Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
4351
2024-12-06 09:55
jtkhikadjthsad.exe
f453c5f8c736ff8c381e7022cad85e3e
Generic Malware
Malicious Library
UPX
PE32
PE File
OS Processor Check
VirusTotal
Malware
Telegram
Malicious Traffic
unpack itself
Tofsee
ComputerName
DNS
1
Keyword trend analysis
×
Info
×
https://steamcommunity.com/profiles/76561199804377619
5
Info
×
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.49.154.73) - mailcious
149.154.167.99 - mailcious
95.217.30.29
23.36.106.129 - mailcious
3
Info
×
ET INFO TLS Handshake Failure
ET INFO Observed Telegram Domain (t .me in TLS SNI)
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
5.0
48
ZeroCERT
4352
2024-12-06 09:53
bestthignsalwaysneedgoodheartf...
256bf9a0cdfb8f2d42aca46420a6410e
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
Malicious Traffic
RWX flags setting
exploit crash
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://192.3.95.197/332/winnit.exe
1
Info
×
192.3.95.197
1
Info
×
ET INFO Executable Download from dotted-quad Host
4.6
37
ZeroCERT
4353
2024-12-06 09:53
formule.exe
d93d94dc7baf1f13eb039d1c2bde70d1
Malicious Library
.NET framework(MSIL)
UPX
.NET EXE
PE32
PE File
VirusTotal
Malware
PDB
suspicious privilege
Check memory
Checks debugger
unpack itself
ComputerName
3.2
52
ZeroCERT
4354
2024-12-06 09:50
g8wt4y.ps1
cec79015727b3bff0975cf827521069f
Hide_EXE
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.8
23
ZeroCERT
4355
2024-12-06 09:50
XClient.exe
aa187b344ac3b8373ea57e2d1f594ba0
Malicious Library
Antivirus
UPX
.NET EXE
PE32
PE File
OS Processor Check
VirusTotal
Malware
suspicious privilege
MachineGuid
Check memory
Checks debugger
unpack itself
AntiVM_Disk
VM Disk Size Check
Windows
ComputerName
Cryptographic key
4.0
53
ZeroCERT
4356
2024-12-06 09:48
install.exe
d7389279e9fd25293d23c9acf297db0b
UPX
.NET EXE
PE32
PE File
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
2.0
31
ZeroCERT
4357
2024-12-06 09:48
x75eie.ps1
25e1952efb3a1a45146c028117fd923c
Hide_EXE
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.6
15
ZeroCERT
4358
2024-12-06 09:46
fff.ps1
42fdb45fcd954470c11adb6c97a214b3
Generic Malware
Antivirus
VirusTotal
Malware
Check memory
Creates executable files
unpack itself
Windows
Cryptographic key
2.0
22
ZeroCERT
4359
2024-12-06 09:46
skikda.exe
6c366d318dca314f30309b648776cee9
Malicious Library
PE64
PE File
VirusTotal
Malware
Buffer PE
PDB
suspicious privilege
Check memory
Checks debugger
buffers extracted
unpack itself
4.2
49
ZeroCERT
4360
2024-12-06 09:44
ClientServices.exe
afdcb2b1b8fa9182ced13402ddeeb681
Gen1
Generic Malware
Malicious Library
UPX
Malicious Packer
PE32
PE File
MZP Format
PE64
DLL
OS Processor Check
DllRegisterServer
dll
VirusTotal
Malware
Check memory
Checks debugger
Creates executable files
unpack itself
suspicious process
AppData folder
WriteConsoleW
ComputerName
4.8
45
ZeroCERT
4361
2024-12-06 09:44
Transfer-https.vbs
e2f4a3c6e7570b4424089b24b059c9d0
Hide_EXE
PE32
PE File
VirusTotal
Malware
Creates executable files
AppData folder
DNS
1
Info
×
89.197.154.116 - mailcious
7.6
40
ZeroCERT
4362
2024-12-06 09:42
ClientServices.exe
afdcb2b1b8fa9182ced13402ddeeb681
Gen1
Generic Malware
Malicious Library
UPX
Malicious Packer
PE32
PE File
MZP Format
PE64
DLL
OS Processor Check
DllRegisterServer
dll
VirusTotal
Malware
Checks debugger
Creates executable files
unpack itself
suspicious process
AppData folder
WriteConsoleW
ComputerName
4.6
45
ZeroCERT
4363
2024-12-06 09:42
pothjmawdtrg.exe
d1ccaa1cdc4f59d2e32065f37e3d707f
Generic Malware
Malicious Library
UPX
PE32
PE File
OS Processor Check
unpack itself
0.6
ZeroCERT
4364
2024-12-06 09:40
kisteruop.exe
aa7c3909bcc04a969a1605522b581a49
Generic Malware
Malicious Library
Antivirus
UPX
PE32
PE File
VirusTotal
Malware
DNS
1
Info
×
154.216.17.90
2.8
61
ZeroCERT
4365
2024-12-06 09:40
thisprojectreallygreatforevery...
f977140ed2efb487abbee562a4daaa1b
MS_RTF_Obfuscation_Objects
RTF File
doc
VirusTotal
Malware
buffers extracted
RWX flags setting
exploit crash
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://66.63.187.231/35/winnit.exe
1
Info
×
66.63.187.231
5.2
38
ZeroCERT
First
Previous
291
292
293
294
295
296
297
298
299
300
Next
Last
Total : 53,960cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword