File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 167.71.178.92 · Get-System.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Privesc/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: b1eb88cd2d4d53adbd593081e4c37ca243ecca59
    SHA256: 795edc88ad1f89b9218fd03d0b48b3f5e9780d61c1919d47b554dbffb99424af
    25.86KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-TokenManipulation.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 9e73086c698c522b47719d567aa14003320ef521
    SHA256: 069e5cecdd18e8ff73c434cc6508d60ac5ba8396855446832ec3f55334945c71
    92.48KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Get-MicrophoneAudio.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c607f9d0bd55e882b8baf6d1b7b43cb63793a5f5
    SHA256: a123b3edcfe9793541904aa85a0abc650631c2992306b83b103afdb2527bb90d
    7.19KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Get-System.ps1

    /fhlbc/PowerSploit/Privesc/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: b1eb88cd2d4d53adbd593081e4c37ca243ecca59
    SHA256: 795edc88ad1f89b9218fd03d0b48b3f5e9780d61c1919d47b554dbffb99424af
    25.86KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-TokenManipulation.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 9e73086c698c522b47719d567aa14003320ef521
    SHA256: 069e5cecdd18e8ff73c434cc6508d60ac5ba8396855446832ec3f55334945c71
    92.48KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Get-MicrophoneAudio.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c607f9d0bd55e882b8baf6d1b7b43cb63793a5f5
    SHA256: a123b3edcfe9793541904aa85a0abc650631c2992306b83b103afdb2527bb90d
    7.19KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Get-System.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Privesc/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: b1eb88cd2d4d53adbd593081e4c37ca243ecca59
    SHA256: 795edc88ad1f89b9218fd03d0b48b3f5e9780d61c1919d47b554dbffb99424af
    25.86KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Invoke-TokenManipulation.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 9e73086c698c522b47719d567aa14003320ef521
    SHA256: 069e5cecdd18e8ff73c434cc6508d60ac5ba8396855446832ec3f55334945c71
    92.48KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Get-MicrophoneAudio.ps1

    /tradecraftlabs/fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c607f9d0bd55e882b8baf6d1b7b43cb63793a5f5
    SHA256: a123b3edcfe9793541904aa85a0abc650631c2992306b83b103afdb2527bb90d
    7.19KB
    2019-10-23 16:02:07 +0000 UTC

  • 167.71.178.92 · Get-System.ps1

    /fhlbc/PowerSploit/Privesc/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: b1eb88cd2d4d53adbd593081e4c37ca243ecca59
    SHA256: 795edc88ad1f89b9218fd03d0b48b3f5e9780d61c1919d47b554dbffb99424af
    25.86KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Invoke-TokenManipulation.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 9e73086c698c522b47719d567aa14003320ef521
    SHA256: 069e5cecdd18e8ff73c434cc6508d60ac5ba8396855446832ec3f55334945c71
    92.48KB
    2019-11-14 03:16:31 +0000 UTC

  • 167.71.178.92 · Get-MicrophoneAudio.ps1

    /fhlbc/PowerSploit/Exfiltration/

    ·

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c607f9d0bd55e882b8baf6d1b7b43cb63793a5f5
    SHA256: a123b3edcfe9793541904aa85a0abc650631c2992306b83b103afdb2527bb90d
    7.19KB
    2019-11-14 03:16:31 +0000 UTC

  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • filestore.fes.org.ua · 6.1 09-shellcode-reflective-dll-injection.zip

    /video_docs/Udemy - Malware Development 2 Advanced Injection and API Hooking 2021-10/9. Reflective Loading Trojans/

    Ukraine · Cosmonova LLC

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: 80fc0b7a4b49c9a09cfc6a8ee4ecd482588780a9
    SHA256: 527a6b42ddadab4cc66556a98ceea4697e3d8adc4508f5fe9699f9e8ac1ec4b5
    application/zip
    292.83KB
    2021-10-16 19:13:45 +0000 UTC

  • files.cavite.eu · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • teste.office-m66.info · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • files.bfa.ae · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • de.freedif.org · veil_3.1.14.orig.tar.gz

    /kali/pool/main/v/veil/

    Singapore · MyRepublic Ltd.

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: 4194b4dd8935652fb31d19544271e5cc879f50eb
    SHA256: 18ec21d1ba7e730b83bc8ff097d219bf8eb0d1c116859101767991484471a8f4
    application/x-gzip
    194.64KB
    2020-04-23 13:18:22 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC