File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 167.71.178.92 · Invoke-NinjaCopy.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a5b7f082fe0c36b3b6dd8035a22c1955b81e8cc9
    SHA256: b52821c6061d244f4c197e78636317b122972e7abed2892ecc7c713f24f866be
    433.24KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-Mimikatz.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3da065e07b990034e9db78421672f70b63aa5329
    SHA256: ebf54f745dc81e1958f75e4ca91dd0ab989fc9787bb6b0bf993e2f51d9a2a5bb
    2.10MB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-CredentialInjection.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7343ec8549dca37f7b5310d5973e62a9d7ec4121
    SHA256: 7de9b5e764eaab1cb9b343f784c95b81d294ed754da7608411e8e78777803d96
    442.91KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-ReflectivePEInjection.ps1

    /tradecraftlabs/fhlbc/PowerSploit/CodeExecution/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e104ea8908a0c21f245b629dc075ad1dbdea364d
    SHA256: c81d0073c92d0b4d0cc66a4c1d64d4ca2afbe56d78eb9d9611be8055919fd8ba
    132.60KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-NinjaCopy.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a5b7f082fe0c36b3b6dd8035a22c1955b81e8cc9
    SHA256: b52821c6061d244f4c197e78636317b122972e7abed2892ecc7c713f24f866be
    433.24KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-Mimikatz.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3da065e07b990034e9db78421672f70b63aa5329
    SHA256: ebf54f745dc81e1958f75e4ca91dd0ab989fc9787bb6b0bf993e2f51d9a2a5bb
    2.10MB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-CredentialInjection.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7343ec8549dca37f7b5310d5973e62a9d7ec4121
    SHA256: 7de9b5e764eaab1cb9b343f784c95b81d294ed754da7608411e8e78777803d96
    442.91KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-ReflectivePEInjection.ps1

    /fhlbc/PowerSploit/CodeExecution/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e104ea8908a0c21f245b629dc075ad1dbdea364d
    SHA256: c81d0073c92d0b4d0cc66a4c1d64d4ca2afbe56d78eb9d9611be8055919fd8ba
    132.60KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-Mimikatz.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3da065e07b990034e9db78421672f70b63aa5329
    SHA256: ebf54f745dc81e1958f75e4ca91dd0ab989fc9787bb6b0bf993e2f51d9a2a5bb
    2.10MB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-CredentialInjection.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7343ec8549dca37f7b5310d5973e62a9d7ec4121
    SHA256: 7de9b5e764eaab1cb9b343f784c95b81d294ed754da7608411e8e78777803d96
    442.91KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-ReflectivePEInjection.ps1

    /tradecraftlabs/fhlbc/PowerSploit/CodeExecution/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e104ea8908a0c21f245b629dc075ad1dbdea364d
    SHA256: c81d0073c92d0b4d0cc66a4c1d64d4ca2afbe56d78eb9d9611be8055919fd8ba
    132.60KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-NinjaCopy.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a5b7f082fe0c36b3b6dd8035a22c1955b81e8cc9
    SHA256: b52821c6061d244f4c197e78636317b122972e7abed2892ecc7c713f24f866be
    433.24KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-Mimikatz.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3da065e07b990034e9db78421672f70b63aa5329
    SHA256: ebf54f745dc81e1958f75e4ca91dd0ab989fc9787bb6b0bf993e2f51d9a2a5bb
    2.10MB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-CredentialInjection.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7343ec8549dca37f7b5310d5973e62a9d7ec4121
    SHA256: 7de9b5e764eaab1cb9b343f784c95b81d294ed754da7608411e8e78777803d96
    442.91KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-ReflectivePEInjection.ps1

    /fhlbc/PowerSploit/CodeExecution/

    ·

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e104ea8908a0c21f245b629dc075ad1dbdea364d
    SHA256: c81d0073c92d0b4d0cc66a4c1d64d4ca2afbe56d78eb9d9611be8055919fd8ba
    132.60KB
    2019-11-14 03:16:31 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC