Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
22831
2022-12-20 18:27
product.doc
47c1af8dc03fcf167b2e2909fa0fecd6
RTF File
doc
VirusTotal
Malware
exploit crash
Exploit
DNS
crashed
1
Info
×
208.67.105.179 - malware
4.0
14
Dr
22832
2022-12-20 18:27
navegador_do_arquivo.html
45d27aa9152120a7a42b13fa72aafb76
NPKI
crashed
0.2
Dr
22833
2022-12-20 18:24
original-2.ndjson
a9e581f18b190d241cf52701f8f6b69a
Generic Malware
AntiDebug
AntiVM
Email Client Info Stealer
suspicious privilege
Checks debugger
Creates shortcut
unpack itself
installed browsers check
Browser
Email
ComputerName
3.4
guest
22834
2022-12-20 18:23
whatis.html
8391144259d7e8600cc01618e78a15c3
AntiDebug
AntiVM
PNG Format
JPEG Format
MSOffice File
Code Injection
RWX flags setting
exploit crash
unpack itself
Windows utilities
Windows
Exploit
DNS
crashed
3.8
guest
22835
2022-12-20 18:13
whatis.html
8391144259d7e8600cc01618e78a15c3
AntiDebug
AntiVM
PNG Format
MSOffice File
JPEG Format
Code Injection
RWX flags setting
exploit crash
unpack itself
Windows utilities
Tofsee
Windows
Exploit
DNS
crashed
2
Info
×
ET INFO TLS Handshake Failure
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
3.8
guest
22836
2022-12-20 18:13
navegador_do_arquivo.html
45d27aa9152120a7a42b13fa72aafb76
NPKI
crashed
0.2
Dr
22837
2022-12-20 18:12
about-physical-networks.html
1d62ca2190ec1a492ab345316bc73236
Anti_VM
AntiDebug
AntiVM
PNG Format
MSOffice File
JPEG Format
Code Injection
RWX flags setting
exploit crash
unpack itself
Windows utilities
Windows
Exploit
DNS
crashed
3.8
guest
22838
2022-12-20 16:49
PO-220804.doc
0d39ab326800c93da1a84bc4c69b39f8
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
buffers extracted
exploit crash
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://208.67.105.148/wealthx.exe
1
Info
×
208.67.105.148 - mailcious
4.4
35
ZeroCERT
22839
2022-12-20 16:47
product.doc
47c1af8dc03fcf167b2e2909fa0fecd6
RTF File
doc
VirusTotal
Malware
exploit crash
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://208.67.105.179/arinzezx.exe
1
Info
×
208.67.105.179 - malware
4.0
14
ZeroCERT
22840
2022-12-20 16:23
https://www.visible.com/accoun...
aa5a7c858535b9e0d36cfe3e66077f24
PWS[m]
Downloader
Create Service
DGA
Socket
ScreenShot
DNS
Internet API
Code injection
Hijack Network
Sniff Audio
HTTP
Steal credential
KeyLogger
P2P
Escalate priviledges
persistence
FTP
Http API
AntiDebug
AntiVM
PNG Format
MSOffice File
JPEG Format
VirusTotal
Malware
Code Injection
RWX flags setting
exploit crash
unpack itself
Windows utilities
malicious URLs
Tofsee
Windows
Exploit
DNS
crashed
2
Info
×
www.visible.com(35.190.57.191)
35.190.57.191
2
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO TLS Handshake Failure
4.6
guest
22841
2022-12-20 14:37
neojik.exe
bc857ecb5e0ad328a5dac42119f9209a
Malicious Library
UPX
PE32
PE File
OS Processor Check
Malware download
AveMaria
NetWireRC
VirusTotal
Malware
AutoRuns
MachineGuid
Check memory
Creates executable files
unpack itself
AppData folder
Windows
RAT
ComputerName
DNS
DDNS
keylogger
2
Info
×
dezember22.duckdns.org(212.86.115.220)
212.86.115.220 -
3
Info
×
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin (Inbound)
ET MALWARE Ave Maria/Warzone RAT Encrypted CnC Checkin
5.2
M
14
ZeroCERT
22842
2022-12-20 14:34
wopngduxgf.exe
dc017def056e0c20105a4d767541a580
PWS[m]
RAT
email
stealer
Downloader
UPX
DNS
Code injection
KeyLogger
Escalate priviledges
persistence
AntiDebug
AntiVM
PE32
.NET EXE
PE File
VirusTotal
Malware
AutoRuns
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
Windows
8.2
M
38
ZeroCERT
22843
2022-12-20 14:33
ladia.exe
f5399e9a1250cd605e255fdad3403457
Malicious Library
UPX
PE32
OS Processor Check
PE File
PDB
unpack itself
RCE
1.2
ZeroCERT
22844
2022-12-20 14:32
j.jpg.ps1
97817d0d04e4a937009187a101a1962d
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.6
10
ZeroCERT
22845
2022-12-20 14:06
alakim.exe
aabb09c3690d466afdfbbaeb791a8bc8
Malicious Library
UPX
PE32
PE File
FormBook
Malware download
VirusTotal
Malware
suspicious privilege
Malicious Traffic
Check memory
Creates executable files
unpack itself
1
Keyword trend analysis
×
Info
×
http://www.hijrahfwd.com/8rmt/?GVoxs=aO6o73ml0LOUhLgaY0qggU8a8dAyqmwgtzDB+vBDlWO/5GdJLRYMNvwevV6n/QAmN+rOPz0V&5jr=UlSp
4
Info
×
www.247repairs.info()
www.rio727casino.com()
www.hijrahfwd.com(2.57.90.16)
2.57.90.16 - mailcious
1
Info
×
ET MALWARE FormBook CnC Checkin (GET)
3.8
M
27
ZeroCERT
First
Previous
1521
1522
1523
1524
1525
1526
1527
1528
1529
1530
Next
Last
Total : 53,947cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword