File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • dllcodacker.ir · TheFatRat.zip

    //tools/

    Iran · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.)

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Empire_PowerShell_Framework_Gen1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara APT_APT29_Win_FlipFlop_LDR From Florian Roth by threatintel@volexity.com
    Yara CobaltStrike_Unmodifed_Beacon From Florian Roth by yara@s3c.za.net
    Yara Empire_Invoke_MetasploitPayload From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_ShellcodeMSIL From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_DllInjection From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Install_SSP From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_SecurityPackages From Florian Roth by Florian Roth (Nextron Systems)
    Yara Mimikatz_Memory_Rule_1 From Florian Roth by Florian Roth
    Yara Empire_Invoke_Portscan_Gen From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_SMBAutoBrute From Florian Roth by Florian Roth (Nextron Systems)
    Yara Invoke_SMBExec_Invoke_WMIExec_1 From Florian Roth by Florian Roth (Nextron Systems)
    Yara TA17_293A_malware_1 From Florian Roth by US-CERT Code Analysis Team (modified by Florian Roth)
    Yara Empire_Invoke_SSHCommand From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PsExec From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_GPPPassword From Florian Roth by Florian Roth (Nextron Systems)
    Yara p0wnedPotato From Florian Roth by Florian Roth (Nextron Systems)
    Yara NTLM_Dump_Output From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_dumpCredStore From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_PS1_PowerCat_Mar21 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_KeePassConfig From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Get_Keystrokes From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Out_Minidump From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_JBoss From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Exploit_Jenkins From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_PostExfil From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_Invoke_EgressCheck From Florian Roth by Florian Roth (Nextron Systems)
    Yara HKTL_NET_GUID_UnmanagedPowerShell From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)

    SHA1: b6232e9e30b76932e1d4e88f40889b040f19d5b8
    SHA256: d1c3f8766bf523a6e0ffa23c663b2bd486e27d85abd02a1d410ad603eb6683c7
    application/zip
    1.35GB
    2025-10-09 10:30:36 +0000 UTC

  • filestore.fes.org.ua · 6.1 09-shellcode-reflective-dll-injection.zip

    /video_docs/Udemy - Malware Development 2 Advanced Injection and API Hooking 2021-10/9. Reflective Loading Trojans/

    Ukraine · Cosmonova LLC

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: 80fc0b7a4b49c9a09cfc6a8ee4ecd482588780a9
    SHA256: 527a6b42ddadab4cc66556a98ceea4697e3d8adc4508f5fe9699f9e8ac1ec4b5
    application/zip
    292.83KB
    2021-10-16 19:13:45 +0000 UTC

  • files.cavite.eu · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • teste.office-m66.info · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • files.bfa.ae · PowerUpSQL.ps1

    /

    United States · MICROSOFT-CORP-MSN-AS-BLOCK

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c269162d5e6ff66a20cec50a16a7bafaf80c813b
    SHA256: 7a34fcb1fde516f523941549830ff80443a555dd64346f5b773ede24847207d6
    1.20MB
    2025-07-28 15:50:01 +0000 UTC

  • de.freedif.org · veil_3.1.14.orig.tar.gz

    /kali/pool/main/v/veil/

    Singapore · MyRepublic Ltd.

    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Download archived sample
    The password is "infected"

    SHA1: 4194b4dd8935652fb31d19544271e5cc879f50eb
    SHA256: 18ec21d1ba7e730b83bc8ff097d219bf8eb0d1c116859101767991484471a8f4
    application/x-gzip
    194.64KB
    2020-04-23 13:18:22 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.7.0.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3d7c344747c40c8eba779aff058c1dc397f16e26
    SHA256: 6f3c7b669c87b204b9132ed0268a3624c0e5646a8e2501716136f34ed3e42c44
    application/octet-stream
    3.19MB
    2016-01-04 13:30:02 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.7.0.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3d7c344747c40c8eba779aff058c1dc397f16e26
    SHA256: 6f3c7b669c87b204b9132ed0268a3624c0e5646a8e2501716136f34ed3e42c44
    application/octet-stream
    3.19MB
    2016-01-04 13:30:02 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.6.1+0~git1451447247.ce01d9.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d9186423b1d10045a5ecccc37fa3119a022b59a8
    SHA256: b84d17bc8df78efdd6eb46bff08d5240dd06e36b7b009ce69fde9360908a5832
    application/octet-stream
    3.21MB
    2015-12-30 03:59:07 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.6.1+0~git1451447247.ce01d9.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d9186423b1d10045a5ecccc37fa3119a022b59a8
    SHA256: b84d17bc8df78efdd6eb46bff08d5240dd06e36b7b009ce69fde9360908a5832
    application/octet-stream
    3.21MB
    2015-12-30 03:59:07 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.7.1.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 351b3ece1bf1b85c13b1c96a1a3986a87ba09416
    SHA256: ed4b89cdebc312bf96f32faf6a664b138f6fc6f96e18642e2742c0bb25820de3
    application/octet-stream
    4.44MB
    2019-03-07 14:00:20 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.7.0.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3d7c344747c40c8eba779aff058c1dc397f16e26
    SHA256: 6f3c7b669c87b204b9132ed0268a3624c0e5646a8e2501716136f34ed3e42c44
    application/octet-stream
    3.19MB
    2016-01-04 13:30:02 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.7.0.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3d7c344747c40c8eba779aff058c1dc397f16e26
    SHA256: 6f3c7b669c87b204b9132ed0268a3624c0e5646a8e2501716136f34ed3e42c44
    application/octet-stream
    3.19MB
    2016-01-04 13:30:02 +0000 UTC

  • kali.mirror.gtcomm.net · beef-xss_0.4.6.1+0~git1451447247.ce01d9.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d9186423b1d10045a5ecccc37fa3119a022b59a8
    SHA256: b84d17bc8df78efdd6eb46bff08d5240dd06e36b7b009ce69fde9360908a5832
    application/octet-stream
    3.21MB
    2015-12-30 03:59:07 +0000 UTC

  • kali.mirror.globo.tech · beef-xss_0.4.6.1+0~git1451447247.ce01d9.orig.tar.gz

    /kali/pool/main/b/beef-xss/

    Canada · GTCOMM

    Yara CobaltStrike_C2_Host_Indicator From Florian Roth by yara@s3c.za.net
    Yara Empire_PowerShell_Framework_Gen4 From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_PowerShell_IEX_Download_Combo From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_shellpop_Bash From Florian Roth by Tobias Michalski
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara WebShell__findsock_php_findsock_shell_php_reverse_shell From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d9186423b1d10045a5ecccc37fa3119a022b59a8
    SHA256: b84d17bc8df78efdd6eb46bff08d5240dd06e36b7b009ce69fde9360908a5832
    application/octet-stream
    3.21MB
    2015-12-30 03:59:07 +0000 UTC