File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 74.121.0.115 · MM-Client.exe

    /pub/sample-files/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c7b3825fb926d80a4715325e22355dd8e1f81aa3
    SHA256: 61e9be901f1047d1e040856a90806edae05b6c485c955abb5454359098fcd52c
    application/x-msdos-program
    4.02MB
    2020-03-30 20:32:19 +0000 UTC

  • 49.13.241.77 · DisinstallaLauncherPrecedente.exe

    /Q-Launcher/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: dcd500c9600bc0b876eecd03b1c5aa7df2929e1e
    SHA256: 9c185b76af0f000758b1d070321b6402d79e0860caee4b94f4a10476f3594da9
    application/x-msdos-program
    59.42MB
    2025-03-31 07:48:01 +0000 UTC

  • 192.47.67.205 · Web21(Ver5.0.0).zip

    /web21_download/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen

    SHA1: 3aeee915dd7ed82fdb3e732c147f2d6cd216b43c
    SHA256: 3c2e5904ff7987bd15b3860a36a11ddeb646019ec4fe750296fa907de6dba7e3
    application/zip
    384.90MB
    2024-08-14 06:24:43 +0000 UTC

  • 74.121.0.115 · MM-Client.exe

    /pub/sample-files/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c7b3825fb926d80a4715325e22355dd8e1f81aa3
    SHA256: 61e9be901f1047d1e040856a90806edae05b6c485c955abb5454359098fcd52c
    application/x-msdos-program
    4.02MB
    2020-03-30 20:32:19 +0000 UTC

  • 218.155.220.108 · 해체안심ON.exe

    /building-demolition/src/DemolitionPlanApp/bin/Release/net8.0-windows/win-x64/publish/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen

    SHA1: 04c4864bef04b920479c7c98b27af2426dadef4c
    SHA256: 9497275cc61fb5e61b708dc40a599cf92cc379c716429f3a10c7d8cf8fd583c2
    application/x-msdownload
    153.14MB
    2026-01-23 07:09:09 +0000 UTC

  • 193.38.55.230 · IPBan-Windows-x86_2_0_1.zip

    /

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: f69c07e4bedb9015527fdb3f91db66998db2e3d5
    SHA256: c2a3872602d2c6fe28a148943c8b0404bbde64bd73aefccce6744dd2be6696e8
    application/zip
    11.68MB
    2025-01-23 20:31:51 +0000 UTC

  • 218.155.220.108 · 해체안심ON_Start.exe

    /building-demolition/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen

    SHA1: 6d963269d1ea92667dccd1eebf8879cb3c3292fc
    SHA256: 1cd6b0c0701aae167c50de7f1cc312e2b240cdb97a4def171309d22975c604ff
    application/x-msdownload
    153.13MB
    2026-01-23 04:48:31 +0000 UTC

  • 189.72.213.249 · ScreenPresso_1.8.5.0.zip

    /softwares/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 9012009bccbabd21868a4d51955144069849bd9d
    SHA256: fc8c739365fddea0702237bce9d7ba924b9461067072455f2cb4e3af1d267682
    application/zip
    8.17MB
    2024-12-05 12:43:50 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.20.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: d2d3ee1ee021ce3dd167aee23f61467670244266
    SHA256: 39b268e0e51f3ae38c0791d145cf6b6055386ec852c62c90b2fed00c6b1a4919
    application/zip
    98.10MB
    2025-09-17 08:41:28 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.17.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 5c1585a68faa1d6c99a7af7801749397946841d2
    SHA256: 65918698793333778f91636d3d4d8043231c44e85e382c539a41643513867bc1
    application/zip
    98.06MB
    2025-04-07 11:56:46 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.15.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 9a26d7f9391cb2b78164821f779a183236039c8f
    SHA256: fa6b786c3a0560fc119f8341c190e3dbf172f92b415d36899d541ee8f1513241
    application/zip
    96.88MB
    2024-12-27 09:50:02 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.14.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 87726d12c536027ce04fba3afd55af6e6c9baa6a
    SHA256: 8819df1e76f58f63df4c11e38548d42eeb050c3836b2ebb5aee00a771daac002
    application/zip
    96.88MB
    2024-12-18 12:05:02 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.13.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 61faf1f63f6e35764f955f103c62db8ec5fe3a3c
    SHA256: f664126b737f58d7dc79704191d6e170988a8c576b3438a56acef4d4bc1f9eaf
    application/zip
    96.88MB
    2024-12-17 13:51:23 +0000 UTC

  • 134.122.69.207 · LdapConnectChecker.zip

    /hes/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 2234a0d7dbab7fb0a1b4406d61dc3d15c523054d
    SHA256: dae106816f0f0b82f112902ecd12608ade395c1cb05b42ae5ef3a59fda6fab03
    application/zip
    27.80MB
    2024-09-04 13:15:53 +0000 UTC

  • 134.122.69.207 · windows_x64_latest.zip

    /hes/ipi/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 2980e58032a6b82a24c23de11d4611a37f9bd273
    SHA256: 7fc1d49578b01cf3b96252d1e071f0ba655cd283f59fec0753a84cf3269eddf0
    application/zip
    98.10MB
    2025-09-17 08:41:53 +0000 UTC

  • 134.122.69.207 · windows_x64_3.16.20.zip

    /hes/ipi/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: bb72dfae79bb19ec91e6f7dda18035f4d4475296
    SHA256: 72ec751c4b2dbf5a0fe8c747634fd41f9799987ca60dc5369bad132acc9c4a03
    application/zip
    98.10MB
    2025-09-17 08:41:53 +0000 UTC

  • 192.47.67.205 · Web21(Ver5.0.0).zip

    /web21_download/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Yara detect_Redline_Stealer From AbuseCH by Varp0s

    SHA1: 98b8314403b6a13cac2b4eac811c0fc168a00e9d
    SHA256: c971568a3c0afef558d11716e0913f65ae8444b72b8faaed607c3b3bb31fa7d7
    application/zip
    384.90MB
    2024-08-14 06:24:43 +0000 UTC

  • 109.169.81.85 · AgenTrak - Uninstall Files.zip

    /

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 784ca8376b02d2caa20a2dd7f96f11d41ac9ebbc
    SHA256: f1fd8ade996280df549b420948ac6e1f719c2844d3aaf4d254c52ecd6047a860
    application/zip
    76.82MB
    2025-03-07 17:17:27 +0000 UTC

  • 167.86.113.140 · 1.2.6.zip

    /update/EdenChronicles/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen

    SHA1: a15e67794d99f1be08791acafd676d40850a2180
    SHA256: 5a31b23f0664270052ca21e0f01f016841fdff60a3351b4a3c540fa33540a629
    application/zip
    149.57MB
    2025-12-10 17:51:19 +0000 UTC

  • 43.160.253.26 · OPC.exe

    /OPC/DE_YOU/

    ·

    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen

    SHA1: 3e6a57f71f5f5af9a383e1fa650e734a47fad159
    SHA256: 9aba0d511c1a6b49f0bb0bbfb88b81c02cf94862e33439f25d1e8152bb04bc0b
    application/octet-stream
    122.48MB
    2026-01-04 12:42:55 +0000 UTC