Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
14371
2023-03-21 10:11
RegSvcs.exe
5aecc5c3cb23cdf6cd97d3f8de866d2b
RAT
.NET DLL
DLL
PE32
PE File
ZeroCERT
14372
2023-03-21 10:09
vbc.exe
5ccc064218d48040cb306d30cbd83079
RAT
Generic Malware
Antivirus
AntiDebug
AntiVM
.NET EXE
PE32
PE File
VirusTotal
Malware
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
unpack itself
Check virtual network interfaces
suspicious process
Windows
ComputerName
Cryptographic key
1
Keyword trend analysis
×
Info
×
http://amandamuggleton.com.au/.wp-cli/cache/Hqiogfzdx.bmp
2
Info
×
amandamuggleton.com.au(116.0.23.217)
116.0.23.217 - suspicious
1
Info
×
ET HUNTING Suspicious Terse Request for .bmp
11.4
M
21
ZeroCERT
14373
2023-03-21 10:09
information3.txt.ps1
d05f9f87c9f7f3f31fa5993f77d0b76a
Generic Malware
Antivirus
Check memory
unpack itself
WriteConsoleW
Windows
Cryptographic key
1.0
ZeroCERT
14374
2023-03-21 10:09
vbc.exe
d94d4ff9589037731d7dfb4d9e582b0b
PWS
.NET framework
RAT
.NET EXE
PE32
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
DNS
1
Info
×
202.146.218.59
3.0
M
40
ZeroCERT
14375
2023-03-21 10:07
curriculum_vitae-copie.vbs
61dd16fa14a6fd952a3422de967ebec1
Generic Malware
Antivirus
AntiDebug
AntiVM
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Code Injection
Check memory
Checks debugger
Creates shortcut
unpack itself
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
6.2
4
ZeroCERT
14376
2023-03-21 10:06
laoxiang.exe
a6a9abf50eb980d12622e14c237a9f37
Malicious Library
PE32
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
AntiVM_Disk
sandbox evasion
anti-virtualization
VM Disk Size Check
human activity check
Browser
DNS
crashed
1
Info
×
202.146.218.59
6.6
M
43
ZeroCERT
14377
2023-03-21 10:06
AlCapone99.exe
3db6d94b8df4916aa7cb0d67f2bba3f6
UPX
Malicious Library
OS Processor Check
PE32
PE File
VirusTotal
Malware
unpack itself
2.0
M
45
ZeroCERT
14378
2023-03-21 07:44
LService.dat
513c34815b063e50d6f18c91366ff349
RAT
.NET DLL
DLL
PE32
PE File
VirusTotal
Malware
PDB
0.6
1
ZeroCERT
14379
2023-03-21 07:44
LServiceHandler.jpg
2b8ed230651d29c3f4a7a330b742bbdd
.NET EXE
PE32
PE File
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
ICMP traffic
unpack itself
Windows utilities
suspicious process
AppData folder
Windows
4.0
8
ZeroCERT
14380
2023-03-20 18:13
zxcvb.exe
688774feec1cc9685acaece804dc7a26
PWS
.NET framework
RAT
UPX
OS Processor Check
.NET EXE
PE32
PE File
VirusTotal
Malware
Check memory
Checks debugger
unpack itself
ComputerName
2.2
M
50
ZeroCERT
14381
2023-03-20 18:13
photo_004.exe
60bd74449157229bda4bec8234885f7f
Generic Malware
UPX
Malicious Library
OS Processor Check
PE32
PE File
unpack itself
Remote Code Execution
1.2
ZeroCERT
14382
2023-03-20 18:05
File_pass1234.zip
477411ecd609489540e26607c6f44ac2
ZIP Format
VirusTotal
Malware
0.4
M
1
ZeroCERT
14383
2023-03-20 14:29
D0C93848394-Spodogenic.vbs
218ddf74d466267211be24dac160e93a
Generic Malware
Antivirus
VirusTotal
Malware
suspicious privilege
Check memory
Checks debugger
buffers extracted
WMI
Creates shortcut
unpack itself
Windows utilities
suspicious process
Windows
ComputerName
Cryptographic key
7.4
M
2
ZeroCERT
14384
2023-03-20 14:29
43444VBS NO STARTUP.vbs
7b470a829fac968e56744f805ab85efc
Generic Malware
Antivirus
PowerShell
VirusTotal
Malware
powershell
suspicious privilege
Check memory
Checks debugger
Creates shortcut
unpack itself
suspicious process
WriteConsoleW
Windows
ComputerName
Cryptographic key
5.4
11
ZeroCERT
14385
2023-03-20 11:29
chat-gpt.exe
65c2ae916c616382ed8d8df33aa50bbc
Generic Malware
UPX
Malicious Library
Malicious Packer
Antivirus
OS Processor Check
PE64
PE File
VirusTotal
Malware
powershell
PDB
suspicious privilege
MachineGuid
Check memory
Checks debugger
Creates shortcut
unpack itself
powershell.exe wrote
suspicious process
Windows
ComputerName
Cryptographic key
4.4
36
ZeroCERT
First
Previous
951
952
953
954
955
956
957
958
959
960
Next
Last
Total : 49,444cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword