Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
7801
2024-07-11 13:22
get.exe
abd6cc945e157b48ef90264ae5f68baa
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE64
OS Processor Check
VirusTotal
Malware
2.6
M
46
ZeroCERT
7802
2024-07-11 13:20
winws.exe
1625c2e651375de754d82329b5e8b924
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE64
VirusTotal
Malware
crashed
1.2
18
ZeroCERT
7803
2024-07-11 13:20
gpp.exe
783540957edcf666dd295ac4835f51e8
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
WriteConsoleW
2.0
7
ZeroCERT
7804
2024-07-11 13:18
gg.dll
fb440753675363fa570a94c2f907034f
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
DLL
PE64
OS Processor Check
VirusTotal
Malware
Checks debugger
crashed
1.6
M
39
ZeroCERT
7805
2024-07-11 13:17
goo.exe
8bd9ba6bf43c3664ac3179f8aaaf780b
Malicious Library
Malicious Packer
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
WriteConsoleW
2.4
21
ZeroCERT
7806
2024-07-11 09:36
see.exe
99c32c0ce5e09149ee86bf2e314bf389
RedLine stealer
ILProtector Packer
Malicious Library
.NET framework(MSIL)
UPX
PE File
.NET EXE
PE32
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Windows
Cryptographic key
2.6
M
47
ZeroCERT
7807
2024-07-11 09:33
payload.exe
98cfc67eed512ad39df7bcc60ca10812
PE File
PE64
VirusTotal
Malware
PDB
unpack itself
DNS
crashed
2
Info
×
194.187.251.115 - mailcious
3.115.14.110
3.2
M
20
ZeroCERT
7808
2024-07-11 09:31
igcc.exe
7e2daf9fd0579b5b81c5898a2e10ed2e
Client SW User Data Stealer
Backdoor
RemcosRAT
browser
info stealer
Google
Chrome
User Data
Downloader
Malicious Library
Admin Tool (Sysinternals etc ...)
.NET framework(MSIL)
Create Service
Socket
ScreenShot
Escalate priviledges
PWS
Sniff Audio
DNS
Inter
Remcos
VirusTotal
Malware
Buffer PE
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
unpack itself
Windows
DNS
Cryptographic key
DDNS
keylogger
1
Keyword trend analysis
×
Info
×
http://geoplugin.net/json.gp
4
Info
×
geoplugin.net(178.237.33.50)
sembe.duckdns.org(194.187.251.115) - mailcious
178.237.33.50
194.187.251.115 - mailcious
3
Info
×
ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
12.0
M
53
ZeroCERT
7809
2024-07-11 09:29
f.exe
79f198f849919600241b898f482d197f
Malicious Library
Malicious Packer
UPX
Anti_VM
PE File
PE64
OS Processor Check
VirusTotal
Malware
WriteConsoleW
1.6
M
16
ZeroCERT
7810
2024-07-11 09:26
builds.exe
4022bc5f1dcdf1a90d117aa67917cc41
Generic Malware
Malicious Library
Antivirus
UPX
AntiDebug
AntiVM
PE File
PE32
OS Processor Check
FTP Client Info Stealer
VirusTotal
Malware
Telegram
MachineGuid
Code Injection
Malicious Traffic
Check memory
WMI
unpack itself
Windows utilities
Collect installed applications
suspicious process
AppData folder
sandbox evasion
WriteConsoleW
anti-virtualization
installed browsers check
Tofsee
Windows
Browser
ComputerName
DNS
Software
2
Keyword trend analysis
×
Info
×
https://steamcommunity.com/profiles/76561199735694209
https://t.me/puffclou
5
Info
×
t.me(149.154.167.99) - mailcious
steamcommunity.com(23.76.43.59) - mailcious
149.154.167.99 - mailcious
104.75.41.21 - mailcious
65.109.241.221
3
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO Observed Telegram Domain (t .me in TLS SNI)
ET INFO TLS Handshake Failure
11.6
M
45
ZeroCERT
7811
2024-07-11 09:25
2.exe
f1c70c7cb29d5327ead87fc87f5be9aa
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
unpack itself
2.4
M
51
ZeroCERT
7812
2024-07-11 09:24
1qWbf4Bsej2u.exe
0e9459f87d4d72ca3f3fb54af7432de9
Generic Malware
Malicious Library
Malicious Packer
UPX
DllRegisterServer
dll
PE File
PE64
OS Processor Check
VirusTotal
Malware
1.0
M
32
ZeroCERT
7813
2024-07-11 09:23
1.exe
835246232dbb706d3958d28677176332
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
unpack itself
2.2
M
32
ZeroCERT
7814
2024-07-11 09:22
c.exe
2cf12d7981e0434dbd32f02c9b5647f2
Malicious Library
.NET framework(MSIL)
AntiDebug
AntiVM
PE File
.NET EXE
PE32
VirusTotal
Malware
PDB
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
Windows
DNS
Cryptographic key
crashed
1
Info
×
104.243.242.165
10.2
M
27
ZeroCERT
7815
2024-07-11 09:22
3.exe
293460728c83e7be2fccc67283815c03
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
unpack itself
2.4
M
55
ZeroCERT
First
Previous
521
522
523
524
525
526
527
528
529
530
Next
Last
Total : 53,759cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword