Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
48361
2024-09-25 10:40
msf4448.exe
aa752f99b9bfd2ebbb36acdfdf2fa2b8
Metasploit
Generic Malware
PE File
PE64
VirusTotal
Malware
DNS
1
Info
×
124.221.70.199 - malware
3.0
M
60
ZeroCERT
48362
2024-09-25 10:42
drop1.exe
426f7692316c1fe458d098a1eef915e4
RedLine stealer
Malicious Library
.NET framework(MSIL)
PE File
.NET EXE
PE32
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
2.2
M
44
ZeroCERT
48363
2024-09-25 10:44
mirage.elf
9c9a9e92ef0e5dbdb08955ee2f5ee4d5
AntiDebug
AntiVM
ELF
VirusTotal
Email Client Info Stealer
Malware
suspicious privilege
Checks debugger
Creates shortcut
unpack itself
installed browsers check
Browser
Email
ComputerName
4.2
M
29
ZeroCERT
48364
2024-09-25 10:46
ShellWaitForProcess.exe
e80d930390090acbf7353e9df7d1ac84
UPX
PE File
PE64
OS Processor Check
PDB
0.2
M
ZeroCERT
48365
2024-09-25 10:48
vdshdfsd.exe
5456c9b238c54e52277972cdadf6764d
PE File
.NET EXE
PE32
VirusTotal
Malware
PDB
Check memory
Checks debugger
unpack itself
WriteConsoleW
ComputerName
2.6
M
26
ZeroCERT
48366
2024-09-25 10:48
Software.exe
66c1d33fa2373f9f734336b87f123e31
Gen1
Generic Malware
Malicious Library
UPX
PE File
PE64
OS Processor Check
DLL
ZIP Format
VirusTotal
Malware
Check memory
Checks debugger
Creates executable files
crashed
2.2
M
49
ZeroCERT
48367
2024-09-25 10:49
InnoPack.exe
d1a71a41adffc6131f04ad62bc16866a
Generic Malware
Malicious Library
Admin Tool (Sysinternals etc ...)
Malicious Packer
UPX
PE File
PE32
MZP Format
OS Processor Check
PE64
VirusTotal
Malware
AutoRuns
Check memory
Checks debugger
Creates executable files
unpack itself
AppData folder
Windows
crashed
3.8
16
ZeroCERT
48368
2024-09-25 10:51
Svchost.exe
d7b665428dd5924505511bd5c0f79e28
Malicious Packer
UPX
PE File
.NET EXE
PE32
OS Processor Check
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
ComputerName
2.2
M
54
ZeroCERT
48369
2024-09-25 10:53
Na.exe
a78bd8de97e48d223a7c2f81e538d443
Generic Malware
PE File
.NET EXE
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
ComputerName
2.0
M
31
ZeroCERT
48370
2024-09-25 10:53
lkjhgfdfsd.exe
3f21d4209d237332463e5364186f1b91
PE File
.NET EXE
PE32
VirusTotal
Malware
PDB
Check memory
Checks debugger
unpack itself
WriteConsoleW
ComputerName
2.6
M
27
ZeroCERT
48371
2024-09-25 10:53
lpg.cmd
4541e7e77b39be572ebbffc177ee9407
Generic Malware
Downloader
Antivirus
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Sniff Audio
HTTP
DNS
Code injection
Internet API
FTP
KeyLogger
P2P
AntiDebug
AntiVM
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
4.6
3
ZeroCERT
48372
2024-09-25 10:55
Installeraus.exe
749bd6bf56a6d0ad6a8a4e5712377555
NSIS
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Cryptocurrency Miner
Malware
AutoRuns
Check memory
Checks debugger
WMI
Creates executable files
AppData folder
WriteConsoleW
Windows
ComputerName
DNS
CoinMiner
1
Keyword trend analysis
×
Info
×
http://94.131.119.184:443/agent.ashx
1
Info
×
94.131.119.184
1
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (CoinMiner)
4.8
M
37
ZeroCERT
48373
2024-09-25 10:55
dmsag.exe
5a7ef447d5d556b9d550da1cac582a7a
Confuser .NET
PE File
.NET EXE
PE32
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
ComputerName
2.2
M
25
ZeroCERT
48374
2024-09-25 10:56
test.bat
7d6ef15c4848118fc0ef9b6b797bf308
Generic Malware
Downloader
Antivirus
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Sniff Audio
HTTP
DNS
Code injection
Internet API
FTP
KeyLogger
P2P
AntiDebug
AntiVM
powershell
suspicious privilege
Code Injection
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
malicious URLs
WriteConsoleW
Windows
ComputerName
Cryptographic key
1
Keyword trend analysis
×
Info
×
http://147.45.44.131/files/vkga15.ps1
6.2
ZeroCERT
48375
2024-09-25 10:57
Descargar%20Musica%20Gratis-up...
8b1275afa5ed7d63fc33c02400062814
IAmTheKing Family
HermeticWiper
Emotet
Gen1
Generic Malware
PDF Suspicious Link
Malicious Library
UPX
Anti_VM
PE File
PE32
MZP Format
OS Processor Check
DLL
ftp
Lnk Format
GIF Format
URL Format
PE64
VirusTotal
Malware
AutoRuns
suspicious privilege
MachineGuid
Checks debugger
Creates shortcut
Creates executable files
unpack itself
AppData folder
sandbox evasion
installed browsers check
Windows
Browser
ComputerName
2
Keyword trend analysis
×
Info
×
http://soundfrost.org/pings/update.php?project=14&version=3.9.6
http://soundfrost.org/update/update.php?version=3.9.6&product=14&id=e1e9f0c45386f464933c401e41f43ee30779b6d0
2
Info
×
soundfrost.org(185.132.132.47)
185.132.132.47
6.0
15
ZeroCERT
First
Previous
3221
3222
3223
3224
3225
3226
3227
3228
3229
3230
Next
Last
Total : 49,283cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword