Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
10651
2021-07-29 11:16
REQUESTS.exe
631bbfae6f9b0a92cbc3e525e02103bb
RAT
Generic Malware
UPX
Antivirus
PE32
.NET EXE
PE File
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
WMI
Creates shortcut
ICMP traffic
unpack itself
powershell.exe wrote
suspicious process
WriteConsoleW
Windows
ComputerName
DNS
Cryptographic key
crashed
5
Info
×
google.com(172.217.161.46)
bing.com(13.107.21.200)
45.141.152.18 - malware
13.107.21.200
172.217.26.142
7.6
M
34
ZeroCERT
10652
2021-07-29 11:18
pmo-5.exe
4b6d021cb11a5e8abb0ab28e1ae0f711
Generic Malware
Admin Tool (Sysinternals etc ...)
PE32
.NET EXE
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
2.0
M
21
ZeroCERT
10653
2021-07-29 11:28
fxbggzfdhfgdgn.exe
fe690cdae7fb62b504be7cdc64cda45e
Generic Malware
PE32
PE File
VirusTotal
Malware
RWX flags setting
unpack itself
1.8
M
17
guest
10654
2021-07-29 11:35
reestr.exe
a69e12607d01237460808fa1709e5e86
Generic Malware
PE32
PE File
VirusTotal
Malware
RWX flags setting
unpack itself
crashed
2.2
M
45
guest
10655
2021-07-29 12:18
Statement_320395.xlsm
d7e77f0b7240abdb89310ba128949a97
VBA_macro
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
Check memory
buffers extracted
Creates executable files
RWX flags setting
unpack itself
suspicious process
Windows
2
Info
×
docusignupdates.com(198.52.122.157) - malware
128.199.243.169 - malware
1
Info
×
ET POLICY PE EXE or DLL Windows file download HTTP
4.2
M
19
guest
10656
2021-07-29 12:19
Statement_79328019.xlsm
0849c09e632bce7e4ae4e59745c1879c
VBA_macro
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
Check memory
buffers extracted
Creates executable files
ICMP traffic
unpack itself
suspicious process
Windows
1
Keyword trend analysis
×
Info
×
http://docusignupdates.com:8088/images/avatar_vbm5c3.png
4
Info
×
docusignupdates.com(198.52.122.157) - malware
azuredocs.org(208.83.69.35) - malware
208.83.69.35 - malware
198.52.122.157 - malware
1
Info
×
ET POLICY PE EXE or DLL Windows file download HTTP
4.6
M
18
guest
10657
2021-07-29 12:21
case_L0123456789.xlsb
dfafce895c8a2861c16f66da17563d71
Gen2
Gen1
VBA_macro
Malicious Library
Malicious Packer
UPX
PE32
PE File
VirusTotal
Malware
Check memory
Checks debugger
Creates executable files
RWX flags setting
unpack itself
Windows utilities
Check virtual network interfaces
suspicious process
WriteConsoleW
Windows
ComputerName
DNS
crashed
1
Info
×
185.82.127.199
9.4
16
guest
10658
2021-07-29 12:28
bacground_k8gad.png
81be4859611a7036babd8e5d911908c5
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
27
ZeroCERT
10659
2021-07-29 12:28
button_io79p.png
1c8c2309aaa92dc63258c626bbbbe3c2
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
20
ZeroCERT
10660
2021-07-29 12:28
avatar_vbm5c3.png
4adf054116171db5d17aa343621eae7a
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
28
ZeroCERT
10661
2021-07-29 12:29
bacground_bxfop8.png
11dcb6ef90b899cc413590e66a755256
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
22
ZeroCERT
10662
2021-07-29 12:29
bacground_rvvsrc.png
58c31b264b49d989b8b8c9412bc78b61
Generic Malware
Malicious Library
PE32
DLL
PE File
0.4
M
ZeroCERT
10663
2021-07-29 12:29
button_cou47.png
779e038e1958246fb87628384b52fda4
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
21
ZeroCERT
10664
2021-07-29 12:29
button_xrssq2.png
06b64d576258107103165f793837ac5f
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.2
M
21
ZeroCERT
10665
2021-07-29 12:29
bacground_4skfzc.png
015c9e71548ba2f9a3163a9ef6cb3f91
Generic Malware
Malicious Library
PE32
DLL
PE File
VirusTotal
Malware
1.4
M
32
ZeroCERT
First
Previous
711
712
713
714
715
716
717
718
719
720
Next
Last
Total : 49,422cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword