Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
48931
2021-02-06 22:13
pleskkkk.exe
5b100885c4689277966e7f6205fed891
VirusTotal
Malware
Buffer PE
AutoRuns
Code Injection
Checks debugger
buffers extracted
unpack itself
malicious URLs
Windows
DNS
9.6
M
49
ZeroCERT
48932
2021-02-06 22:11
start.vbs
9e3905e054e78547ec4fbbbb73e92b78
VirusTotal
Malware
WMI
malicious URLs
ComputerName
2.0
14
ZeroCERT
48933
2021-02-06 22:09
pianificazione.exe
05105036a01bb0f7fff05264d83f244f
VirusTotal
Malware
Buffer PE
AutoRuns
PDB
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates executable files
unpack itself
Windows utilities
Check virtual network interfaces
suspicious process
AppData folder
malicious URLs
WriteConsoleW
Windows
ComputerName
DNS
1
Keyword trend analysis
×
Info
×
http://gavrilobtcapikey2884238984928.netsons.org/Runtime%20Broker.exe
2
Info
×
gavrilobtcapikey2884238984928.netsons.org(89.40.172.121) - malware
89.40.172.121 - malware
3
Info
×
ET POLICY PE EXE or DLL Windows file download HTTP
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
ET INFO EXE CheckRemoteDebuggerPresent (Used in Malware Anti-Debugging)
10.2
M
21
ZeroCERT
48934
2021-02-06 22:06
plesk.exe
1c2af9a6792ceb4219d3eb0b1c525381
VirusTotal
Malware
AutoRuns
Check memory
Checks debugger
unpack itself
IP Check
Tofsee
Windows
1
Keyword trend analysis
×
Info
×
https://api.ipify.org/
4
Info
×
gxbrowser.net(193.239.147.224) - malware
cnc.c25e6559668942.xyz() - malware
api.ipify.org(23.21.252.4)
54.235.142.93
1
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
4.0
M
25
ZeroCERT
48935
2021-02-06 22:00
gang.exe
5f2a8fe0c9675f3cad5458dfbac33e34
VirusTotal
Malware
Buffer PE
AutoRuns
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
WMI
unpack itself
Windows utilities
Check virtual network interfaces
malicious URLs
sandbox evasion
WriteConsoleW
Windows
ComputerName
Firmware
DNS
1
Info
×
193.239.147.224 - malware
13.2
M
28
ZeroCERT
48936
2021-02-06 22:00
JGSKDJF.exe
5b100885c4689277966e7f6205fed891
VirusTotal
Malware
Buffer PE
AutoRuns
Code Injection
Checks debugger
buffers extracted
unpack itself
malicious URLs
Windows
9.0
M
49
ZeroCERT
48937
2021-02-06 19:41
disable.vbs
3183ab3e54079f5094f0438ad5d460f6
VirusTotal
Malware
powershell
suspicious privilege
Code Injection
Check memory
Checks debugger
heapspray
Creates shortcut
unpack itself
Disables Windows Security
suspicious process
malicious URLs
WriteConsoleW
Windows
ComputerName
Cryptographic key
8.2
7
ZeroCERT
48938
2021-02-06 19:41
downloaddocument.doc
d3d0fab713c4d62f0c00a790b9b820dc
VirusTotal
Malware
unpack itself
malicious URLs
DNS
2.4
M
12
ZeroCERT
48939
2021-02-06 18:24
crytp.exe
01c615395a542dead29b178a9bc00894
VirusTotal
Malware
Buffer PE
AutoRuns
Code Injection
Checks debugger
buffers extracted
unpack itself
malicious URLs
Windows
DNS
9.4
M
31
ZeroCERT
48940
2021-02-06 18:23
cmon.bat
c0e97fdb841fc8815e1b7cef2bb3f5fb
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
malicious URLs
WriteConsoleW
Windows
ComputerName
Cryptographic key
4.6
ZeroCERT
48941
2021-02-06 18:21
crytp.exe
01c615395a542dead29b178a9bc00894
VirusTotal
Malware
Buffer PE
AutoRuns
Code Injection
Checks debugger
buffers extracted
unpack itself
malicious URLs
Windows
8.8
M
31
ZeroCERT
48942
2021-02-06 18:13
cmon.bat
c0e97fdb841fc8815e1b7cef2bb3f5fb
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
malicious URLs
WriteConsoleW
Windows
ComputerName
DNS
Cryptographic key
5.2
ZeroCERT
48943
2021-02-06 18:12
bigRANSOM.exe
ab5e379db162ff52ec1c769f69276fd5
VirusTotal
Malware
Buffer PE
Code Injection
Checks debugger
buffers extracted
unpack itself
malicious URLs
7.0
M
38
ZeroCERT
48944
2021-02-06 18:10
001_01.ps1
7c22563e145f88519cfbfd7f26d1e3ad
VirusTotal
Malware
unpack itself
malicious URLs
1.8
17
ZeroCERT
48945
2021-02-06 17:48
001_01.ps1
7c22563e145f88519cfbfd7f26d1e3ad
VirusTotal
Malware
malicious URLs
crashed
1.6
17
ZeroCERT
First
Previous
3261
3262
3263
3264
3265
3266
3267
3268
3269
3270
Next
Last
Total : 53,887cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword