File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • deepin.c3sl.ufpr.br · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /deepin/apricot/pool/main/b/backdoor-factory/

    Brazil · Fundacao da UFPR para o DCTC

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2022-04-11 03:13:14 +0000 UTC

  • mirror.lc · beef-xss_0.5.4.0+git20250422.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    · CLOUDFLARENET

    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: ee987d9fa05fbbbb687a45e86e7ca5e799a9f623
    SHA256: 303f672421b08b4bfa59d926f9425343d8fd861b4eeeb6f8b4eaecb8b15f75a9
    application/octet-stream
    4.35MB
    2025-04-30 13:22:28 +0000 UTC

  • mirror.lc · beef-xss_0.5.4.0+git20250422.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    · CLOUDFLARENET

    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: ee987d9fa05fbbbb687a45e86e7ca5e799a9f623
    SHA256: 303f672421b08b4bfa59d926f9425343d8fd861b4eeeb6f8b4eaecb8b15f75a9
    application/octet-stream
    4.35MB
    2025-04-30 13:22:28 +0000 UTC

  • mirror.lc · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /kali/pool/main/b/backdoor-factory/

    · CLOUDFLARENET

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/octet-stream
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • mirror.lc · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /kali/pool/main/b/backdoor-factory/

    · CLOUDFLARENET

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/octet-stream
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • pypi.corp.tevian.ru · pocsuite3-1.3.2.zip

    /packages/00/25/0ef5ca7e960f1395d827c3a6f20ab3424fb09555bd1dc986cef2afccb488/

    Russia · PVimpelCom

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: cb912a4c6fbb41cfbb0d8514677791c61947cc52
    SHA256: 3e14fa9d76ec7bcc629063b5736e304d98acee0f7bc10595419dc7269c941018
    application/zip
    3.43MB
    2019-04-11 09:11:30 +0000 UTC

  • repo.puri.sm · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /pureos/pool/main/b/backdoor-factory/

    Germany · Hetzner Online GmbH

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/octet-stream
    157.30KB
    2018-12-11 03:59:23 +0000 UTC

  • mirror.raspbian.ikoula.com · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /pool/main/b/backdoor-factory/

    France · Ikoula Net SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • mirror.raspbian.ikoula.com · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /pool/main/b/backdoor-factory/

    France · Ikoula Net SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • archive-4.kali.org · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /kali/pool/main/b/backdoor-factory/

    France · OVH SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • archive-4.kali.org · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /kali/pool/main/b/backdoor-factory/

    France · OVH SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • archive-4.kali.org · beef-xss_0.5.4.0+git20250422.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    France · OVH SAS

    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: ee987d9fa05fbbbb687a45e86e7ca5e799a9f623
    SHA256: 303f672421b08b4bfa59d926f9425343d8fd861b4eeeb6f8b4eaecb8b15f75a9
    application/gzip
    4.35MB
    2025-04-30 13:22:28 +0000 UTC

  • archive-4.kali.org · beef-xss_0.5.4.0+git20250422.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    France · OVH SAS

    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: ee987d9fa05fbbbb687a45e86e7ca5e799a9f623
    SHA256: 303f672421b08b4bfa59d926f9425343d8fd861b4eeeb6f8b4eaecb8b15f75a9
    application/gzip
    4.35MB
    2025-04-30 13:22:28 +0000 UTC

  • raspbian.mirror.axinja.net · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /raspbian/pool/main/b/backdoor-factory/

    France · OVH SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • raspbian.mirror.axinja.net · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /raspbian/pool/main/b/backdoor-factory/

    France · OVH SAS

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • mirror.ibice.ru · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /deb.freexian.com/extended-lts/pool/main/b/backdoor-factory/

    Switzerland · ASNET

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2017-07-29 16:40:44 +0000 UTC

  • 1885124929.rsc.cdn77.org · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /deepin/apricot/pool/main/b/backdoor-factory/

    United Kingdom · Datacamp Limited

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2022-04-11 03:13:14 +0000 UTC

  • mirror.deepines.com · backdoor-factory_3.4.2+dfsg.orig.tar.gz

    /deepin/apricot/pool/main/b/backdoor-factory/

    United Kingdom · Datacamp Limited

    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: d11030763d31ca9c4375f4e199e16311c00e5bb7
    SHA256: 46cc8ab8ad94d0b5488b704392d20d51a4c1fcd99626e40699d41573dd2d0131
    application/x-gzip
    157.30KB
    2022-04-11 03:13:14 +0000 UTC

  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • kali.itsec.am · beef-xss_0.5.4.0+git20250422.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Armenia · GNC-Alfa CJSC

    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: ee987d9fa05fbbbb687a45e86e7ca5e799a9f623
    SHA256: 303f672421b08b4bfa59d926f9425343d8fd861b4eeeb6f8b4eaecb8b15f75a9
    application/x-gzip
    4.35MB
    2025-04-30 13:22:28 +0000 UTC