Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
48781
2021-02-17 13:49
6hyuyj.exe
77be0dd6570301acac3634801676b5d7
VirusTotal
Malware
malicious URLs
IP Check
crashed
1
Info
×
api.ipify.org(54.243.164.148)
3.0
M
61
ZeroCERT
48782
2021-02-17 13:45
http://hilltopmagic.xyz/dVhFtc...
d41d8cd98f00b204e9800998ecf8427e
Code Injection
RWX flags setting
unpack itself
Windows utilities
malicious URLs
Windows
1
Info
×
hilltopmagic.xyz(188.225.75.54)
2.6
ZeroCERT
48783
2021-02-17 13:39
work.exe
b896f63a3a842e2ca679f8f85c182a56
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
Windows
Cryptographic key
1
Info
×
www.google.com(216.58.197.228)
2.2
ZeroCERT
48784
2021-02-17 13:37
xmr32.exe
97d89d25e9589f995d374cb7d89b4433
VirusTotal
Malware
malicious URLs
WriteConsoleW
2
Info
×
mozilla.org(44.235.246.155)
detectportal.firefox.com(34.107.221.82)
3.0
M
59
ZeroCERT
48785
2021-02-17 13:23
work.exe
017521d0bb61bc2f48fd865b5a29a069
VirusTotal
Malware
suspicious privilege
Checks debugger
RWX flags setting
unpack itself
malicious URLs
WriteConsoleW
Windows
DNS
Cryptographic key
DDNS
crashed
1
Info
×
binancino.hopto.org(136.244.100.20)
1
Info
×
ET POLICY DNS Query to DynDNS Domain *.hopto .org
5.4
M
50
ZeroCERT
48786
2021-02-17 13:23
vbc.exe
b9609685b1685626956a7d93edca6c49
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
malicious URLs
3.4
M
57
ZeroCERT
48787
2021-02-17 11:43
v.exe
e23246d5a16fd344dfd2fc7177d43890
VirusTotal
Malware
Checks debugger
unpack itself
DNS
crashed
3.4
M
15
ZeroCERT
48788
2021-02-17 11:43
rv.exe
6a9ff2133c36e8ccda6a61a13460f938
VirusTotal
Malware
suspicious process
malicious URLs
crashed
2.6
M
13
ZeroCERT
48789
2021-02-17 11:39
oxchjdfgbnv.exe
753f316cffd68bd3c5161c8387a770b4
VirusTotal
Malware
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
malicious URLs
1
Info
×
hanxlas.ac.ug(185.215.113.77) - mailcious
7.2
M
20
ZeroCERT
48790
2021-02-17 11:37
InstallC_Sh_Directly.exe
e81ce5dcf33ec512ae6f8a37a9e7dddd
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
malicious URLs
3.0
M
46
ZeroCERT
48791
2021-02-17 11:35
bre-m.pdf.exe
0d7df2c6da6eb477449e7af2dc0ced59
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
Windows
DNS
Cryptographic key
1
Info
×
www.google.com(172.217.25.68)
3.4
M
16
ZeroCERT
48792
2021-02-17 11:35
axchjdfgbnv.exe
ffe24ed6fd84a7c44447c54a9d0cb209
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
malicious URLs
ComputerName
DNS
1
Info
×
185.215.113.77 - malware
5.0
M
26
ZeroCERT
48793
2021-02-17 11:25
4818840.dat.exe
106b4adbd60d3ed9b382941f9e16a939
VirusTotal
Malware
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
sandbox evasion
ComputerName
DNS
crashed
6.2
M
22
ZeroCERT
48794
2021-02-17 11:25
44243988062.dat.exe
2c2307bb3cacbca7f7ba9d7d76bb88ff
VirusTotal
Malware
AutoRuns
Code Injection
Check memory
Checks debugger
buffers extracted
Creates executable files
unpack itself
Windows utilities
suspicious process
AppData folder
sandbox evasion
WriteConsoleW
Windows
ComputerName
8.6
M
17
ZeroCERT
48795
2021-02-17 10:52
10.crtf.exe
ac75d6634acbce0bc12d83e68658e7ef
ENERGETIC BEAR
VirusTotal
Malware
Report
suspicious privilege
Checks debugger
buffers extracted
unpack itself
Check virtual network interfaces
ComputerName
DNS
5
Info
×
134.119.186.202
200.52.147.93
142.202.191.164
94.140.114.136 - mailcious
108.170.20.75
4
Info
×
ET CNC Feodo Tracker Reported CnC Server group 12
ET CNC Feodo Tracker Reported CnC Server group 24
ET CNC Feodo Tracker Reported CnC Server group 2
ET CNC Feodo Tracker Reported CnC Server group 4
6.6
M
29
ZeroCERT
First
Previous
3251
3252
3253
3254
3255
3256
3257
3258
3259
3260
Next
Last
Total : 53,963cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword