File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • mirrors.littlecedar.net · blackarch.files.tar.gz

    /blackarch/blackarch/os/x86_64/

    · CLOUDFLARENET

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 7092baec43ddb2c11e2abc5876ba585c38e5ff7a
    SHA256: 6c3d38979f2a959bd901d22922e7835cd6b5ac8e95c6836e8b6b117b00fbe89b
    application/octet-stream
    8.87MB
    2025-11-25 19:08:08 +0000 UTC

  • mirror.diyarciftci.xyz · blackarch.files.tar.gz

    /blackarch/blackarch/os/x86_64/

    Germany · Hetzner Online GmbH

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: c2f174324b684513271e63926362875f7e800fbe
    SHA256: 0b7d300f640e0a1ea7fc81a87ad989bb6adf76a7e3561d56f81bb9f09baa84dc
    application/octet-stream
    8.46MB
    2025-11-05 12:54:16 +0000 UTC

  • mirror.diyarciftci.xyz · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Germany · Hetzner Online GmbH

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: e16a113ddc63304e6f4454fa66a5e06a116a6c6f
    SHA256: c3eb12dc4084d5dfd1fdc76fcaf96679de6a51b479ab1fc881856ba61aee5130
    application/octet-stream
    6.67MB
    2025-11-05 12:54:18 +0000 UTC

  • mirror.diyarciftci.xyz · blackarch.files.tar.gz

    /blackarch/blackarch/os/x86_64/

    Germany · Hetzner Online GmbH

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: c2f174324b684513271e63926362875f7e800fbe
    SHA256: 0b7d300f640e0a1ea7fc81a87ad989bb6adf76a7e3561d56f81bb9f09baa84dc
    application/octet-stream
    8.46MB
    2025-11-05 12:54:16 +0000 UTC

  • mirror.diyarciftci.xyz · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Germany · Hetzner Online GmbH

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: e16a113ddc63304e6f4454fa66a5e06a116a6c6f
    SHA256: c3eb12dc4084d5dfd1fdc76fcaf96679de6a51b479ab1fc881856ba61aee5130
    application/octet-stream
    6.67MB
    2025-11-05 12:54:18 +0000 UTC

  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • ftp.ulak.net.tr · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 707106f4d19369bcfbbb2f4b7058d0476445bdfc
    SHA256: 7f8da59fc7531d7a84067f16d40deb89f305a0e9babc4ffc2c69926845b2e803
    application/octet-stream
    6.64MB
    2025-09-08 00:07:52 +0000 UTC

  • ftp.linux.org.tr · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 707106f4d19369bcfbbb2f4b7058d0476445bdfc
    SHA256: 7f8da59fc7531d7a84067f16d40deb89f305a0e9babc4ffc2c69926845b2e803
    application/octet-stream
    6.64MB
    2025-09-08 00:07:52 +0000 UTC

  • ftp.ulak.net.tr · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 707106f4d19369bcfbbb2f4b7058d0476445bdfc
    SHA256: 7f8da59fc7531d7a84067f16d40deb89f305a0e9babc4ffc2c69926845b2e803
    application/octet-stream
    6.64MB
    2025-09-08 00:07:52 +0000 UTC

  • ftp.linux.org.tr · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Download archived sample
    The password is "infected"

    SHA1: 6296b3f8612ffca7d35d22d762a29596df46f054
    SHA256: 90620e0872a2e30ceaa767b1d41718485bae1b5540d0da737d2a5a7d1436698f
    application/octet-stream
    6.64MB
    2025-09-08 00:07:52 +0000 UTC

  • blackarch.mirror.winslow.cloud · blackarch.files.tar.gz

    /blackarch/os/x86_64/

    Canada · RICAWEBSERVICES

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 528fb17d668589c58a1b1d82af5b109151442322
    SHA256: dbbbffb5ec6f37a196b0bfacfdc03f4a35fd261e915e437e18b7f629f060d15c
    application/octet-stream
    8.25MB
    2025-07-24 09:52:27 +0000 UTC

