File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • mv.ganzi.fun · maccms.zip

    /

    Japan · Alibaba US Technology Co., Ltd.

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3d1a3b736b70e08065f3e00531280172dfa073a8
    SHA256: 1df8e6937d8a81acb98d2efe799c502492279190ec3eec70edb77b2697c32496
    application/zip
    13.67MB
    2025-11-23 18:23:13 +0000 UTC

  • mv.ganzi.fun · maccms.zip

    /

    Japan · Alibaba US Technology Co., Ltd.

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 3dcd82d4076eb0893efa48805cb52ac6994fea9c
    SHA256: c669ef50d54a6b37c0fb231c7e87592e8af79065500c7c3debae081caeb227d1
    application/zip
    4.09MB
    2025-11-23 18:23:04 +0000 UTC

  • www.failed.icu · newsetup3.exe

    /

    The Netherlands · Play2go International Limited

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 0b2f39f957a36ad2e82a565b7413579ea412ebd7
    SHA256: 57d8c260268910d07a00b7b959f54973ed04307175608d05aeee07040e973f80
    application/octet-stream
    629.50KB
    2025-11-23 15:10:42 +0000 UTC

  • 149.56.25.74 · 08140602lsqg.apk.zip

    /geedge_jira/attachment/31108/

    Canada · OVH SAS

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: cd08b184370bc036b8b0d040eb882d877e0cc2c0
    SHA256: ec8bad2886433c8c15b5f2d58211896eb44963600d65bc4dcbf6136f037ab1fb
    application/zip
    47.55MB
    2015-10-21 00:00:00 +0000 UTC

  • 5.45.102.182 · virussign.com_20250909_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 219025b650bc309de34eb4b0bee537d5998261e1
    SHA256: f34cbc7b4984f055fcb1c396abb5cb9da64e0515a5e1a3db11054c6a0510f572
    application/zip
    20.05MB
    2025-09-09 16:05:18 +0000 UTC

  • 5.45.102.182 · virussign.com_20250902_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 24fa57b0bbcb5c146e66fe0fb85bb4ec659f2d19
    SHA256: 136aee57a53d52904643e091094ce267c540fe38f6ece836c44c27c9a1ce4943
    application/zip
    15.92MB
    2025-09-02 16:05:18 +0000 UTC

  • 5.45.102.182 · virussign.com_20250825_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 6dc439fb2bb6a2cc797554005bd1a9a35c49cca7
    SHA256: 723ea3a40d27505f1c470d1fd759dc30ec08d222a00591661bf1152d556ff270
    application/zip
    3.89MB
    2025-08-25 16:05:15 +0000 UTC

  • dd.2p.pw · Letstalk.apk

    /soft/

    Sweden · HOSTHATCH

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara CISA_10410305_01 From AlienVault

    SHA1: ece8606a3f42fa074270626f82599c0b14f2e3e5
    SHA256: 5de08e124534f28a8b2b27435ed939dd3aa53072e703a4ac300c6c2abdda1c87
    application/octet-stream
    242.79MB
    2023-08-05 02:13:58 +0000 UTC

  • www.wordpress2024.holisticschoolofmassage.com · ONE_TV_VIP___base.apk

    /apps/

    United States · WEBBYENT

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d7c3104a7d8e7d1f95610891c3f0a7342f378353
    SHA256: 3230182cabf8c9fb24ebe4a65e9856c8212c23daa9051300b1fda1d339252d57
    application/vnd.android.package-archive
    40.16MB
    2025-02-15 22:24:55 +0000 UTC

  • linox.bz · ONE_TV_VIP___base.apk

    /apps/

    United States · WEBBYENT

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a8dae150cc328ac2815159313327a8cbd94c5eca
    SHA256: 7b81774412301dd7469c40d055c2cab1746a842e85b9489fb89fe92752f54d28
    application/vnd.android.package-archive
    40.16MB
    2025-02-15 22:24:55 +0000 UTC

  • linox.bz · ONE_TV_VIP___base.apk

    /apps/

    United States · WEBBYENT

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7632670cfcfc361b242b7c1dca033e4a9f362f23
    SHA256: 0e5bff6ad1c72596bf198677406b8ef3ac59ef976bd64c0be609b6f88c421f36
    application/vnd.android.package-archive
    40.16MB
    2025-02-15 22:24:55 +0000 UTC

  • www.wordpress2024.holisticschoolofmassage.com · ONE_TV_VIP___base.apk

    /apps/

    United States · WEBBYENT

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 434f01151672867102d759b2a1da31f0951f425b
    SHA256: 6db05175993450d548128de253d01dc3375e31eb4a841689f002c2a375b672ee
    application/vnd.android.package-archive
    40.16MB
    2025-02-15 22:24:55 +0000 UTC

  • dd.2p.pw · Letstalk.apk

    /soft/

    Sweden · HOSTHATCH

    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)

    SHA1: fe774e928b8c2f230a45b6e0db81d7631e54faad
    SHA256: 25c885d9a6acd25d464eb586b35f223bfa4f2d72357a2d48bb3370fb87548de7
    application/octet-stream
    242.79MB
    2023-08-05 02:13:58 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250611_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c8dd02528aaa4f2b2489e053b95acf7703b77a50
    SHA256: 022613a0e2838dc693feed2ee2d7bcb2f8d0033a36f615f499cfc0396efcc959
    application/zip
    39.71MB
    2025-06-11 16:05:27 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250610_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara Base64_encoded_Executable From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 2364e048d2fc16b1cb22eb29bc2a485bb675af55
    SHA256: 73971a2062516be4850d4a708764a19a85794936f6d7e479d4d3ad887e84ca22
    application/zip
    60.84MB
    2025-06-10 16:05:27 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250608_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Hunting_Rule_ShikataGaNai From Florian Roth by Steven Miller
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_SimplePolyEngine From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 65baa1fe641afc8e4f0b850a2c1c94a84a68776a
    SHA256: b23834d873f502af5d11f4e1291ed10a703de04d017a1aa70aed4149eea04c1f
    application/zip
    65.03MB
    2025-06-08 16:05:27 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250605_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara Typical_Malware_String_Transforms From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 4b32c974690387bcdcdc7a975e2ddbef1c28f556
    SHA256: 4fcc38c844693ffa99b2bc51508fb8b92224704c88d8734628f4c1159d77fc1a
    application/zip
    20.08MB
    2025-06-05 16:05:20 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250604_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_MEW From AlienVault by ditekSHen
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 950f0e4dbe5a9cbf174d31b3f5ff07db48d51a88
    SHA256: 71e046942745d9d24d63f72dd3afff31caece0371bc2e3234dd05451e708da8a
    application/zip
    46.55MB
    2025-06-04 16:05:24 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250618_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara PUP_InstallRex_AntiFWb From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: b621b3e06cb2cdea4636389e95c7e81771757186
    SHA256: 4260dea137937a04284941ca1ba41b16f78d531e28e77f0cfb5629f6e1c98c62
    application/zip
    25.79MB
    2025-06-18 16:05:21 +0000 UTC

  • allthethings.ddns.net · virussign.com_20250611_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_ASPack From AlienVault by ditekSHen
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: c8dd02528aaa4f2b2489e053b95acf7703b77a50
    SHA256: 022613a0e2838dc693feed2ee2d7bcb2f8d0033a36f615f499cfc0396efcc959
    application/zip
    39.71MB
    2025-06-11 16:05:27 +0000 UTC