Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
8251
2024-07-11 13:27
msbuild.exe
77b8c18bece02b6cfa33f68c743b3c3c
Generic Malware
Malicious Library
UPX
PE File
PE64
OS Processor Check
Lnk Format
GIF Format
VirusTotal
Malware
AutoRuns
PDB
Check memory
Creates shortcut
Creates executable files
unpack itself
suspicious TLD
Windows
ComputerName
DNS
2
Info
×
sexapp.cc(43.135.32.151)
43.135.32.151
1
Info
×
ET DNS Query for .cc TLD
5.2
M
10
ZeroCERT
8252
2024-07-11 13:26
cldapi.dll
01616e91c5618d727f6a8110a582e3ff
Malicious Packer
UPX
PE File
DLL
PE64
OS Processor Check
VirusTotal
Malware
PDB
0.8
M
7
ZeroCERT
8253
2024-07-11 13:26
Pillager32.exe
d50a3bd841116bf8e7b37268a56a5caf
Malicious Library
Malicious Packer
PE File
.NET EXE
PE32
JPEG Format
ZIP Format
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
PDB
suspicious privilege
Check memory
Checks debugger
unpack itself
Collect installed applications
installed browsers check
Browser
Email
Software
crashed
5.6
M
51
ZeroCERT
8254
2024-07-11 13:24
krpt.dll
d4ef22f79c607984534fb8a21fce15ac
Generic Malware
Malicious Library
UPX
PE File
DLL
PE32
OS Processor Check
VirusTotal
Malware
Checks debugger
unpack itself
1.2
M
18
ZeroCERT
8255
2024-07-11 13:24
gg.exe
282895a5fdd5a9c87ef8ddefba4e07aa
UPX
PE File
PE64
OS Processor Check
VirusTotal
Malware
0.4
M
7
ZeroCERT
8256
2024-07-11 13:22
parent.exe
79f0217feda3db821ac7c89d9c31ec7f
Generic Malware
PE File
PE32
VirusTotal
Malware
PDB
WriteConsoleW
0.8
2
ZeroCERT
8257
2024-07-11 13:22
get.exe
abd6cc945e157b48ef90264ae5f68baa
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE64
OS Processor Check
VirusTotal
Malware
2.6
M
46
ZeroCERT
8258
2024-07-11 13:20
winws.exe
1625c2e651375de754d82329b5e8b924
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE64
VirusTotal
Malware
crashed
1.2
18
ZeroCERT
8259
2024-07-11 13:20
gpp.exe
783540957edcf666dd295ac4835f51e8
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
WriteConsoleW
2.0
7
ZeroCERT
8260
2024-07-11 13:18
gg.dll
fb440753675363fa570a94c2f907034f
Generic Malware
Malicious Library
Malicious Packer
UPX
PE File
DLL
PE64
OS Processor Check
VirusTotal
Malware
Checks debugger
crashed
1.6
M
39
ZeroCERT
8261
2024-07-11 13:17
goo.exe
8bd9ba6bf43c3664ac3179f8aaaf780b
Malicious Library
Malicious Packer
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
WriteConsoleW
2.4
21
ZeroCERT
8262
2024-07-11 09:36
see.exe
99c32c0ce5e09149ee86bf2e314bf389
RedLine stealer
ILProtector Packer
Malicious Library
.NET framework(MSIL)
UPX
PE File
.NET EXE
PE32
OS Processor Check
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Windows
Cryptographic key
2.6
M
47
ZeroCERT
8263
2024-07-11 09:33
payload.exe
98cfc67eed512ad39df7bcc60ca10812
PE File
PE64
VirusTotal
Malware
PDB
unpack itself
DNS
crashed
2
Info
×
194.187.251.115 - mailcious
3.115.14.110
3.2
M
20
ZeroCERT
8264
2024-07-11 09:31
igcc.exe
7e2daf9fd0579b5b81c5898a2e10ed2e
Client SW User Data Stealer
Backdoor
RemcosRAT
browser
info stealer
Google
Chrome
User Data
Downloader
Malicious Library
Admin Tool (Sysinternals etc ...)
.NET framework(MSIL)
Create Service
Socket
ScreenShot
Escalate priviledges
PWS
Sniff Audio
DNS
Inter
Remcos
VirusTotal
Malware
Buffer PE
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
unpack itself
Windows
DNS
Cryptographic key
DDNS
keylogger
1
Keyword trend analysis
×
Info
×
http://geoplugin.net/json.gp
4
Info
×
geoplugin.net(178.237.33.50)
sembe.duckdns.org(194.187.251.115) - mailcious
178.237.33.50
194.187.251.115 - mailcious
3
Info
×
ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
12.0
M
53
ZeroCERT
8265
2024-07-11 09:29
f.exe
79f198f849919600241b898f482d197f
Malicious Library
Malicious Packer
UPX
Anti_VM
PE File
PE64
OS Processor Check
VirusTotal
Malware
WriteConsoleW
1.6
M
16
ZeroCERT
First
Previous
551
552
553
554
555
556
557
558
559
560
Next
Last
Total : 54,215cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword