Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
9661
2023-10-11 15:44
yam.com
cba85534bde3fb07415e32b156011a87
PWS
SMTP
KeyLogger
AntiDebug
AntiVM
PE File
PE32
.NET EXE
Browser Info Stealer
FTP Client Info Stealer
VirusTotal
Email Client Info Stealer
Malware
PDB
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
Browser
Email
ComputerName
Software
crashed
9.8
M
41
ZeroCERT
9662
2023-10-11 15:44
gncd.exe
83410598ff9829688f54886ba98d6fee
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
unpack itself
1.8
M
46
ZeroCERT
9663
2023-10-11 15:30
oshandokij.txt.exe
5796315d4909f06ae1b74d4b6035445e
AgentTesla
Malicious Library
UPX
PE File
PE32
.NET EXE
Browser Info Stealer
VirusTotal
Email Client Info Stealer
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
Browser
Email
ComputerName
crashed
3.8
54
ZeroCERT
9664
2023-10-11 14:25
Min1.exe
6178b26f7cf49fbb0e917a965068edfb
PE File
PE64
VirusTotal
Malware
1.6
M
55
malware123
9665
2023-10-11 14:24
Min.exe
6d1b84686d5dd7d8b6d0ab310b5481d1
PE File
PE64
VirusTotal
Malware
1.6
M
55
malware123
9666
2023-10-11 14:15
Min.exe
6d1b84686d5dd7d8b6d0ab310b5481d1
PE File
PE64
VirusTotal
Malware
1.6
M
55
malware123
9667
2023-10-11 14:00
W8vQdbz8.exe
63c85f130b60b2c292e0eaf9794fe897
PE File
PE64
ftp
VirusTotal
Malware
unpack itself
2.0
M
56
malware123
9668
2023-10-11 13:57
LogonFile.exe
bff3120685dafe9e31206887df290c02
Malicious Library
UPX
Malicious Packer
PE File
PE64
OS Processor Check
VirusTotal
Malware
crashed
1.6
50
malware123
9669
2023-10-11 13:48
DS.exe
5dd5dcb6da07a09fa38ceb7257e6d777
Generic Malware
Malicious Library
UPX
Malicious Packer
PE File
PE32
DllRegisterServer
dll
OS Processor Check
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
AntiVM_Disk
anti-virtualization
VM Disk Size Check
Remote Code Execution
DNS
1
Info
×
43.154.131.186
5.6
57
guest
9670
2023-10-11 13:43
soft.exe
4e8f34a4c631073808c74481f456e357
Generic Malware
Malicious Library
UPX
Malicious Packer
PE File
PE64
OS Processor Check
VirusTotal
Malware
crashed
1.4
M
56
guest
9671
2023-10-11 11:38
vpn_2.41_x86.exe
e9f6a165d0e416dc8b7bd49465a3fa5c
Emotet
Malicious Library
UPX
PE File
PE32
OS Processor Check
VirusTotal
Malware
PDB
buffers extracted
unpack itself
sandbox evasion
Browser
ComputerName
DNS
1
Info
×
104.194.222.123
4.6
5
ZeroCERT
9672
2023-10-11 11:38
Run.exe
1f5ce1bd1c533fcc0066c163f6c20cb6
UPX
PE File
PE64
OS Processor Check
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
Check virtual network interfaces
Tofsee
Windows
Cryptographic key
1
Keyword trend analysis
×
Info
×
https://files.catbox.moe/kxoths.pdf
2
Info
×
files.catbox.moe(108.181.20.35) - malware
108.181.20.35 - mailcious
2
Info
×
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
2.4
27
ZeroCERT
9673
2023-10-11 11:34
pew.EXE
6b34210f067d66503d97a9fe6925a4cf
Gen1
Emotet
Generic Malware
Malicious Library
UPX
Antivirus
PE File
PE64
CAB
VirusTotal
Malware
AutoRuns
PDB
suspicious privilege
Check memory
Checks debugger
Creates shortcut
Creates executable files
unpack itself
Windows utilities
WriteConsoleW
Windows
ComputerName
Remote Code Execution
Cryptographic key
5.8
27
ZeroCERT
9674
2023-10-11 11:33
jinglebello.vbs
27bdf0b81793b0047531dcd59ca2f72f
Generic Malware
Antivirus
Hide_URL
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
Check virtual network interfaces
suspicious process
WriteConsoleW
Tofsee
Windows
ComputerName
Cryptographic key
3
Keyword trend analysis
×
Info
×
http://apps.identrust.com/roots/dstrootcax3.p7c
https://uploaddeimagens.com.br/images/004/616/609/original/rump_vbs.jpg?1695408937
http://95.214.27.121/oshandokij.txt
3
Info
×
uploaddeimagens.com.br(172.67.215.45) - malware
23.67.53.18
172.67.215.45 - malware
1
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
8.4
3
ZeroCERT
9675
2023-10-11 11:32
Informazioni.url
71f0e30a7451930cd63fe6b7438489b8
AntiDebug
AntiVM
URL Format
MSOffice File
VirusTotal
Malware
Code Injection
RWX flags setting
exploit crash
unpack itself
Windows utilities
Tofsee
Windows
Exploit
DNS
crashed
1
Keyword trend analysis
×
Info
×
http://62.173.146.73/scarica/archivio.exe
1
Info
×
62.173.146.73 - mailcious
2
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO TLS Handshake Failure
5.8
5
ZeroCERT
First
Previous
641
642
643
644
645
646
647
648
649
650
Next
Last
Total : 50,081cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword