csrss.exe.6559a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
10.2.4t4y4r89UZ.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.4t4y4r89UZ.exe.55ea8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
16.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
23.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.4t4y4r89UZ.exe.400000.3.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
23.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.5700e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
50.2.csrss.exe.5700e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
42.3.csrss.exe.6559a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
14.2.csrss.exe.5ca4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
42.2.csrss.exe.5700e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.4t4y4r89UZ.exe.5040e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
50.3.csrss.exe.6559a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.5caa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.5700e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
34.3.csrss.exe.65540e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.2.csrss.exe.9ab080.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
23.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.2.csrss.exe.5caa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.3.4t4y4r89UZ.exe.5880000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.3.csrss.exe.65540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
34.3.csrss.exe.655bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.4t4y4r89UZ.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
10.2.4t4y4r89UZ.exe.9ab080.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
50.3.csrss.exe.655bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
16.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
23.2.csrss.exe.5700e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.4t4y4r89UZ.exe.5040e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
42.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
50.2.csrss.exe.5700e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.3.4t4y4r89UZ.exe.58f0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
14.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
42.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
Click to see the 99 entries |