File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • files.liyanfeng.com · MS_ToolKit_2.6.2(New Support Server2016).zip

    /

    Canada · Rica Web Services

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 76f7e21bf01dbe9ceb83cc04530c88355f897688
    SHA256: 987d482cf0ef50197ebb154791aa461ef1d6d19fcbbd094c52b326a1bc8b8ae8
    application/zip
    55.55MB
    2018-03-28 16:18:59 +0000 UTC

  • files.liyanfeng.com · MS Toolkit_2.6.zip

    /

    Canada · Rica Web Services

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: bea031d63055376136d29075751609a747fc0d54
    SHA256: 8f1075f5eb65f165a1f158d62b162eb620d349c78a7a27f333ada1f6b364a4f4
    application/zip
    53.66MB
    2017-03-08 08:30:59 +0000 UTC

  • www.betersys.nl · BeterSys.zip

    /update64/

    Germany · Hetzner Online GmbH

    Yara INDICATOR_EXE_Packed_Dotfuscator From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 674783e03a39cf483f0b6d68a1776a48609ad360
    SHA256: f89827810b797cb7c52a2890fdb3c8c31b711b89564a73bc6b8445ec915d4f21
    application/zip
    51.36MB
    2026-02-02 12:28:08 +0000 UTC

  • betersys.nl · BeterSys.zip

    /update64/

    Germany · Hetzner Online GmbH

    Yara INDICATOR_EXE_Packed_Dotfuscator From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 674783e03a39cf483f0b6d68a1776a48609ad360
    SHA256: f89827810b797cb7c52a2890fdb3c8c31b711b89564a73bc6b8445ec915d4f21
    application/zip
    51.36MB
    2026-02-02 12:28:08 +0000 UTC

  • zsirmo.hu · Microsoft Toolkit.exe

    /winloader/

    Hungary · Deninet KFT

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c4de105bc0d4debf2eab7563fc3127f6677a43c3
    SHA256: 3d5bf21c0f5b37ae78ef8c685d31f72d9d894daf4fa4e11870fb1ac5b7ce9047
    application/x-msdos-program
    54.55MB
    2018-03-20 11:59:41 +0000 UTC

  • www.zsirmo.hu · Microsoft Toolkit.exe

    /winloader/

    Hungary · Deninet KFT

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c4de105bc0d4debf2eab7563fc3127f6677a43c3
    SHA256: 3d5bf21c0f5b37ae78ef8c685d31f72d9d894daf4fa4e11870fb1ac5b7ce9047
    application/x-msdos-program
    54.55MB
    2018-03-20 11:59:41 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · Pre-Install.exe

    /torrents/IObit Smart Defrag Pro 10.3.0.435/

    United States · Cloudflare, Inc.

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: fb033c5f82ab12881fb632fba7944bc48acb4632
    SHA256: d80942b5254fe06628c9f4b75a75276e45f64e5e666d2d9f7237d9439c220f17
    application/octet-stream
    1.64MB
    2025-11-05 16:13:47 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · Pre-Install.exe

    /torrents/IObit Smart Defrag Pro 10.3.0.435/

    United States · Cloudflare, Inc.

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: fb033c5f82ab12881fb632fba7944bc48acb4632
    SHA256: d80942b5254fe06628c9f4b75a75276e45f64e5e666d2d9f7237d9439c220f17
    application/octet-stream
    1.64MB
    2025-11-05 16:13:47 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · ScreenConnectVersions.zip

    /files/

    United Kingdom ·

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen

    SHA1: 55961f0eae5d63ef424b070955dd6913839fd908
    SHA256: ebc9b659ecdc303e15e9df3d25493bdf55b3a5fec550af05b4cb4e3a02a4bac8
    application/zip
    6.03GB
    2025-12-04 20:53:02 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · ScreenConnectVersions.zip

    /files/

    United Kingdom ·

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen

    SHA1: 1e2cf150a697f61477dc894a34d932c084bd2c3f
    SHA256: 489df9feb4ab3445e3780af20db09eecbe174c6c70643f123415f6203cd88b2f
    application/zip
    6.03GB
    2025-12-04 20:53:02 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · ScreenConnect Patcher V3.exe

    /files/

    United Kingdom ·

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 172c2099eb6459e9a31ed1a6abbadf84541cd255
    SHA256: 61fe6cc6710a8d2c605883134afbd61705ea0d0f1cecd71d6fe04b152f2703c9
    application/octet-stream
    809.00KB
    2025-11-28 17:47:01 +0000 UTC

  • vwykayte2015db5y0kdhlgslj9p7cfwzn0ydaiwiesw7f4agx84o14r0f2gmncb.pp.ua · ScreenConnect Patcher V3.exe

    /files/

    United Kingdom ·

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 172c2099eb6459e9a31ed1a6abbadf84541cd255
    SHA256: 61fe6cc6710a8d2c605883134afbd61705ea0d0f1cecd71d6fe04b152f2703c9
    application/octet-stream
    809.00KB
    2025-11-28 17:47:01 +0000 UTC

  • www.migueltimana.swgoodidea.com · Activadores.zip

    /installers/

    United States · HostDime.com, Inc.

