Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
44956
2021-05-31 09:21
filename.exe
6196cc4ad4f0a19ace433c987b0fc94a
Generic Malware
Malicious Packer
PE File
OS Processor Check
PE32
PDB
unpack itself
Windows
RCE
crashed
2.4
ZeroCERT
44957
2021-05-31 09:21
clip.exe
24b6fa846f9d1e068e55654ab7ab451b
Malicious Library
PE File
PE32
OS Processor Check
DLL
VirusTotal
Malware
Check memory
Creates executable files
unpack itself
Windows utilities
suspicious process
AppData folder
WriteConsoleW
Windows
ComputerName
DNS
5.4
M
56
ZeroCERT
44958
2021-05-31 09:19
ao.exe
b1d319888860b7a6400c5e5099d59e48
.NET EXE
PE File
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
2.0
M
45
ZeroCERT
44959
2021-05-31 09:19
drunk.exe
3b053dc6b2a1fd69b96cde6a7d320034
AsyncRAT
backdoor
PWS
.NET framework
.NET EXE
PE File
PE32
VirusTotal
Malware
PDB
suspicious privilege
MachineGuid
Malicious Traffic
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
IP Check
ComputerName
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://icanhazip.com/
3
Info
×
icanhazip.com(104.22.19.188)
172.67.9.138
104.22.18.188
1
Info
×
ET POLICY IP Check Domain (icanhazip. com in HTTP Host)
6.6
M
55
ZeroCERT
44960
2021-05-31 09:17
google.bat
362fbb934eb02fbb301049a2bce6eac9
AgentTesla
Antivirus
DGA
DNS
Socket
Create Service
Sniff Audio
HTTP
Escalate priviledges
KeyLogger
FTP
Code injection
Http API
Internet API
Steal credential
ScreenShot
Downloader
P2P
AntiDebug
AntiVM
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
5.0
1
ZeroCERT
44961
2021-05-31 09:17
bmw1.exe
05b5c49112ebf3d93b737c5540a28faa
Generic Malware
Malicious Packer
PE File
OS Processor Check
PE32
PDB
unpack itself
Windows
RCE
DNS
crashed
3.0
ZeroCERT
44962
2021-05-28 16:47
D3q0V9hldAyJ1xR.exe
3206c82d7448508708770a5537362024
PWS
.NET framework
.NET EXE
PE File
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
Windows
Cryptographic key
2.4
29
ZeroCERT
44963
2021-05-28 16:45
bmw1.exe
6387d9c50daa7741006fbe72cf0ee048
Generic Malware
Malicious Library
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
2.6
24
ZeroCERT
44964
2021-05-28 16:43
bmw.exe
cffded7466d8a28a09577a407c907fc3
Generic Malware
Malicious Library
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
2.6
22
ZeroCERT
44965
2021-05-28 11:11
file2.exe
8e459aae5e232ee1e29e70645cd0fa83
Generic Malware
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
3.0
M
47
r0d
44966
2021-05-28 11:08
file21.exe
f9003a4991f68b4b07e73ac1e89cf374
Generic Malware
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
2.8
M
38
r0d
44967
2021-05-28 11:05
file.exe
7a2f5bc93c259322c16e5a94f7139031
Generic Malware
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
3.0
M
24
r0d
44968
2021-05-28 10:57
PKL.exe
b375d47d63b41b7e1aca548742b01382
Generic Malware
PE File
PE32
VirusTotal
Malware
RWX flags setting
unpack itself
anti-virtualization
crashed
2.6
M
36
r0d
44969
2021-05-28 10:09
vbc.exe
ca1cad0dfeee9119a7bef5911c8f194e
Malicious Library
.NET EXE
PE File
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
1.6
M
26
r0d
44970
2021-05-28 09:47
seleja.exe
38976248b5751e588795a5c9c4ca0327
Malicious Library
Malicious Packer
PE File
OS Processor Check
PE32
VirusTotal
Malware
PDB
unpack itself
Windows
crashed
2.8
M
18
r0d
First
Previous
2991
2992
2993
2994
2995
2996
2997
2998
2999
3000
Next
Last
Total : 53,366cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword