Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
7831
2024-07-15 09:28
nlb.txt.vbs
afd1fa691ac9b0ab5b39fd8a0d0e40d7
Generic Malware
Antivirus
PowerShell
VirusTotal
Malware
powershell
AutoRuns
suspicious privilege
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
Creates executable files
unpack itself
Check virtual network interfaces
suspicious process
WriteConsoleW
Tofsee
Windows
ComputerName
DNS
Cryptographic key
1
Keyword trend analysis
×
Info
×
https://paste.ee/d/V3Lmu/0
2
Info
×
paste.ee(104.21.84.67) - mailcious
172.67.187.200 - mailcious
3
Info
×
ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee)
ET POLICY Pastebin-style Service (paste .ee) in TLS SNI
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
10.6
M
10
ZeroCERT
7832
2024-07-15 09:27
dmi.txt.vbs
7e4e5ec429a0738c15593112bcf50406
Generic Malware
Antivirus
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
1
Keyword trend analysis
×
Info
×
http://38.22.104.227:666/tnttawy.jpg
6.2
M
23
ZeroCERT
7833
2024-07-15 09:21
nlb.txt.vbs
afd1fa691ac9b0ab5b39fd8a0d0e40d7
Antivirus
VirusTotal
Malware
0.6
M
10
ZeroCERT
7834
2024-07-15 09:21
dmi.txt.vbs
7e4e5ec429a0738c15593112bcf50406
Antivirus
VirusTotal
Malware
0.8
M
23
ZeroCERT
7835
2024-07-15 09:19
pqjvyogm.exe
6498c822022751dbe8abb655e6ac9db0
PE File
.NET EXE
PE32
0.4
M
ZeroCERT
7836
2024-07-15 09:19
AntiVirus2.exe
e81179996dbd2490c45ca13d80eae0a8
PE File
.NET EXE
PE32
VirusTotal
Malware
1.6
M
58
ZeroCERT
7837
2024-07-15 09:19
1PDF.FaturaDetay_202407.exe
d8bf792f818877bf4848fde9511caeb8
Malicious Library
Antivirus
UPX
DllRegisterServer
dll
PE File
PE32
MZP Format
VirusTotal
Malware
1.6
44
ZeroCERT
7838
2024-07-15 09:19
SIP.03746.XSLSX.exe
a3e681364daaa68ce0177581573f483f
Malicious Library
Antivirus
UPX
DllRegisterServer
dll
PE File
PE32
MZP Format
VirusTotal
Malware
1.4
38
ZeroCERT
7839
2024-07-15 09:19
217.exe
42e2d273ee6215957f2b979737a74b45
Generic Malware
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
1.2
26
ZeroCERT
7840
2024-07-14 18:02
random.exe
f7a1094ec901c30a546487c8aa2a3093
EnigmaProtector
PE File
PE32
VirusTotal
Malware
Check memory
ICMP traffic
unpack itself
Collect installed applications
sandbox evasion
anti-virtualization
installed browsers check
Browser
ComputerName
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://85.28.47.4/920475a59bac849d.php
1
Info
×
85.28.47.4 - mailcious
7.8
M
64
ZeroCERT
7841
2024-07-14 18:00
Sazae-1.exe
4695f98bf6e8c0908c0b6af77ec31a6c
Emotet
Hide_EXE
Malicious Library
.NET framework(MSIL)
UPX
Anti_VM
PE File
.NET EXE
PE32
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Windows
ComputerName
Cryptographic key
2.8
M
61
ZeroCERT
7842
2024-07-14 17:58
potkmdaw.exe
cefc3739d099bae51eb2a9d3887ac12c
Generic Malware
Downloader
Malicious Library
UPX
Create Service
Socket
DGA
Http API
ScreenShot
Escalate priviledges
Steal credential
PWS
Sniff Audio
HTTP
DNS
Code injection
Internet API
persistence
FTP
KeyLogger
P2P
AntiDebug
AntiVM
PE File
PE64
OS Proces
VirusTotal
Malware
PDB
MachineGuid
Code Injection
Creates executable files
ICMP traffic
AppData folder
RCE
DNS
1
Info
×
95.169.205.186 - mailcious
7.4
M
49
ZeroCERT
7843
2024-07-14 17:58
fatherscientificpro.zip
23cad24465d730936b5c3d2b7de5bfd1
ZIP Format
VirusTotal
Malware
1.2
M
42
ZeroCERT
7844
2024-07-14 17:56
1.exe
2b292145e4ec28e8bd8b22c1353543d1
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
unpack itself
2.2
M
34
ZeroCERT
7845
2024-07-14 17:56
Q-backup.exe
55f03bade4a94d05b69e40b38b8554ae
Malicious Library
.NET framework(MSIL)
PE File
.NET EXE
PE32
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Windows
ComputerName
Cryptographic key
3.2
M
59
ZeroCERT
First
Previous
521
522
523
524
525
526
527
528
529
530
Next
Last
Total : 53,867cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword