MD5 Hash File type Added Source Yara Hits
84e3ad0d62d21739d632d2106864e79e ELF 2017-10-16 01:20:43 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
b3d26632c4077e731ef2da329974519d ELF 2017-10-16 01:33:40 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
24734ef952fe363415cd4c2f7322276f ELF 2017-10-16 01:37:29 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
79e9dd35aef6558461c4b93cd0c55b76 Java 2018-03-06 19:59:10http://94.130.104.170/79e9dd35aef6558461c4b93... YRP/domain YRP/contentis_base64 YRP/JavaDropper FlorianRoth/RAT_JavaDropper [+]
db46adcfae462e7c475c171fbe66df82 Java 2018-03-06 21:05:19http://94.130.104.170/DB46ADCFAE462E7C475C171... YRP/domain YRP/contentis_base64 YRP/JavaDropper FlorianRoth/RAT_JavaDropper [+]
f901c645188f9c80afa8f49174f065ce PE32+ 2018-05-24 00:58:05 CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
7b5eb0f6680d4b3cbbcc70efe09f374a ASCII 2018-06-08 15:10:17 YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
27f54e0271e4f58b7d3c8ddc5c6d617f data 2018-07-23 20:38:42 CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+]