File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • pitagorabot.com · payload.exe

    /

    United Kingdom · Wildcard UK Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 5fc7c620ff944601d2c3bd8aca66163d3f604702
    SHA256: f028fc9fa27987c24a8ef6b9c25733f9d1b7692276c85c0894b8d3f09a739c58
    application/x-msdownload
    72.07KB
    2025-08-22 10:21:38 +0000 UTC

  • 188.84.239.125 · payload.exe

    /

    Spain · Vodafone Spain

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 4bded4db0766f093b7c696233bcf52f6c1756751
    SHA256: def8c021254f6c24ab46e11ddc8187d0275329d9cdd75a7d01132e5e601d1f1a
    application/x-msdos-program
    72.07KB
    2025-06-08 20:10:49 +0000 UTC

  • 2.155.153.73 · payload.exe

    /

    Spain · Vodafone Spain

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 4bded4db0766f093b7c696233bcf52f6c1756751
    SHA256: def8c021254f6c24ab46e11ddc8187d0275329d9cdd75a7d01132e5e601d1f1a
    application/x-msdos-program
    72.07KB
    2025-06-08 20:10:49 +0000 UTC

  • 77.231.83.40 · payload.exe

    /

    Spain · Vodafone Spain

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 4bded4db0766f093b7c696233bcf52f6c1756751
    SHA256: def8c021254f6c24ab46e11ddc8187d0275329d9cdd75a7d01132e5e601d1f1a
    application/x-msdos-program
    72.07KB
    2025-06-08 20:10:49 +0000 UTC

  • 176.31.253.10 · Linux-Malware-Samples.zip

    /oks/

    France · OVH SAS

    Yara APT_MAL_WinntiLinux_Dropper_AzazelFork_May19 From Florian Roth by Silas Cutler (havex [@] chronicle.security), Chronicle Security
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com

    SHA1: 25faf01d15847c1a19f2051f00affa23a8ead022
    SHA256: 1330037d47b8b222b94bc138b607bb2b2df227fb19ea62efd7e8e193e471bd2d
    application/zip
    542.63MB
    2025-06-18 08:23:41 +0000 UTC

  • 89.197.154.116 · WinWord.exe

    /

    United Kingdom · Virtual1 Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: dcbf5c5a6836d91b0fa980b79177225a00316a17
    SHA256: f32fc4880a6de2a154c27520726c5ef2fb09844e45d96ba1fb5a72acebddd738
    application/x-msdos-program
    72.07KB
    2025-05-23 15:59:39 +0000 UTC

  • 89.197.154.116 · Uploader.exe

    /

    United Kingdom · Virtual1 Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 9253cca535cc06a29cc9e6626c1a23381ff8d429
    SHA256: 604167d5426d058c89f0eea8c9b79baca3fcae7424668ad9e1884df42b6eae19
    application/x-msdos-program
    72.07KB
    2025-05-12 17:45:05 +0000 UTC

  • 89.197.154.116 · Accounts.exe

    /

    United Kingdom · Virtual1 Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: 62c908447200801d8f3dea96881f2605b83fab57
    SHA256: 5daa2384b006db87cf718ad270f165b61974ba8a2b033c9d1aadea284e5ee17b
    application/x-msdos-program
    72.07KB
    2025-04-17 19:27:01 +0000 UTC

  • 89.197.154.115 · Meeting.exe

    /

    United Kingdom · Virtual1 Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: adf1fe6df61d59ca7ac6232de6ed3c07d6656a8c
    SHA256: 6779bc4c64850150de694166f4b215ce25bbaca7d60b293fa7bb65e6bdecbc1a
    application/x-msdos-program
    72.07KB
    2024-09-04 09:33:04 +0000 UTC

  • 89.197.154.115 · Meeting.exe

    /

    United Kingdom · Virtual1 Limited

    Yara CobaltStrike_Resources_Reverse_Bin_v2_5_through_v4_x From Florian Roth by gssincla@google.com
    Download archived sample
    The password is "infected"

    SHA1: adf1fe6df61d59ca7ac6232de6ed3c07d6656a8c
    SHA256: 6779bc4c64850150de694166f4b215ce25bbaca7d60b293fa7bb65e6bdecbc1a
    application/x-msdos-program
    72.07KB
    2024-09-04 09:33:04 +0000 UTC