6.2.rlavBKPBEc.exe.56ea8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.9ab080.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.5caa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.2.rlavBKPBEc.exe.562a8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.5ca4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.5caa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.2.rlavBKPBEc.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.5caa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.3.rlavBKPBEc.exe.5ed9a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.5ca4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.5ca4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.2.rlavBKPBEc.exe.5624f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.3.csrss.exe.6559a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.5ca4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.9ab080.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.5ca4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.65540e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.2.rlavBKPBEc.exe.9a56e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.5ca4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.655bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.3.rlavBKPBEc.exe.5ed40e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.9ad2e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.5ca4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.3.csrss.exe.6559a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.5caa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
32.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
31.2.csrss.exe.5700e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
37.2.csrss.exe.9ab080.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.5700e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.2.rlavBKPBEc.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
1.2.rlavBKPBEc.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.2.rlavBKPBEc.exe.5140e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.2.rlavBKPBEc.exe.56e4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.3.rlavBKPBEc.exe.5f99a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.5caa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.3.csrss.exe.6559a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.5caa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.3.rlavBKPBEc.exe.5930000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.5700e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
31.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.5caa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.6559a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.2.rlavBKPBEc.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.3.rlavBKPBEc.exe.5f940e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.2.rlavBKPBEc.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
37.3.csrss.exe.65540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.3.csrss.exe.6559a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.5700e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
37.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.3.rlavBKPBEc.exe.5f9bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.3.rlavBKPBEc.exe.5edbce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
47.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.2.rlavBKPBEc.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
1.2.rlavBKPBEc.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
26.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
32.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
26.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
1.2.rlavBKPBEc.exe.5080e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.5700e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.5700e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
26.2.csrss.exe.5700e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
47.3.csrss.exe.6559a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
1.2.rlavBKPBEc.exe.5080e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
26.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.3.csrss.exe.655bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.2.csrss.exe.9ad2e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
26.2.csrss.exe.5700e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
1.2.rlavBKPBEc.exe.9a56e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.3.csrss.exe.655bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
47.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
47.3.csrss.exe.65540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
32.3.csrss.exe.65540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
31.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.2.rlavBKPBEc.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
26.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
6.2.rlavBKPBEc.exe.5140e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
47.2.csrss.exe.5700e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
31.3.csrss.exe.6559a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
37.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
32.2.csrss.exe.5700e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
37.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.5700e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
37.2.csrss.exe.5700e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
47.2.csrss.exe.5700e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
6.3.rlavBKPBEc.exe.59f0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
32.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
31.2.csrss.exe.5700e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
31.3.csrss.exe.5fb0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
Click to see the 112 entries |