File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • box.misaelabanto.com · androlea.ps1

    /

    France · Contabo GmbH

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Download archived sample
    The password is "infected"

    SHA1: 81dba35df4b9066430511a6eadacc6940052572b
    SHA256: 2b44c36f7c5baafbb99a9cadfc77ca1a91e12768c28205351b362975b40c6d65
    application/octet-stream
    3.55MB
    2022-01-05 21:24:23 +0000 UTC

  • mirror.damiencoop.be · snort3-community-rules.zip

    /

    Germany · WIIT AG

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara Cobaltbaltstrike_Payload_Encoded From Florian Roth by Avast Threat Intel Team
    Yara WEBSHELL_ASPX_reGeorgTunnel From Florian Roth by threatintel@volexity.com
    Yara ironshell_php From Florian Roth by Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
    Download archived sample
    The password is "infected"

    SHA1: 2d3b79eb5f94d1960d5e005000b925dec33df199
    SHA256: d7878cab16efd75d7fa071a8ede5ccc615f5b4d7e2ec6a7f7ff8c579acc467c3
    application/zip
    2.75MB
    2025-05-22 20:40:43 +0000 UTC

  • pypi.corp.tevian.ru · capesolo-0.4.11.tar.gz

    /packages/00/9f/0db316e5456dd811fcd3a2aa4d1282ed639aa02af2b0f0a69173fd9d70c1/

    Russia · PVimpelCom

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara RAT_adWind From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Adzok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_BlackShades From Florian Roth by Brian Wallace (@botnet_hunter)
    Yara RAT_BlueBanana From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Bozok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_ClientMesh From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara APT_MAL_Sandworm_Exaramel_Task_Names From Florian Roth by FR/ANSSI/SDO
    Yara MAL_HawkEye_Keylogger_Gen_Dec18 From Florian Roth by Florian Roth (Nextron Systems)
    Yara RAT_JavaDropper From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_LostDoor From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara RAT_Paradox From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_QRat From Florian Roth by Kevin Breen @KevTheHermit
    Yara RAT_ShadowTech From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Sub7Nation From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_unrecom From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Vertex From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara WindowsCredentialEditor From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: eb3f78bfbca21a885ed281b778fb210d969828d5
    SHA256: f834cbd8fb6edcf50542d4c2f699bfb4105325598c7c1caecbc123a1bfa2e487
    application/octet-stream
    4.37MB
    2024-11-15 12:40:34 +0000 UTC

  • 93.115.21.186 · mimikatz_trunk.zip

    /

    The Netherlands · MVPS LTD

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara HackTool_Producers From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: 4112ef95386ea4d1131be7c600d49a310e9d8f5b
    SHA256: 7accd179e8a6b2fc907e7e8d087c52a7f48084852724b03d25bebcada1acbca5
    application/zip
    1.15MB
    2022-09-19 15:54:21 +0000 UTC

  • 93.115.21.186 · mimikatz_master.zip

    /

    The Netherlands · MVPS LTD

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Download archived sample
    The password is "infected"

    SHA1: fb1cde1f0333b12a1cab1a57a8dc07753a635cad
    SHA256: fbd9e458ee55e970e58e776215bdcffc869d3732a0dec6aab4a879e507a12c4b
    application/zip
    2.92MB
    2025-06-20 21:22:58 +0000 UTC

  • 93.115.21.186 · mimikatz.zip

    /

    The Netherlands · MVPS LTD

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara mimikatz From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara HackTool_Producers From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: 4112ef95386ea4d1131be7c600d49a310e9d8f5b
    SHA256: 7accd179e8a6b2fc907e7e8d087c52a7f48084852724b03d25bebcada1acbca5
    application/zip
    1.15MB
    2022-09-19 15:54:21 +0000 UTC

  • box.misaelabanto.com · androlea.ps1

    /

    France · Contabo GmbH

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Download archived sample
    The password is "infected"

    SHA1: 81dba35df4b9066430511a6eadacc6940052572b
    SHA256: 2b44c36f7c5baafbb99a9cadfc77ca1a91e12768c28205351b362975b40c6d65
    application/octet-stream
    3.55MB
    2022-01-05 21:24:23 +0000 UTC

  • pypi.corp.tevian.ru · capesolo-0.4.11.tar.gz

    /packages/00/9f/0db316e5456dd811fcd3a2aa4d1282ed639aa02af2b0f0a69173fd9d70c1/

    Russia · PVimpelCom

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara RAT_adWind From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Adzok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_BlackShades From Florian Roth by Brian Wallace (@botnet_hunter)
    Yara RAT_BlueBanana From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Bozok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_ClientMesh From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara APT_MAL_Sandworm_Exaramel_Task_Names From Florian Roth by FR/ANSSI/SDO
    Yara MAL_HawkEye_Keylogger_Gen_Dec18 From Florian Roth by Florian Roth (Nextron Systems)
    Yara RAT_JavaDropper From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_LostDoor From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara RAT_Paradox From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_QRat From Florian Roth by Kevin Breen @KevTheHermit
    Yara RAT_ShadowTech From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Sub7Nation From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_unrecom From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Vertex From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara WindowsCredentialEditor From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: eb3f78bfbca21a885ed281b778fb210d969828d5
    SHA256: f834cbd8fb6edcf50542d4c2f699bfb4105325598c7c1caecbc123a1bfa2e487
    application/octet-stream
    4.37MB
    2024-11-15 12:40:34 +0000 UTC

  • box.misaelabanto.com · androlea.ps1

    /

    France · Contabo GmbH

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Download archived sample
    The password is "infected"

    SHA1: 81dba35df4b9066430511a6eadacc6940052572b
    SHA256: 2b44c36f7c5baafbb99a9cadfc77ca1a91e12768c28205351b362975b40c6d65
    application/octet-stream
    3.55MB
    2022-01-05 21:24:23 +0000 UTC

  • box.misaelabanto.com · androlea.ps1

    /

    Germany · Contabo GmbH

    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Download archived sample
    The password is "infected"

    SHA1: 81dba35df4b9066430511a6eadacc6940052572b
    SHA256: 2b44c36f7c5baafbb99a9cadfc77ca1a91e12768c28205351b362975b40c6d65
    application/octet-stream
    3.55MB
    2022-01-05 21:24:23 +0000 UTC