File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 46.105.62.210 · glog-0.6.0.tar.gz

    /distfiles.gentoo.org/distfiles/0a/

    France · OVH SAS

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 31376c7916aee2fc6375994468744123ad6179b9
    SHA256: 8a83bf982f37bb70825df71a9709fa90ea9f4447fb3c099e1d720a439d88bad6
    application/x-gzip
    188.74KB
    2022-07-07 14:52:18 +0000 UTC

  • oh5.kryptographen.eu · Install Printer Script Format.zip

    /zTool/

    Germany · Hetzner Online GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 82d376e8a820ba22dd9146b1320e60c46bb54514
    SHA256: d68f62a3e8802e877d02f5d743d6c70ec78d0a6603c908424c414face5150b37
    application/zip
    31.39KB
    2026-03-03 23:20:03 +0000 UTC

  • 51.254.59.25 · ansible-core_2.19.11.orig.tar.gz

    /pool/main/a/ansible-core/

    France · OVH SAS

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: a0eecbca5d6bc8eaa682ea44684a57358c906d6e
    SHA256: 6f397815d2ca63ffabf72548304a5b6e65017a577498a5f6e2ac8fad279963dc
    application/x-gzip
    3.27MB
    2026-06-19 23:30:15 +0000 UTC

  • 51.254.59.25 · ansible-core_2.19.0~beta6.orig.tar.gz

    /pool/main/a/ansible-core/

    France · OVH SAS

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 7596692f60b74afd2a8781a7e0a17d6b0ec44ef8
    SHA256: 816c0dc6b2323ca3e37f4f23e40a541f287daf24e623714adf5ebeb11c2be40b
    application/x-gzip
    3.23MB
    2025-06-12 22:37:26 +0000 UTC

  • 195.201.80.158 · iptv.zip

    /

    Germany · Hetzner Online GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e422438bb6506bf67f43b37a4df1a449b79dda7d
    SHA256: 1fa907714e513ece9dabb3c902f1b2dad3f022a61cad60633273f5e47f390e75
    application/zip
    74.16MB
    2026-09-27 22:55:15 +0000 UTC

  • files.sean-lauritzen.net · xiph-opus-v1.5.2.tar.gz

    /public/Repos/ladybird/Build/vcpkg/downloads/

    United States · Verizon Business

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 18b7eba72a283f0ade28533cc0282228f5c0907a
    SHA256: d9494f4cca21dd8872f4d4d00652ba12a5a3bc4a149356da8e1a13a463be2878
    application/x-gzip
    3.99MB
    2026-07-12 14:23:55 +0000 UTC

  • 194.42.102.4 · glog-0.6.0.tar.gz

    /distfiles/0a/

    Romania · Lansoft Data Srl

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 31376c7916aee2fc6375994468744123ad6179b9
    SHA256: 8a83bf982f37bb70825df71a9709fa90ea9f4447fb3c099e1d720a439d88bad6
    application/octet-stream
    188.74KB
    2022-07-07 14:52:18 +0000 UTC

  • 129.125.2.21 · python-aiohttp_3.8.4.orig.tar.gz

    /debian-security/pool/updates/main/p/python-aiohttp/

    The Netherlands · SURF B.V.

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 09487833fdd1661f2e34227976516ec33838fd09
    SHA256: bf2e1a9162c1e441bf805a1fd166e249d574ca04e03b34f97e2928769e91ab5c
    application/x-gzip
    7.00MB
    2024-11-29 12:10:28 +0000 UTC

  • 94.237.109.236 · try.ps1

    /

    The Netherlands · UpCloud Ltd

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 8741ee5b5a0cc7ef5cbc8b1d383edc2c2d0c563c
    SHA256: 896d062097ebaa6956a641dbd89092a8a22d893b63c27bed2d91ebb4c3aaf5df
    application/octet-stream
    11.69KB
    2026-09-22 19:48:06 +0000 UTC

  • 107.173.17.208 · servidor_completo_pool.py

    /

    United States · HostPapa

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: e6b1b0f9ab1d7daee1d2da99eabc678318ecc835
    SHA256: a74445e1c11d2f0fc80f641142c179d4fc13b13f39209cc366b17df228b67faf
    text/x-python
    115.04KB
    2026-09-27 23:24:23 +0000 UTC

