41.2.csrss.exe.4aaa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.3.csrss.exe.5359a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.3.csrss.exe.53540e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.3.csrss.exe.535bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.3.csrss.exe.5359a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.4aa4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.3.csrss.exe.53540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.3.csrss.exe.535bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.4aaa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.2.csrss.exe.4aa4f30.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.2.csrss.exe.9ab080.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.3.csrss.exe.535bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.3.csrss.exe.5359a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.9a56e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.3.csrss.exe.53540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.4aa4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.3.csrss.exe.53540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
44.2.csrss.exe.4aaa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.9ad2e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.9a56e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.3.csrss.exe.535bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.4aaa8d0.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.4aaa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.3.csrss.exe.535bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.4500e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.3.csrss.exe.53540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.400000.2.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
2.2.csrss.exe.4aa4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.3.csrss.exe.5359a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.2.csrss.exe.4500e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.3.csrss.exe.53540e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.csrss.exe.4aa4f30.9.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.2.csrss.exe.9ad2e0.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.400000.3.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.csrss.exe.4aaa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.4aa4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.4aa4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.400000.3.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
44.2.csrss.exe.4aa4f30.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
44.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.4aaa8d0.11.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
41.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
44.2.csrss.exe.4500e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
44.2.csrss.exe.9a56e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.400000.0.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.4500e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
2.2.csrss.exe.4500e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.csrss.exe.9ad2e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.4500e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.3.csrss.exe.5359a80.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.2.csrss.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
11.3.csrss.exe.535bce0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.4aaa8d0.10.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
27.2.csrss.exe.400000.2.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
44.2.csrss.exe.400000.1.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
41.2.csrss.exe.9ab080.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
11.2.csrss.exe.9ad2e0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
18.2.csrss.exe.4500e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
41.2.csrss.exe.4500e50.10.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.3.csrss.exe.535bce0.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.5359a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.2.csrss.exe.9ab080.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
2.3.csrss.exe.5359a80.3.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.3.csrss.exe.535bce0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.csrss.exe.4500e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.csrss.exe.9ab080.0.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
0.2.csrss.exe.400000.1.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.4500e50.9.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
27.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.3.csrss.exe.5359a80.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3eb18:$s2: The Magic Word!
- 0x4ac58:$s2: The Magic Word!
- 0x3ee78:$s3: Software\Oracle\VirtualBox
- 0x3eb07:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.4500e50.11.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
0.2.csrss.exe.4500e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
2.3.csrss.exe.53540e0.2.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
27.2.csrss.exe.9ad2e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x3c8b8:$s2: The Magic Word!
- 0x489f8:$s2: The Magic Word!
- 0x3cc18:$s3: Software\Oracle\VirtualBox
- 0x3c8a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.53540e0.1.raw.unpack | MAL_ME_RawDisk_Agent_Jan20_2 | Detects suspicious malware using ElRawDisk | Florian Roth | - 0x444b8:$s2: The Magic Word!
- 0x505f8:$s2: The Magic Word!
- 0x44818:$s3: Software\Oracle\VirtualBox
- 0x444a7:$sc1: 00 5C 00 5C 00 2E 00 5C 00 25 00 73
|
19.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
41.2.csrss.exe.400000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
41.2.csrss.exe.4500e50.10.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
41.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
11.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
11.2.csrss.exe.4500e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
27.2.csrss.exe.4500e50.11.raw.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.3.csrss.exe.4db0000.0.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
2.2.csrss.exe.400000.3.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
19.2.csrss.exe.4500e50.9.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
18.2.csrss.exe.400000.3.unpack | JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | |
Click to see the 99 entries |