Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
1
2024-07-31 14:55
23.exe
367009ea6fe948f4c0773f4cd1274a5f
Admin Tool (Sysinternals etc ...)
UPX
AntiDebug
AntiVM
PE File
PE32
Malware download
AsyncRAT
NetWireRC
VirusTotal
Malware
Cryptocurrency wallets
Cryptocurrency
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
WMI
RWX flags setting
unpack itself
Ransomware
Windows
ComputerName
DNS
Cryptographic key
2
Keyword trend analysis
×
Info
×
http://poslisoubor.cz/gf.php?33f6c54a9a525e2c37453931c2aadebe/9.txt - rule_id: 41656
http://poslisoubor.cz/gf.php?33f6c54a9a525e2c37453931c2aadebe/9.txt
3
Info
×
poslisoubor.cz(109.71.208.62)
109.71.208.62
41.216.183.3 - mailcious
5
Info
×
ET DROP Spamhaus DROP Listed Traffic Inbound group 3
SURICATA TLS invalid record type
SURICATA TLS invalid record/traffic
SURICATA Applayer Detect protocol only one direction
ET MALWARE Generic AsyncRAT Style SSL Cert
1
Info
×
http://poslisoubor.cz/gf.php?33f6c54a9a525e2c37453931c2aadebe/9.txt
12.4
M
30
ZeroCERT
2
2024-03-27 07:52
sleep.exe
142b6a00a17c3f7853f4cfeebfe72c13
Admin Tool (Sysinternals etc ...)
UPX
PE File
PE32
VirusTotal
Malware
AutoRuns
Check memory
Creates executable files
RWX flags setting
unpack itself
AppData folder
Windows
Remote Code Execution
crashed
4.0
M
57
ZeroCERT
3
2024-01-11 07:36
santa.exe
42d990690985f79c5f131af8cb5f9fdb
Admin Tool (Sysinternals etc ...)
UPX
PE32
PE File
VirusTotal
Malware
WMI
RWX flags setting
ComputerName
Remote Code Execution
crashed
3.0
53
ZeroCERT
4
2023-11-09 10:20
Challan.exe
816cdd0d2e0852404804a683d1cd1b53
UPX
Admin Tool (Sysinternals etc ...)
PE File
PE32
VirusTotal
Malware
Check memory
RWX flags setting
unpack itself
suspicious process
ComputerName
Remote Code Execution
crashed
3.6
48
ZeroCERT
5
2023-09-23 09:34
LB3.exe
0c2246bc569ddf7c9e93ccbf87aeb397
Generic Malware
Admin Tool (Sysinternals etc ...)
UPX
PE File
PE32
VirusTotal
Malware
Remote Code Execution
1.8
51
ZeroCERT
6
2023-08-16 07:52
addo.exe
6730aa28aed92b39ba1a23d43c45399a
AgentTesla
Generic Malware
UPX
Admin Tool (Sysinternals etc ...)
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
PE32
Browser Info Stealer
Email Client Info Stealer
Buffer PE
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
RWX flags setting
unpack itself
Check virtual network interfaces
IP Check
Windows
Browser
Email
ComputerName
crashed
2
Info
×
api.ipify.org(173.231.16.76)
64.185.227.156
9.8
ZeroCERT
7
2023-06-14 16:02
hh.exe
49e5db7cd2169dfc4d0e2011beccf2a0
Generic Malware
UPX
Malicious Library
Malicious Packer
Admin Tool (Sysinternals etc ...)
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
crashed
2.2
M
50
r0d
8
2023-06-14 16:01
hh.exe
49e5db7cd2169dfc4d0e2011beccf2a0
Generic Malware
UPX
Malicious Library
Malicious Packer
Admin Tool (Sysinternals etc ...)
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
crashed
2.2
M
50
r0d
9
2023-06-14 09:49
zapo.exe
eebc680d6a397eb6c40f449d6a13bf6f
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
Remote Code Execution
2.4
M
36
ZeroCERT
10
2023-06-14 09:48
hard.exe
7bc8c2521bcfbff7e6b904e2ca3edd15
Generic Malware
UPX
Antivirus
PE File
PE32
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
RWX flags setting
unpack itself
Windows utilities
powershell.exe wrote
suspicious process
Windows
ComputerName
Cryptographic key
crashed
5.6
M
34
ZeroCERT
11
2023-06-14 09:46
test12.exe
b0b642d21e471002fe600e813ee8a5e4
UPX
PE File
PE32
VirusTotal
Malware
AutoRuns
RWX flags setting
Windows
crashed
2.2
M
36
ZeroCERT
12
2023-06-14 09:46
hh.exe
49e5db7cd2169dfc4d0e2011beccf2a0
UPX
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
crashed
2.2
M
47
ZeroCERT
13
2023-06-14 09:44
nai.exe
4a28daa7b3ea61ede54d0038bb7d4c10
UPX
PE File
PE32
VirusTotal
Malware
RWX flags setting
crashed
1.4
M
25
ZeroCERT
14
2023-06-14 09:43
maikati.exe
da9ff05785b6d6ce84e38275f92818d0
Malicious Library
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
1.6
M
27
ZeroCERT
15
2023-06-14 09:42
remcvos.exe
49954bffc9fed256663cf3b7d19eefe4
UPX
PE File
PE32
VirusTotal
Malware
RWX flags setting
crashed
1.6
M
35
ZeroCERT
First
1
2
3
4
5
6
7
8
9
10
Next
Last
Total : 165cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword