Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
1
2023-10-03 19:49
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
Antivirus
.NET framework(MSIL)
PE File
PE32
.NET EXE
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.6
M
53
guest
2
2023-10-03 19:49
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
Antivirus
.NET framework(MSIL)
PE File
PE32
.NET EXE
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.0
M
53
guest
3
2023-10-03 19:48
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
Antivirus
.NET framework(MSIL)
PE File
PE32
.NET EXE
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.6
M
53
guest
4
2023-10-03 19:47
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
Antivirus
.NET framework(MSIL)
PE File
PE32
.NET EXE
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.0
M
53
guest
5
2023-10-03 19:46
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
Antivirus
.NET framework(MSIL)
PE File
PE32
.NET EXE
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.6
M
53
guest
6
2023-08-08 18:43
UpdateSvc.exe
089428711dddec20eabf7732eea8fb8d
Generic Malware
.NET framework(MSIL)
Antivirus
.NET EXE
PE File
PE32
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
WriteConsoleW
Ransomware
Windows
ComputerName
5.4
M
35
ZeroCERT
First
1
Last
Total : 6cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword