File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r1.apk

    /pub/alpine/v3.6/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 87125b2885c2ed731e9ced1c6d01d4221ca3c8b5
    SHA256: 8bdb0644410c8b347cdc066a2012b5443179657e87e2f64afdcadf453bf4722d
    application/octet-stream
    1.07MB
    2017-05-16 07:21:05 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r1.apk

    /pub/alpine/v3.6/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 87125b2885c2ed731e9ced1c6d01d4221ca3c8b5
    SHA256: 8bdb0644410c8b347cdc066a2012b5443179657e87e2f64afdcadf453bf4722d
    application/octet-stream
    1.07MB
    2017-05-16 07:21:05 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • shares.integrate.com.mo · maimaidogz.ps1

    /Script/

    Macao · Companhia de Telecomunicacoes de Macau SARL

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 2748ed369c4cb2086da77efda37ab1b40fdffb2a
    SHA256: fdebde46d1f53b51edd4d0eb146fd1ced78af0f322d4c5a56bf8e5eabd9fb90c
    3.09MB
    2025-04-12 14:13:42 +0000 UTC

  • shares.integrate.com.mo · Updater.exe

    /Script/

    Macao · Companhia de Telecomunicacoes de Macau SARL

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 51c4c0cc4079dba8ddce58426d5cfa5fb1d72d6a
    SHA256: 0d3655e590f83979900d6667cfb705ee15f27982cdbca88ce90a6cac3fd6c2cd
    application/x-msdos-program
    3.12MB
    2025-04-12 16:28:39 +0000 UTC

  • 93.115.21.186 · Invoke-Mimikatz.ps1

    /

    The Netherlands · MVPS LTD

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3da065e07b990034e9db78421672f70b63aa5329
    SHA256: ebf54f745dc81e1958f75e4ca91dd0ab989fc9787bb6b0bf993e2f51d9a2a5bb
    2.10MB
    2025-06-20 21:33:21 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r2.apk

    /pub/alpine/v3.8/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 6f001765984049263b2c3b9df343a1bc0898e71e
    SHA256: cccdfeed581187b36744f9bd21bb8b73aa6cef5a727148d8394f4e894fdfcb9e
    application/octet-stream
    1.08MB
    2018-06-06 15:23:23 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r2.apk

    /pub/alpine/v3.8/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 6f001765984049263b2c3b9df343a1bc0898e71e
    SHA256: cccdfeed581187b36744f9bd21bb8b73aa6cef5a727148d8394f4e894fdfcb9e
    application/octet-stream
    1.08MB
    2018-06-06 15:23:23 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r2.apk

    /pub/alpine/v3.7/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a4d0bb3f07f9b9e0816437d3d18f438a74bdc877
    SHA256: 7aec08d5f68c53766e15810ecae8894192154efd6ad2b58df7a024e2bad2453e
    application/octet-stream
    1.08MB
    2017-11-01 06:13:58 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r2.apk

    /pub/alpine/v3.7/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a4d0bb3f07f9b9e0816437d3d18f438a74bdc877
    SHA256: 7aec08d5f68c53766e15810ecae8894192154efd6ad2b58df7a024e2bad2453e
    application/octet-stream
    1.08MB
    2017-11-01 06:13:58 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r1.apk

    /pub/alpine/v3.6/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 87125b2885c2ed731e9ced1c6d01d4221ca3c8b5
    SHA256: 8bdb0644410c8b347cdc066a2012b5443179657e87e2f64afdcadf453bf4722d
    application/octet-stream
    1.07MB
    2017-05-16 07:21:05 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.5-r1.apk

    /pub/alpine/v3.6/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 87125b2885c2ed731e9ced1c6d01d4221ca3c8b5
    SHA256: 8bdb0644410c8b347cdc066a2012b5443179657e87e2f64afdcadf453bf4722d
    application/octet-stream
    1.07MB
    2017-05-16 07:21:05 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • mirrors.gobler.net · crackmapexec-3.1.4-r1.apk

    /pub/alpine/v3.5/community/x86_64/

    Denmark · MH HOLDING AF 1. JUNI 2009 ApS

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 39a5019d2dee7898eefdbe074b929b4c2cb0f04d
    SHA256: 5d91c49dd26df971ed88cdb3b7006a1f888fdc5ab39523199e341c3abda54f06
    application/octet-stream
    1.07MB
    2016-11-02 10:17:15 +0000 UTC

  • shares.integrate.com.mo · maimaidogz.ps1

    /Script/

    Macao · Companhia de Telecomunicacoes de Macau SARL

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 2748ed369c4cb2086da77efda37ab1b40fdffb2a
    SHA256: fdebde46d1f53b51edd4d0eb146fd1ced78af0f322d4c5a56bf8e5eabd9fb90c
    3.09MB
    2025-04-12 14:13:42 +0000 UTC

  • shares.integrate.com.mo · Updater.exe

    /Script/

    Macao · Companhia de Telecomunicacoes de Macau SARL

    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 51c4c0cc4079dba8ddce58426d5cfa5fb1d72d6a
    SHA256: 0d3655e590f83979900d6667cfb705ee15f27982cdbca88ce90a6cac3fd6c2cd
    application/x-msdos-program
    3.12MB
    2025-04-12 16:28:39 +0000 UTC