File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 5.45.102.182 · virussign.com_20250823_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_ConfuserEx From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 70e1b2224ea2241362bbdc298618324d012c0e98
    SHA256: db9f00ec04537fb52566c85244bab8f8116bfb41c7794e70a33a959c9c5624ee
    application/zip
    11.16MB
    2025-08-23 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20250525_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara APT_NK_Methodology_Artificial_UserAgent_IE_Win7 From Florian Roth by Steve Miller aka @stvemillertime
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: 8d77fcda74b48347c40fddc3d699665334e0e9f8
    SHA256: 654179176a9af1a55c3b1edab9e2ba13966c471483dd568fba3b161e5c3e633e
    application/zip
    22.69MB
    2025-05-25 16:05:23 +0000 UTC

  • 5.45.102.182 · virussign.com_20250525_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara APT_NK_Methodology_Artificial_UserAgent_IE_Win7 From Florian Roth by Steve Miller aka @stvemillertime
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: 8d77fcda74b48347c40fddc3d699665334e0e9f8
    SHA256: 654179176a9af1a55c3b1edab9e2ba13966c471483dd568fba3b161e5c3e633e
    application/zip
    22.69MB
    2025-05-25 16:05:23 +0000 UTC

  • pypi.hadiko.de · workbench-0.3.2.tar.gz

    /packages/0c/4e/6d3ad2534e60fad14d8f837c2c1a3f1657f2b4aff8a589b3519c2a448dc3/

    Germany · Universitaet Stuttgart

    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_RLPack From AlienVault by ditekSHen
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Download archived sample
    The password is "infected"

    SHA1: 2635fd0b6ec8accd110ec13ee4600189aa9a6f19
    SHA256: 30aecf5ecb61fdeab5ea92a25fae265aea6c48a85b145cd4c4b8bfae44de42c4
    application/x-gzip
    8.72MB
    2014-08-29 21:59:03 +0000 UTC

  • 119.6.110.83 · tftpd64_v4.64.zip

    /

    China · CHINA UNICOM China169 Backbone

    Yara INDICATOR_EXE_Packed_eXPressor From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: f96fe60a1848e90e67f1222eb13558d203d4a1a7
    SHA256: 2c120739f729286cc34d1e245c143ed1611acd1f94892169099c6410f169a226
    application/zip
    639.62KB
    2022-09-20 17:37:11 +0000 UTC