  • files.sean-lauritzen.net · xiph-opus-v1.5.2.tar.gz

    /Repos/ladybird/Build/vcpkg/downloads/

    United States · Verizon Business

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 2e4178cf52b4af6e8333b0b4a2f542a4f9d3b919
    SHA256: 3a12a0408204d8c7acdc776523ae18f1307614af74d7a4309ba029107b0eb219
    application/x-gzip
    3.99MB
    2026-07-12 14:23:55 +0000 UTC

  • setup.efrank.at · boxstarter.ps1

    /

    Germany · Hetzner Online GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d6b7de6e1fdd9c737ec44bfe6f1c6e286e1174b7
    SHA256: e27b673b11ab008d1561c4e05bfc476a87a2827cd0f63aba701d6506b4c40445
    13.40KB
    2026-02-11 01:08:48 +0000 UTC

  • 103.179.190.183 · parallels-windows-prepare.sh

    /openclaw/scripts/e2e/

    Vietnam · NhanHoa Software company

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 9b4fa8b42b4f79c2be4eb2de6dc783ca30c81851
    SHA256: 1882b1fc8a811b929193edf6f5ae989b65323a2b8d7c8473795f9bbb729185d4
    text/x-sh
    24.43KB
    2026-07-25 07:09:34 +0000 UTC

  • www.smart-lms.smartreturn.com.eg · marketing-site.zip

    /

    France · Contabo GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 24e06bf89795890c0373257b12eab73147725e78
    SHA256: 0b6584ecbcf77b04465c1acf668e309a1998715c396902299157eded8a261e64
    application/zip
    57.94MB
    2026-09-28 21:59:52 +0000 UTC

  • www.smart-lms.smartreturn.com.eg · marketing-site.zip

    /

    France · Contabo GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: c4f30d969e43db01b121b9fc016e6218765b48ab
    SHA256: bccbaaed433d00beafbe5fe5957f15f6d713138eee5593bd1a2ae39cb0d2853b
    application/zip
    57.94MB
    2026-09-28 21:59:52 +0000 UTC

  • smart-lms.smartreturn.com.eg · marketing-site.zip

    /

    France · Contabo GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: d86b2528f6156f9fe6e0a207641a6518a1e1e1d2
    SHA256: 2033bd0e13d8b60dc51a7df4833a2f2ec35f4c04f5e77a80295c51d494f13770
    application/zip
    57.94MB
    2026-09-28 21:59:52 +0000 UTC

  • smart-lms.smartreturn.com.eg · marketing-site.zip

    /

    France · Contabo GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 396a0823cfa52956a4483194534e5488db6f9f48
    SHA256: ca152a1c7f4fa9d6aefa55a15fd5a1f9a3c45703822daf56f07f89c666f004c0
    application/zip
    57.94MB
    2026-09-28 21:59:52 +0000 UTC

  • 188.245.172.126 · td-agent-bit_0.12.0.orig.tar.gz

    /pool/main.bak/t/td-agent-bit/

    Germany · Hetzner Online GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 5b4f511f7dc7f08dfc1a58a44fb41fe08358eded
    SHA256: 28753a9d5c0a250e2ba344181d93ecb043957f83c7a87f2c928c0ab439d91f64
    application/octet-stream
    6.24MB
    2017-08-08 09:53:51 +0000 UTC

  • 188.245.172.126 · td-agent-bit_0.12.0.orig.tar.gz

    /pool/main/t/td-agent-bit/

    Germany · Hetzner Online GmbH

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 5b4f511f7dc7f08dfc1a58a44fb41fe08358eded
    SHA256: 28753a9d5c0a250e2ba344181d93ecb043957f83c7a87f2c928c0ab439d91f64
    application/octet-stream
    6.24MB
    2017-08-08 09:53:51 +0000 UTC

  • share.lauer.ddns.net · Microsoft-Activation-Scripts-master.zip

    /Privat/Software/

    Germany · Deutsche Telekom AG

    Yara Suspicious_PowerShell_WebDownload_1 From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 1438077440f89dee6ea9e9913351ab62231c1673
    SHA256: b14db0c28487d8f3ef043af25489233c7719c1e6ea950b09ae38c34c1569b069
    application/zip
    476.02KB
    2025-06-18 15:24:26 +0000 UTC