Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
2086
2025-02-18 17:47
bug_report.md
22deaa2a857a964e2d6009a8daad2e19
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2087
2025-02-18 17:47
random.exe
454d208cdba1e652722f6e612fc51339
Themida
Admin Tool (Sysinternals etc ...)
UPX
PE File
PE32
VirusTotal
Malware
Checks debugger
unpack itself
Checks Bios
Detects VMWare
VMware
anti-virtualization
Windows
crashed
5.4
M
40
ZeroCERT
2088
2025-02-18 17:46
feature_request.md
4bbb0812310331153f28c0e0eebba33c
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2089
2025-02-18 17:46
YouTubeToMP3-x64.exe
fce58eddcf4fc7ea19691e27dff9b1d0
Gen1
RedLine stealer
Generic Malware
Downloader
Malicious Library
UPX
Obsidium protector
Malicious Packer
Anti_VM
PE File
ftp
PE32
OS Processor Check
MZP Format
DLL
PE64
PNG Format
HWP
MSOffice File
URL Format
GIF Format
Lnk Format
Malware
Malicious Traffic
Check memory
Checks debugger
Creates shortcut
Creates executable files
RWX flags setting
unpack itself
AppData folder
AntiVM_Disk
VM Disk Size Check
Ransomware
ComputerName
1
Keyword trend analysis
×
Info
×
http://www.google-analytics.com/collect
3
Info
×
www.google-analytics.com(172.217.25.174)
142.251.222.46
172.217.161.78 - phishing
6.6
guest
2090
2025-02-18 17:45
bug_report.md
22deaa2a857a964e2d6009a8daad2e19
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
4.6
guest
2091
2025-02-18 17:45
feature_request.md
4bbb0812310331153f28c0e0eebba33c
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2092
2025-02-18 17:44
feature_request.md
4bbb0812310331153f28c0e0eebba33c
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2093
2025-02-18 17:44
bug_report.md
22deaa2a857a964e2d6009a8daad2e19
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2094
2025-02-18 17:44
bug_report.md
22deaa2a857a964e2d6009a8daad2e19
Downloader
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Hijack Network
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
MSOffice File
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
DNS
1
Info
×
152.199.39.108 - mailcious
5.2
guest
2095
2025-02-18 17:43
dlaos.exe
454202e31bcf6ecb61ba74a4fd450b5e
Malicious Library
UPX
Javascript_Blob
PE File
PE32
MZP Format
PNG Format
ZIP Format
Browser Info Stealer
VirusTotal
Malware
Check memory
buffers extracted
Creates executable files
unpack itself
sandbox evasion
Browser
ComputerName
DNS
1
Info
×
185.143.228.176 - mailcious
5.8
M
41
ZeroCERT
2096
2025-02-18 17:43
extension_dropper.exe
b4c1cb38678259fbbce4f5a1fbb3043a
Generic Malware
Malicious Library
UPX
Javascript_Blob
PE File
PE32
OS Processor Check
PNG Format
ZIP Format
Browser Info Stealer
VirusTotal
Malware
Check memory
Creates executable files
unpack itself
Browser
ComputerName
RCE
3.6
M
49
ZeroCERT
2097
2025-02-18 17:43
KbSwZup.exe
c30852886cb5a9c1f956d738a355ed8c
Themida
UPX
Anti_VM
PE File
PE32
VirusTotal
Malware
Checks debugger
unpack itself
Checks Bios
Detects VMWare
VMware
anti-virtualization
Windows
crashed
5.4
M
59
ZeroCERT
2098
2025-02-18 17:43
profile-0f547b7082aba8ffbe7e2d...
2307599139ab91a62a92e09797b45eb9
AntiDebug
AntiVM
Email Client Info Stealer
suspicious privilege
Checks debugger
Creates shortcut
unpack itself
installed browsers check
Browser
Email
ComputerName
3.4
guest
2099
2025-02-18 17:43
profile-0f547b7082aba8ffbe7e2d...
2307599139ab91a62a92e09797b45eb9
AntiDebug
AntiVM
Email Client Info Stealer
suspicious privilege
Checks debugger
Creates shortcut
unpack itself
installed browsers check
Browser
Email
ComputerName
3.4
guest
2100
2025-02-18 17:41
update.exe
0c1d951bd8edb3b7ee31d34c543c3db3
Generic Malware
Malicious Library
UPX
PE File
PE32
DllRegisterServer
dll
DLL
OS Processor Check
Check memory
Checks debugger
Creates executable files
unpack itself
AppData folder
2.4
guest
First
Previous
131
132
133
134
135
136
137
138
139
140
Next
Last
Total : 53,462cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword