File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 5.45.102.182 · virussign.com_20251018_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: 3e86f40d9052b3af89ec185cd5ae748f981a429c
    SHA256: ffa6efc8d484887b5ca4fc2885778397c10af4f0aa702968199b9a669fcef8cf
    application/zip
    8.47MB
    2025-10-18 16:05:28 +0000 UTC

  • 5.45.102.182 · virussign.com_20251011_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: 4c09e00477f9af6113bafcf968ecaa78bcd44233
    SHA256: bb2681aea713e177cc846909f2b76e54511f9017af90544b6caf39476423094d
    application/zip
    9.91MB
    2025-10-11 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20251005_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: b7cf928186bbb014b77ea3f6f7688df14dcba392
    SHA256: 74baeccc1b3eb3181cadc24c9f32c54c9fd8100031fc95a8c7fdc10aadc80d29
    application/zip
    8.77MB
    2025-10-05 16:05:15 +0000 UTC

  • 5.45.102.182 · virussign.com_20251004_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Download archived sample
    The password is "infected"

    SHA1: 93e06aadf55c1b0d911171cf8ee3ddd55c2aa1d8
    SHA256: 5424a2ee6e888249f61f8f442054cb525ed8d716d4bc3a2a6711be0edcbfb538
    application/zip
    14.99MB
    2025-10-04 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20251003_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: e87c124dc11f7bbb33cb22986f161c2168574bb9
    SHA256: dbe23620275280a818a6071fc311a8d68d58066b471341b3d7fe867a682eea13
    application/zip
    11.87MB
    2025-10-03 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20250923_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: b688b9046bf2b3a00a27dac114824b17789952db
    SHA256: 3db7cb353c5638425ccb1b2bdaa11cc090258f1515e98316dd6d89ee8940a0d9
    application/zip
    10.72MB
    2025-09-23 16:05:16 +0000 UTC

  • 5.45.102.182 · virussign.com_20250920_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: d2ec694e95d1ec577524fdde565fc6e0d5f38421
    SHA256: c9ac48b7438491a7f4d00899296ca3582b7489c021d249196fc735f59b9a42cc
    application/zip
    18.54MB
    2025-09-20 16:05:18 +0000 UTC

  • 5.45.102.182 · virussign.com_20250908_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: 0d2233162f41cb296417828843295a80badd53d5
    SHA256: 5bdc042951ba89321b233176a4565ec7a81dee5f4dc6d3e61418393dabe918b8
    application/zip
    30.03MB
    2025-09-08 16:05:20 +0000 UTC

  • 5.45.102.182 · virussign.com_20250824_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara INDICATOR_EXE_Packed_Themida From AlienVault by ditekSHen
    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: cf4f154c4c435a799652fa45c0df0187da5ee2eb
    SHA256: 623e0e504bcb5de900113e825d4afd9e71d6fe50d7331920dfc6fb14b6a65bd4
    application/zip
    16.01MB
    2025-08-24 16:05:18 +0000 UTC