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 1c80cb21a2bf0b24e3297cb83d32135bf5ee8e49
    SHA256: f1455424d3227d5a8966315494e2d3574f66406f2eda50ced3f770b98429cd80
    application/zip
    62.11MB
    2022-07-15 04:34:54 +0000 UTC

  • migueltimana.swgoodidea.com · Activadores.zip

    /installers/

    United States · HostDime.com, Inc.

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: b59c1fbec2e70eafce8701527601f4ea3db26b66
    SHA256: 0bd5479aa73f39f62f36e6c9b1568831753d3ecd9935204952868569e195cebb
    application/zip
    62.11MB
    2022-07-15 04:34:54 +0000 UTC

  • programas-vps.uwhosting.com.br · 22621.1555.zip

    /

    Canada · OVH SAS

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 341fc6770e732a7b4f857fc4c60bcc73838d905c
    SHA256: 3f06431a2f55fe3f80088f51f577096451a42c719c2491e000ca26d73ed9796f
    application/zip
    15.81MB
    2023-05-11 18:27:30 +0000 UTC

  • www.sousol.antipod.es · Activation_v2.6.4.exe

    /ISOs/

    France · OVH SAS

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: d5f920158dd9c0a02544ca38634b25e729cc96a9
    SHA256: 1367e82a9fef9c1d2ffdf9b58a9348da3dda8f52c5e4a2df562d77978635e951
    application/x-msdownload
    56.65MB
    2020-10-19 18:35:05 +0000 UTC

  • sousol.antipod.es · Activation_v2.6.4.exe

    /ISOs/

    France · OVH SAS

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: d5f920158dd9c0a02544ca38634b25e729cc96a9
    SHA256: 1367e82a9fef9c1d2ffdf9b58a9348da3dda8f52c5e4a2df562d77978635e951
    application/x-msdownload
    56.65MB
    2020-10-19 18:35:05 +0000 UTC

  • mail.reveantivirus.com · Malware Samples.zip

    /reveantivirus.com/linux/Builds/Abhishek_Samples/

    United States · IO INC

    Yara INDICATOR_EXE_Packed_Dotfuscator From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara INDICATOR_EXE_Packed_ConfuserEx From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_Fody From AlienVault by ditekSHen
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara detect_Redline_Stealer From AbuseCH by Varp0s
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara INDICATOR_EXE_Packed_RLPack From AlienVault by ditekSHen
    Yara Win32_Ransomware_WannaCry From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Yara Nanocore_RAT_Gen_2 From Florian Roth by Florian Roth (Nextron Systems)
    Yara IronTiger_Gh0stRAT_variant From Florian Roth by Cyber Safety Solutions, Trend Micro
    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_AgileDotNet From AlienVault by ditekSHen

    SHA1: 858628631c3c3f4ecf2e514fcabed03e8eaae303
    SHA256: ee1c69393d43294561be4c725c1cd98217e77b9e0b7dbc769824ea2b042dba63
    application/zip
    1.29GB
    2018-06-21 08:03:32 +0000 UTC

  • mail.reveantivirus.com · Malware Samples.zip

    /reveantivirus.com/linux/Builds/Abhishek_Samples/

    United States · IO INC

    Yara INDICATOR_EXE_Packed_Dotfuscator From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara INDICATOR_EXE_Packed_ConfuserEx From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_Fody From AlienVault by ditekSHen
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara detect_Redline_Stealer From AbuseCH by Varp0s
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara INDICATOR_EXE_Packed_RLPack From AlienVault by ditekSHen
    Yara Win32_Ransomware_WannaCry From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Yara Nanocore_RAT_Gen_2 From Florian Roth by Florian Roth (Nextron Systems)
    Yara IronTiger_Gh0stRAT_variant From Florian Roth by Cyber Safety Solutions, Trend Micro
    Yara INDICATOR_EXE_DotNET_Encrypted From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_AgileDotNet From AlienVault by ditekSHen
    Yara SUSP_NET_NAME_ConfuserEx From Florian Roth by Arnim Rupp
    Yara IMPLANT_4_v7 From Florian Roth by US CERT
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen

    SHA1: a88dda25ca0eae844a037284a09b438a96de2a5f
    SHA256: e097bd556396adafb3270f86d11704556de2e951f6b2379e2feff21f26f0eb3e
    application/zip
    1.29GB
    2018-06-21 08:03:32 +0000 UTC

  • pub.julienth37.fr · WiNToBootic.exe

    /fichiers-sites/Tutoriels/Windows7/AIO/

    France · Free SAS

    Yara INDICATOR_EXE_Packed_SmartAssembly From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 5190a27f99c90c82617c83e1d1b77974f8c6a6b0
    SHA256: c8b53d7d44f841eeeaf9ce26f3c2ddbfa6ca9681e0b470e36eacd09aedf5d64d
    application/x-msdos-program
    865.00KB
    2015-11-24 08:29:34 +0000 UTC