MD5 Hash File type Added Source Yara Hits
0d416f8cd599c029f28344f288c73caf C 2018-03-07 04:07:57http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
80dd1344d788763f85cf034380b1111a ASCII 2018-03-07 04:10:39http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
db979c04a99b96d370988325bb5a8b21 ASCII 2018-03-07 04:11:41http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
712a51ba3742dc9855d069c689ac7a20 ASCII 2018-03-07 04:12:24http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
e55ce0a39308f104fa6a6b0f060a441a ASCII 2018-03-07 04:14:01http://52.53.132.25/v1.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
f130de5609bdef156d0f32e2c2ecb1f4 ASCII 2018-03-07 04:15:00http://167.114.128.52/im.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
e78a0935c33bf8f1f0e91a05e427c473 ASCII 2018-03-07 04:17:30http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
1c1a986f48160010c53a618167795cd7 ASCII 2018-03-07 04:17:39http://172.93.54.174/old/Invoke-sillykatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ea03c66ea6311902b614c01380f5b40b ASCII 2018-03-07 04:18:15http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
51f1a9743572fd5f2a40198e623b5222 C 2018-03-07 04:53:30http://207.148.71.41/CodeExecution-dll.jpg CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
fce31d7f7aa9f4c15267bb43afc8526f ASCII 2018-12-20 01:58:45https://pastebin.com/raw/UDJxdggR CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
3f50a58b4e4bdb16c9d0efc796e55d3a ASCII 2019-01-05 01:47:05https://pastebin.com/raw/FkyichTu CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
c3a2f2c8d1a4bc9c0cc1dde4b67536fc ASCII 2019-02-03 13:52:11http://deforestacion.tk/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
aaddd2378dad079904b58063f6b6bfe8 ASCII 2019-02-23 01:49:04http://pastebin.com/raw/jkBxauyv CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
5d6589c7ff58d89f08c6854b3794d178 ASCII 2019-05-05 03:34:44http://45.76.216.23/PowerShell/Invoke-Credent... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
a09639208ce794ec515a1f04346fc5ef ASCII 2019-05-05 03:35:26http://45.76.216.23/PowerShell/Invoke-Mimikat... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
555675d92c585673d9cf57f7b6a2116e ASCII 2019-05-05 03:36:12http://45.76.216.23/PowerShell/Invoke-NinjaCo... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
a875e14f20afb3a8e37e1447d920466e C 2019-05-05 03:36:22http://45.76.216.23/PowerShell/Invoke-Reflect... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
a08de44a9b17db1d4d4272e7daf1251e ASCII 2019-06-22 02:11:32https://pastebin.com/raw/1w6BLxha CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
db26a9937355e7d4f2b6cd41bff19679 UTF-8 2019-06-28 19:40:01http://123.207.143.211/main.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
1da978138d17115245f1b6fe9d26b678 ASCII 2019-07-09 14:15:56https://pastebin.com/raw/yJnNFtb9 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
931778f778ea3257e61c1221f34422bb ASCII 2019-07-17 14:03:09https://pastebin.com/raw/CY2EEMJN CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
f579d8f8bac96123fd6d1adf7239a4c8 HTML 2019-08-06 14:50:11https://pastebin.com/gUJMLv20 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
69ab6aa89a9ac6803f6d6a83118fdff1 HTML 2019-08-06 14:50:46https://pastebin.com/2q8dT2n3 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]
f0f4bc53d852e0647dd7efd6d03386e2 ASCII 2019-09-16 16:14:43http://144.34.184.232/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
c86050690e0575e952a75840d815c0bf data 2019-10-25 22:21:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 [+]
67acf4a2155c58b81fe4e50db844dc46 ASCII 2019-10-25 22:22:55User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
393ed9b620587a01e6b5aac0720ee846 ASCII 2019-10-25 22:22:55User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
2401613d11276e67eae857826bd00337 ASCII 2019-12-04 01:18:46https://pastebin.com/raw/Ukz4qARy CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+]