Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
4336
2024-12-07 07:27
RemoveWAT 2.2.6.exe
bfacf78644ca41fd6d4b23976e7574a1
Gen1
Generic Malware
Malicious Library
Malicious Packer
Admin Tool (Sysinternals etc ...)
UPX
.NET EXE
PE32
CAB
PE File
OS Processor Check
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
ComputerName
3.0
46
guest
4337
2024-12-06 14:10
fukjsefsdfh.exe
8531a3df05fa0928c7d51087a203be69
Malicious Library
PE32
PE File
VirusTotal
Malware
unpack itself
ComputerName
crashed
2.8
53
r0d
4338
2024-12-06 13:49
DOCTOR FIRM ORDER FORM.EXE
7921d3a2df6061b71d17c17db395b7e0
.NET framework(MSIL)
AntiDebug
AntiVM
.NET EXE
PE32
PE File
VirusTotal
Malware
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
7.6
53
guest
4339
2024-12-06 10:04
file.exe
70f7fdd57cd561a114ac03e1f50649fe
Malicious Library
Admin Tool (Sysinternals etc ...)
.NET EXE
PE32
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
Windows
DNS
Cryptographic key
1
Info
×
23.36.106.129 - mailcious
3.8
42
ZeroCERT
4340
2024-12-06 10:02
26.ps1
6c7bb2eade7ae01218c2e33fc7d30d1f
Generic Malware
Antivirus
powershell
unpack itself
powershell.exe wrote
Check virtual network interfaces
Windows
ComputerName
Cryptographic key
2
Info
×
ftp.bbqmanhattan.com(177.234.144.74)
177.234.144.74
1
Info
×
SURICATA Applayer Detect protocol only one direction
3.2
ZeroCERT
4341
2024-12-06 09:59
piotjhjadkaw.exe
eaef085a8ffd487d1fd11ca17734fb34
Generic Malware
Malicious Library
Antivirus
UPX
PE32
PE File
VirusTotal
Malware
DNS
1
Info
×
154.216.17.90
2.8
53
ZeroCERT
4342
2024-12-06 09:57
wL3EGdM.exe
7823e902900881094372948957825fe1
Malicious Library
.NET EXE
PE32
PE File
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
ComputerName
3.0
40
ZeroCERT
4343
2024-12-06 09:55
opyhjdase.exe
0d53256905411410fcfbbbcda13abdbb
Generic Malware
Malicious Library
Malicious Packer
UPX
PE64
PE File
OS Processor Check
VirusTotal
Malware
1.8
44
ZeroCERT
4344
2024-12-06 09:55
jtkhikadjthsad.exe
f453c5f8c736ff8c381e7022cad85e3e
Generic Malware
Malicious Library
UPX
PE32
PE File
OS Processor Check
VirusTotal
Malware
Telegram
Malicious Traffic
unpack itself
Tofsee
ComputerName
DNS
1
Keyword trend analysis
×
Info
×
https://steamcommunity.com/profiles/76561199804377619
5
Info
×
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious
149.154.167.99 - mailcious
95.217.30.29
23.36.106.129 - mailcious
3
Info
×
ET INFO TLS Handshake Failure
ET INFO Observed Telegram Domain (t .me in TLS SNI)
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
5.0
48
ZeroCERT
4345
2024-12-06 09:53
bestthignsalwaysneedgoodheartf...
256bf9a0cdfb8f2d42aca46420a6410e
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
Malicious Traffic
RWX flags setting
exploit crash
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://192.3.95.197/332/winnit.exe
1
Info
×
192.3.95.197
1
Info
×
ET INFO Executable Download from dotted-quad Host
4.6
37
ZeroCERT
4346
2024-12-06 09:53
formule.exe
d93d94dc7baf1f13eb039d1c2bde70d1
Malicious Library
.NET framework(MSIL)
UPX
.NET EXE
PE32
PE File
VirusTotal
Malware
PDB
suspicious privilege
Check memory
Checks debugger
unpack itself
ComputerName
3.2
52
ZeroCERT
4347
2024-12-06 09:50
g8wt4y.ps1
cec79015727b3bff0975cf827521069f
Hide_EXE
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.8
23
ZeroCERT
4348
2024-12-06 09:50
XClient.exe
aa187b344ac3b8373ea57e2d1f594ba0
Malicious Library
Antivirus
UPX
.NET EXE
PE32
PE File
OS Processor Check
VirusTotal
Malware
suspicious privilege
MachineGuid
Check memory
Checks debugger
unpack itself
AntiVM_Disk
VM Disk Size Check
Windows
ComputerName
Cryptographic key
4.0
53
ZeroCERT
4349
2024-12-06 09:48
install.exe
d7389279e9fd25293d23c9acf297db0b
UPX
.NET EXE
PE32
PE File
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
2.0
31
ZeroCERT
4350
2024-12-06 09:48
x75eie.ps1
25e1952efb3a1a45146c028117fd923c
Hide_EXE
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.6
15
ZeroCERT
First
Previous
281
282
283
284
285
286
287
288
289
290
Next
Last
Total : 53,953cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword