SHA256 Hash File type Added Source Yara Hits
C 2018-03-07 04:07:57http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 04:10:39http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:11:41http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:12:24http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:14:01http://52.53.132.25/v1.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2018-03-07 04:15:00http://167.114.128.52/im.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:17:30http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:17:39http://172.93.54.174/old/Invoke-sillykatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:18:15http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
C 2018-03-07 04:53:30http://207.148.71.41/CodeExecution-dll.jpg CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-12-20 01:58:45https://pastebin.com/raw/UDJxdggR CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-01-05 01:47:05https://pastebin.com/raw/FkyichTu CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-02-03 13:52:11http://deforestacion.tk/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2019-02-23 01:49:04http://pastebin.com/raw/jkBxauyv CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-05-05 03:34:44http://45.76.216.23/PowerShell/Invoke-Credent... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-05-05 03:35:26http://45.76.216.23/PowerShell/Invoke-Mimikat... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-05-05 03:36:12http://45.76.216.23/PowerShell/Invoke-NinjaCo... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
C 2019-05-05 03:36:22http://45.76.216.23/PowerShell/Invoke-Reflect... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2019-06-22 02:11:32https://pastebin.com/raw/1w6BLxha CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
UTF-8 2019-06-28 19:40:01http://123.207.143.211/main.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-07-09 14:15:56https://pastebin.com/raw/yJnNFtb9 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-07-17 14:03:09https://pastebin.com/raw/CY2EEMJN CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
HTML 2019-08-06 14:50:11https://pastebin.com/gUJMLv20 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
HTML 2019-08-06 14:50:46https://pastebin.com/2q8dT2n3 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-09-16 16:14:43http://144.34.184.232/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
data 2019-10-25 22:21:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 [+]
ASCII 2019-10-25 22:22:55User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2019-10-25 22:22:55User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2019-12-04 01:18:46https://pastebin.com/raw/Ukz4qARy CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-12-20 12:25:58https://pastebin.com/raw/e8kSryaf CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-12-20 12:28:20https://pastebin.com/raw/vJrm3cs2 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2019-12-25 12:00:51https://pastebin.com/raw/phS7sDeA CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2020-01-10 18:22:37User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2020-04-18 16:43:29User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2020-07-07 16:54:37User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2020-07-10 18:37:05User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2020-07-10 22:16:25User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2020-07-10 23:50:12User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2020-11-01 00:05:38User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
ASCII 2021-06-14 07:56:45User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]