  • blackarch.mirror.winslow.cloud · blackarch.files.tar.gz

    /blackarch/os/aarch64/

    Canada · RICAWEBSERVICES

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 1d41c93b6f6e508c670d5a4e4f512cc3b91b550c
    SHA256: 0de9bb9011313d1fb6d2f8da92a6bf2e74d4c95770390eb186a6df2fcefd08f7
    application/octet-stream
    6.65MB
    2025-07-02 08:12:05 +0000 UTC

  • subs.arazcctv.ir · blackarch.files.tar.gz

    /blackarch/blackarch/os/x86_64/

    · CLOUDFLARENET

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 893e8d56ba4d4dac14ac3ea17e6e4a47c61b1742
    SHA256: 386103866fa8aa10e3aca5ff221c19a491d6e6e87d29a3e059bc906144f1b82c
    application/octet-stream
    8.26MB
    2025-06-14 23:23:26 +0000 UTC

  • subs.arazcctv.ir · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    · CLOUDFLARENET

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 2e6d16dd3bf310a9bf05f8137b2e6c6eff2de305
    SHA256: a686927f971e6b25ae836a0313c2578f7ba3a58958401c79a19dc5a0f0d3d2c5
    application/octet-stream
    6.65MB
    2025-06-14 17:16:01 +0000 UTC

  • blackarch.mirror.digitalpacific.com.au · blackarch.files.tar.gz

    /blackarch/os/aarch64/

    Australia · Hostopia Australia Web Pty Ltd

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 2e6d16dd3bf310a9bf05f8137b2e6c6eff2de305
    SHA256: a686927f971e6b25ae836a0313c2578f7ba3a58958401c79a19dc5a0f0d3d2c5
    application/octet-stream
    6.65MB
    2025-06-11 16:34:33 +0000 UTC

  • blackarch.mirror.digitalpacific.com.au · blackarch.files.tar.gz

    /blackarch/os/aarch64/

    Australia · Hostopia Australia Web Pty Ltd

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 2e6d16dd3bf310a9bf05f8137b2e6c6eff2de305
    SHA256: a686927f971e6b25ae836a0313c2578f7ba3a58958401c79a19dc5a0f0d3d2c5
    application/octet-stream
    6.65MB
    2025-06-11 16:34:33 +0000 UTC

  • blackarch.mirror.winslow.cloud · blackarch.files.tar.gz

    /blackarch/os/x86_64/

    Canada · RICAWEBSERVICES

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: d5ca14798c20e598eb247bbd1a605a8551d24fbf
    SHA256: 81c19b581186e9b9d8467fa9951a16a27d234c689b46a33ebc9ecc5d255f081e
    application/octet-stream
    8.24MB
    2025-06-04 22:09:32 +0000 UTC

  • blackarch.mirror.winslow.cloud · blackarch.files.tar.gz

    /blackarch/os/aarch64/

    Canada · RICAWEBSERVICES

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: b1e860f2902f230e6fb0cfa345f12787db23d397
    SHA256: 61fbc241c238c4f58ac70c2a464c2285e8c1618b09a0f0b8b1d7370cf9ee2a99
    application/octet-stream
    6.64MB
    2025-06-04 22:09:34 +0000 UTC

  • tr.archive.ubuntu.com · blackarch.files.tar.gz

    /blackarch/blackarch/os/x86_64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara HackTool_Samples From Florian Roth
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 93ea155106eb1a471fac90bac5219eb07a5da3f2
    SHA256: 297eb83ee6b9273ab74da10fbe2e4f28948d3893fb3cbaa275378b7a75121652
    application/octet-stream
    8.23MB
    2025-05-22 21:20:36 +0000 UTC

  • tr.archive.ubuntu.com · blackarch.files.tar.gz

    /blackarch/blackarch/os/aarch64/

    Türkiye · National Academic Network and Information Center

    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 6741d73fe101e2bbfb63d4548f97dae6f6b3b4bd
    SHA256: f107188836695f13aa41e166d3764a1239a57b9be26469f4cd44a37a8718225e
    application/octet-stream
    6.64MB
    2025-05-22 23:05:25 +0000 UTC