File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • allthethings.ddns.net · virussign.com_20250608_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Hunting_Rule_ShikataGaNai From Florian Roth by Steven Miller
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 65baa1fe641afc8e4f0b850a2c1c94a84a68776a
    SHA256: b23834d873f502af5d11f4e1291ed10a703de04d017a1aa70aed4149eea04c1f
    application/zip
    65.03MB
    2025-06-08 16:05:27 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250619_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: c6eaf883875402ca2b5c7e983b9a4539bc48ec18
    SHA256: cf8b4a961c8f0c0ad20b38523c404dbe6c2032d4d5b779615cde57a528e71cf6
    application/zip
    10.32MB
    2025-06-19 16:05:14 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250602_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 00925122515312713ff5b182a92ecaa8fe340fa3
    SHA256: 9ce8e9e1d506218a990ad50aa419df91c3ef51885d77bf451cb2360266ae9a98
    application/zip
    26.13MB
    2025-06-02 16:05:22 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250608_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Hunting_Rule_ShikataGaNai From Florian Roth by Steven Miller
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 65baa1fe641afc8e4f0b850a2c1c94a84a68776a
    SHA256: b23834d873f502af5d11f4e1291ed10a703de04d017a1aa70aed4149eea04c1f
    application/zip
    65.03MB
    2025-06-08 16:05:27 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250602_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 00925122515312713ff5b182a92ecaa8fe340fa3
    SHA256: 9ce8e9e1d506218a990ad50aa419df91c3ef51885d77bf451cb2360266ae9a98
    application/zip
    26.13MB
    2025-06-02 16:05:22 +0000 UTC

  • 5.45.102.182 · virussign.com_20250619_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: c6eaf883875402ca2b5c7e983b9a4539bc48ec18
    SHA256: cf8b4a961c8f0c0ad20b38523c404dbe6c2032d4d5b779615cde57a528e71cf6
    application/zip
    10.32MB
    2025-06-19 16:05:14 +0000 UTC

  • 5.45.102.182 · virussign.com_20250608_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Hunting_Rule_ShikataGaNai From Florian Roth by Steven Miller
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 65baa1fe641afc8e4f0b850a2c1c94a84a68776a
    SHA256: b23834d873f502af5d11f4e1291ed10a703de04d017a1aa70aed4149eea04c1f
    application/zip
    65.03MB
    2025-06-08 16:05:27 +0000 UTC

  • 5.45.102.182 · virussign.com_20250602_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 00925122515312713ff5b182a92ecaa8fe340fa3
    SHA256: 9ce8e9e1d506218a990ad50aa419df91c3ef51885d77bf451cb2360266ae9a98
    application/zip
    26.13MB
    2025-06-02 16:05:22 +0000 UTC

  • 5.45.102.182 · virussign.com_20250619_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: c6eaf883875402ca2b5c7e983b9a4539bc48ec18
    SHA256: cf8b4a961c8f0c0ad20b38523c404dbe6c2032d4d5b779615cde57a528e71cf6
    application/zip
    10.32MB
    2025-06-19 16:05:14 +0000 UTC

  • 5.45.102.182 · virussign.com_20250608_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Hunting_Rule_ShikataGaNai From Florian Roth by Steven Miller
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 65baa1fe641afc8e4f0b850a2c1c94a84a68776a
    SHA256: b23834d873f502af5d11f4e1291ed10a703de04d017a1aa70aed4149eea04c1f
    application/zip
    65.03MB
    2025-06-08 16:05:27 +0000 UTC

  • 5.45.102.182 · virussign.com_20250602_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 00925122515312713ff5b182a92ecaa8fe340fa3
    SHA256: 9ce8e9e1d506218a990ad50aa419df91c3ef51885d77bf451cb2360266ae9a98
    application/zip
    26.13MB
    2025-06-02 16:05:22 +0000 UTC

  • pypi.hadiko.de · workbench-0.3.2.tar.gz

    /packages/0c/4e/6d3ad2534e60fad14d8f837c2c1a3f1657f2b4aff8a589b3519c2a448dc3/

    Germany · Universitaet Stuttgart

    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_RLPack From AlienVault by ditekSHen
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Download archived sample
    The password is "infected"

    SHA1: 2635fd0b6ec8accd110ec13ee4600189aa9a6f19
    SHA256: 30aecf5ecb61fdeab5ea92a25fae265aea6c48a85b145cd4c4b8bfae44de42c4
    application/x-gzip
    8.72MB
    2014-08-29 21:59:03 +0000 UTC