Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
1801
2025-02-27 10:29
vgetbackthegreatchococlateicre...
d811656da0b305d188ff88875e396173
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
Malicious Traffic
buffers extracted
exploit crash
unpack itself
Exploit
DNS
crashed
3
Keyword trend analysis
×
Info
×
http://67.217.247.193/712/wnc/new_image.jpg
http://217.154.84.12/909/cream/getbackthegreatchococlateicream.hta
http://217.154.84.12/909/getbackthegreatchococlateicream.gIF
2
Info
×
217.154.84.12 -
67.217.247.193 -
5.0
M
36
ZeroCERT
1802
2025-02-27 09:40
nicegirlsheisagoodgirlforevery...
428f467bcc5858d19804cbd26b6ed599
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
Malicious Traffic
buffers extracted
exploit crash
unpack itself
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://194.164.127.111/606/susi/nicegirlsheisagoodgirlforeverytimenicegirlshe.hta
2
Info
×
194.164.127.111 - malware
67.217.247.193 - mailcious
5.0
M
34
ZeroCERT
1803
2025-02-27 09:40
6NPpGdC.exe
75728febe161947937f82f0f36ad99f8
ScreenShot
AntiDebug
AntiVM
PE File
.NET EXE
PE32
VirusTotal
Malware
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
crashed
7.4
M
33
ZeroCERT
1804
2025-02-27 09:30
tOOifSdzE7c9dXR.scr
4312fbdb32f292a78413e7bacb2ca15b
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
PDB
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
DDNS
Software
crashed
2
Keyword trend analysis
×
Info
×
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/121.133.128.1
6
Info
×
api.telegram.org(149.154.167.220)
reallyfreegeoip.org(104.21.16.1)
checkip.dyndns.org(193.122.6.168)
158.101.44.242
104.21.64.1 - mailcious
149.154.167.220
15.2
M
56
ZeroCERT
1805
2025-02-27 09:28
4KKi8Zrv9nyAmhR.exe
f4ec22c70471ac39a3622273716f1186
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
PDB
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
DDNS
Software
crashed
2
Keyword trend analysis
×
Info
×
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/121.133.128.1
6
Info
×
api.telegram.org(149.154.167.220) -
reallyfreegeoip.org(104.21.48.1) -
checkip.dyndns.org(132.226.247.73) -
132.226.8.169 -
104.21.48.1 -
149.154.167.220 -
15.2
M
48
ZeroCERT
1806
2025-02-27 09:27
flowersgoodforseetheviewnicefo...
3111c2e791cd71ee989c47e3713771f6
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
Malicious Traffic
buffers extracted
exploit crash
unpack itself
Exploit
DNS
crashed
3
Keyword trend analysis
×
Info
×
http://67.217.247.193/712/wnc/new_image.jpg
http://217.154.84.12/341/flowersgoodforseetheviewniceforgirls.gIF
http://217.154.84.12/341/seena/flowersgoodforseetheviewniceforgirlsflowers.hta
3
Info
×
104.21.16.1 -
217.154.84.12 -
67.217.247.193 -
5.0
34
ZeroCERT
1807
2025-02-27 09:26
osfile01.exe
5a96793424a2719352dacb473cf30119
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
powershell
suspicious privilege
MachineGuid
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
Windows utilities
powershell.exe wrote
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
DDNS
Software
crashed
2
Keyword trend analysis
×
Info
×
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/121.133.128.1
4
Info
×
reallyfreegeoip.org(104.21.112.1)
checkip.dyndns.org(193.122.130.0)
158.101.44.242
104.21.32.1 - mailcious
15.0
M
51
ZeroCERT
1808
2025-02-27 09:25
setup1217.msi
b38984b30e2a2f00d79e3471300b3f2b
Generic Malware
Malicious Library
MSOffice File
CAB
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
AntiVM_Disk
VM Disk Size Check
ComputerName
2
Keyword trend analysis
×
Info
×
http://ocaowyumocioiqqm.xyz:443/api/client_hello
http://ocaowyumocioiqqm.xyz:443/avast_update
2
Info
×
ocaowyumocioiqqm.xyz(31.192.232.23)
31.192.232.23
2.4
12
ZeroCERT
1809
2025-02-27 09:23
jKuil2m4oIniPNC.exe
f61bc92e52d3fc1d7eb4b82fbc54bdd5
Malicious Library
.NET framework(MSIL)
PE File
.NET EXE
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
2.4
48
ZeroCERT
1810
2025-02-27 09:23
seemybestgirlfriendeverseensmi...
fe1d1d081fdd49de785049f4c94944b5
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
buffers extracted
RWX flags setting
exploit crash
Exploit
crashed
3.6
35
ZeroCERT
1811
2025-02-27 09:23
cryptedprosp.exe
0cf95a046681822e11ceac015721f1e5
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
powershell
PDB
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
powershell.exe wrote
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
DDNS
Software
crashed
2
Keyword trend analysis
×
Info
×
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/121.133.128.1
6
Info
×
checkip.dyndns.org(193.122.6.168) -
reallyfreegeoip.org(104.21.112.1) -
api.telegram.org(149.154.167.220) -
104.21.16.1 - malware
158.101.44.242
149.154.167.220
15.8
55
ZeroCERT
1812
2025-02-27 09:22
coinbase.exe
5f41899fe8f7801b20885898e0f4c05a
Gen1
Generic Malware
Malicious Library
UPX
Malicious Packer
Antivirus
ASPack
PE File
PE32
MZP Format
DllRegisterServer
dll
OS Processor Check
PE64
DLL
VirusTotal
Malware
Checks debugger
Creates executable files
unpack itself
suspicious process
AppData folder
ComputerName
crashed
4.0
22
ZeroCERT
1813
2025-02-27 00:33
4KKi8Zrv9nyAmhR.exe
f4ec22c70471ac39a3622273716f1186
Generic Malware
Malicious Library
.NET framework(MSIL)
Antivirus
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
.NET EXE
PE32
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
powershell
PDB
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
powershell.exe wrote
Check virtual network interfaces
suspicious process
WriteConsoleW
IP Check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
DDNS
Software
crashed
2
Keyword trend analysis
×
Info
×
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/121.133.128.1
6
Info
×
checkip.dyndns.org(158.101.44.242)
reallyfreegeoip.org(104.21.64.1)
api.telegram.org(149.154.167.220)
104.21.96.1 - mailcious
132.226.247.73
149.154.167.220
15.2
53
guest
1814
2025-02-26 14:50
q3na5Mc.exe
4871c39a4a7c16a4547820b8c749a32c
Client SW User Data Stealer
LokiBot
ftp Client
info stealer
Socket
Http API
ScreenShot
PWS
HTTP
DNS
Internet API
AntiDebug
AntiVM
PE File
.NET EXE
PE32
VirusTotal
Malware
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
unpack itself
malicious URLs
ComputerName
DNS
crashed
2
Keyword trend analysis
×
Info
×
https://steamcommunity.com/profiles/76561199829660832
https://t.me/l793oy
5
Info
×
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious
149.154.167.99 - mailcious
23.49.154.73 - mailcious
159.69.100.232
10.8
M
45
ZeroCERT
1815
2025-02-26 10:24
Metin2Release.exe
5d155e2650319956e20fb581e6542f3a
Hide_EXE
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
PDB
1.2
1
guest
First
Previous
121
122
123
124
125
126
127
128
129
130
Next
Last
Total : 53,366cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword