Home
Favorites
Tools
Dr.Zero Chatbot
Notifications
Guide
2020-06-10
Version history
2020-06-10
login
popup
Submissions
10
15
20
50
Request
Connection
hash(md5,sha256)
Signature
PE API
Tag or IDS
Icon
user nickname
Date range button:
Date range picker
First seen:
Last seen:
No
Date
Request
Urls
Hosts
IDS
Rule
Score
Zero
VT
Player
Etc
1
2025-03-31 12:24
pdf.ps1
642647cf863119977d7bd52e848e0cfe
Client SW User Data Stealer
Backdoor
RemcosRAT
browser
info stealer
Hide_EXE
Generic Malware
Google
Chrome
User Data
Downloader
Malicious Library
.NET framework(MSIL)
Antivirus
Create Service
Socket
ScreenShot
Escalate priviledges
PWS
Sniff Audio
DNS
Inte
Browser Info Stealer
Remcos
VirusTotal
Email Client Info Stealer
Malware
powershell
AutoRuns
suspicious privilege
Code Injection
Malicious Traffic
Check memory
Checks debugger
buffers extracted
Creates shortcut
Creates executable files
unpack itself
Windows utilities
powershell.exe wrote
suspicious process
AppData folder
AntiVM_Disk
sandbox evasion
WriteConsoleW
VM Disk Size Check
installed browsers check
Windows
Browser
Email
ComputerName
DNS
Cryptographic key
crashed
keylogger
1
Keyword trend analysis
×
Info
×
http://geoplugin.net/json.gp
3
Info
×
geoplugin.net(178.237.33.50)
103.28.89.34
178.237.33.50
1
Info
×
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
17.4
M
8
ZeroCERT
First
1
Last
Total : 1cnts
Delete
×
Do you want to delete it?
View
×
Insert
×
http
domains
hosts
ips
Memo
Tag
Alert
×
Insert error....
keyword