Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
10276
2021-07-21 08:56
HomeTelem.exe
13871a0ca072473e646f147c11c054ea
Antivirus
UPX
Malicious Packer
PE32
PE File
VirusTotal
Malware
1.4
39
ZeroCERT
10277
2021-07-21 09:03
000968231254_1.xlsm
be08be775737dbd2ef07cd65b3c95d7e
VBA_macro
VirusTotal
Malware
RWX flags setting
unpack itself
2.6
30
ZeroCERT
10278
2021-07-21 09:09
F-Launcher.rar
7192a321beef1d52a2fba4254051b4f5
AntiDebug
AntiVM
VirusTotal
Email Client Info Stealer
Malware
suspicious privilege
Checks debugger
Creates shortcut
unpack itself
AntiVM_Disk
VM Disk Size Check
installed browsers check
Browser
Email
ComputerName
4.2
1
ZeroCERT
10279
2021-07-21 09:10
15.docx
0e3e79026507f3cf814f75cd53fea060
VBA_macro
MSOffice File
VirusTotal
Malware
RWX flags setting
unpack itself
Tofsee
2
Keyword trend analysis
×
Info
×
https://feedbackportal.download/ecm/ibm/3173379797/
https://feedbackportal.download/ecm/ibm/
2
Info
×
feedbackportal.download(208.68.37.17) - mailcious
208.68.37.17 - mailcious
1
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
2.4
M
9
ZeroCERT
10280
2021-07-21 09:10
jjroblox.rar
ce3a25ffec557e9ca0e52f2dd6a01485
Escalate priviledges
KeyLogger
AntiDebug
AntiVM
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
unpack itself
2.0
1
ZeroCERT
10281
2021-07-21 09:11
viri.exe
86d212c2cf76ffe4c8ed9ec0af63a264
NPKI
Generic Malware
Anti_VM
PE64
PE File
VirusTotal
Malware
MachineGuid
Check memory
Checks debugger
unpack itself
2.4
M
34
ZeroCERT
10282
2021-07-21 09:13
converter.dot
6fda26b6d723cf0a8ff3577cbd540db9
VBA_macro
MSOffice File
unpack itself
0.8
ZeroCERT
10283
2021-07-21 09:39
new title.doc
aaa839e4993c07fdfba45afe8826d6bf
VBA_macro
Malicious Packer
MSOffice File
Vulnerability
VirusTotal
Malware
unpack itself
2.8
11
ZeroCERT
10284
2021-07-21 09:40
Churner.dll
f7092de5f32c0df837fa7f947a3424af
UPX
PE64
OS Processor Check
DLL
PE File
VirusTotal
Malware
Checks debugger
unpack itself
1.6
2
ZeroCERT
10285
2021-07-21 09:41
100001100002344190721.pdf.exe
885e3c0a5f5ae94558bf669366b9e921
PWS
.NET framework
RAT
Generic Malware
AntiDebug
AntiVM
PE32
OS Processor Check
.NET EXE
PE File
VirusTotal
Malware
suspicious privilege
Code Injection
Check memory
Checks debugger
buffers extracted
unpack itself
Windows
Cryptographic key
8.4
21
ZeroCERT
10286
2021-07-21 10:13
redik.exe
ff361121c102c043c2c4b5c6a6b4410c
Lazarus Family
Generic Malware
Themida Packer
Malicious Library
PE32
.NET EXE
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
Checks Bios
Detects VMWare
Check virtual network interfaces
VMware
anti-virtualization
Windows
Firmware
DNS
Cryptographic key
crashed
1
Keyword trend analysis
×
Info
×
http://194.226.139.106:43188/ - rule_id: 2242
1
Info
×
194.226.139.106 - mailcious
1
Info
×
http://194.226.139.106:43188/
6.8
M
56
r0d
10287
2021-07-21 10:22
new title.doc
aaa839e4993c07fdfba45afe8826d6bf
VBA_macro
Malicious Packer
UPX
MSOffice File
PE32
DLL
PE File
VirusTotal
Malware
Creates executable files
RWX flags setting
unpack itself
Windows utilities
AppData folder
Tofsee
Windows
1
Keyword trend analysis
×
Info
×
https://i.ibb.co/mcYqj2v/Wh-Atmd-RWjre-EJ.jpg
3
Info
×
i.ibb.co(104.194.8.196)
104.194.8.196
172.96.140.18
2
Info
×
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO TLS Handshake Failure
5.4
11
ZeroCERT
10288
2021-07-21 10:24
Server.txt.ps1
73eaacd943a240793fffaa5fb099e185
Antivirus
VirusTotal
Malware
powershell
Check memory
heapspray
unpack itself
WriteConsoleW
Windows
Cryptographic key
2.4
5
ZeroCERT
10289
2021-07-21 10:36
vbc.exe
c8feb9d53b567cd1bfb0e59cf7d26bc2
Generic Malware
PE32
PE File
VirusTotal
Malware
RWX flags setting
unpack itself
2.2
M
31
r0d
10290
2021-07-21 10:39
converter.dot
6fda26b6d723cf0a8ff3577cbd540db9
VBA_macro
MSOffice File
RWX flags setting
unpack itself
1.8
M
ZeroCERT
First
Previous
681
682
683
684
685
686
687
688
689
690
Next
Last
Total : 49,341cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword