SHA256 Hash File type Added Source Yara Hits
ASCII 2022-03-20 17:29:54User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
ASCII 2022-03-20 14:50:30User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-20 13:28:38User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-20 13:08:57User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-20 12:22:24User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
ASCII 2022-03-20 12:15:43User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2022-03-20 11:55:55User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ YRP/Borland_Delphi_v40_v50 [+]
ASCII 2022-03-20 11:44:15User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Dropper_Strings [+]
ASCII 2022-03-20 11:13:44User Submission YRP/powershell YRP/domain YRP/contentis_base64
ASCII 2022-03-20 11:13:00User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-20 10:10:50User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-20 08:00:21User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2022-03-20 02:23:15User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2022-03-20 02:16:54User Submission YRP/Borland YRP/NETexecutableMicrosoft YRP/IsPE32 YRP/IsNET_EXE [+]
PE32 2022-03-20 02:05:05User Submission YRP/Borland_Delphi_40_additional YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ [+]
PE32 2022-03-20 02:02:09User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
ASCII 2022-03-19 19:00:40User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-19 11:00:19http://14.55.65.217:8080/a/lr.ps1 YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2022-03-19 02:09:12User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
ASCII 2022-03-18 12:05:35User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64
PE32+ 2022-03-18 11:07:40User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2022-03-18 11:07:35User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ YRP/Borland_Delphi_v40_v50 [+]
PE32 2022-03-18 11:07:35User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ YRP/Borland_Delphi_v40_v50 [+]
Composite 2022-03-18 10:00:52User Submission YRP/powershell YRP/office_document_vba YRP/Contains_VBA_macro_code YRP/domain [+]
Composite 2022-03-18 10:00:36User Submission YRP/powershell YRP/office_document_vba YRP/Office_AutoOpen_Macro YRP/Contains_VBA_macro_code [+]
DOS 2022-03-18 08:03:46User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
DOS 2022-03-18 08:03:12User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
DOS 2022-03-18 08:03:01User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
DOS 2022-03-18 08:02:56User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
DOS 2022-03-18 08:02:35User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-18 08:00:18User Submission YRP/powershell YRP/domain YRP/contentis_base64 FlorianRoth/PowerShell_Case_Anomaly [+]
PE32 2022-03-18 02:35:05User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32+ 2022-03-18 02:03:47User Submission YRP/IsPE64 YRP/IsWindowsGUI YRP/HasOverlay YRP/ImportTableIsBad [+]
PE32 2022-03-18 02:02:24User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
HTML 2022-03-17 23:05:31https://www.cisa.gov/uscert/ncas/alerts/aa22-... YRP/powershell YRP/domain YRP/IP YRP/url [+]
Composite 2022-03-17 18:03:17User Submission YRP/powershell YRP/office_document_vba YRP/Office_AutoOpen_Macro YRP/Contains_VBA_macro_code [+]
ASCII 2022-03-17 13:02:42User Submission YRP/powershell YRP/domain YRP/contentis_base64 FlorianRoth/PowerShell_Case_Anomaly [+]
HTML 2022-03-17 11:05:01https://www.cisa.gov/uscert/ncas/alerts/aa22-... YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32+ 2022-03-17 02:17:13User Submission YRP/Microsoft_Visual_Cpp_80_DLL YRP/IsPE64 YRP/IsWindowsGUI YRP/HasOverlay [+]
PE32+ 2022-03-17 02:13:20User Submission YRP/possible_includes_base64_packed_functions YRP/IsPE64 YRP/IsWindowsGUI YRP/IsPacked [+]
PE32 2022-03-17 02:01:04User Submission YRP/VC8_Microsoft_Corporation YRP/Armadillo_v4x YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 [+]
PE32 2022-03-16 18:01:43User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2022-03-16 02:34:17User Submission YRP/NETexecutableMicrosoft YRP/IsPE32 YRP/IsNET_EXE YRP/IsWindowsGUI [+]
PE32 2022-03-16 02:07:15User Submission YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
PE32+ 2022-03-16 00:02:29User Submission YRP/IsPE64 YRP/IsWindowsGUI YRP/HasDebugData YRP/HasRichSignature [+]
HTML 2022-03-15 17:03:41User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
HTML 2022-03-15 17:02:41User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
PE32 2022-03-15 16:02:06User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
ASCII 2022-03-15 15:05:08User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2022-03-15 15:04:57User Submission YRP/powershell YRP/domain YRP/contentis_base64 FlorianRoth/PowerShell_Case_Anomaly
ASCII 2022-03-15 15:04:22User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
Composite 2022-03-15 14:06:14User Submission YRP/Contains_UserForm_Object YRP/powershell YRP/office_document_vba YRP/Contains_VBA_macro_code [+]
ASCII 2022-03-15 14:05:33User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
ASCII 2022-03-15 12:03:29User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Misc_Suspicious_Strings [+]
ASCII 2022-03-15 10:05:40User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-14 19:02:27User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
DOS 2022-03-14 04:02:37User Submission YRP/powershell YRP/domain YRP/contentis_base64
HTML 2022-03-14 04:02:19User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]
PE32 2022-03-12 18:01:36User Submission YRP/Visual_Cpp_2005_DLL_Microsoft YRP/Visual_Cpp_2003_DLL_Microsoft YRP/IsPE32 YRP/IsDLL [+]
DOS 2022-03-12 02:48:37User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2022-03-12 02:07:14User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2022-03-12 01:03:51User Submission YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/Borland YRP/IsPE32 [+]
ISO-8859 2022-03-11 15:43:48User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ISO-8859 2022-03-11 13:04:25User Submission YRP/powershell YRP/domain YRP/IP YRP/contentis_base64 [+]
PE32 2022-03-11 03:01:11User Submission YRP/Borland_Delphi_40_additional YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ [+]
ASCII 2022-03-10 11:04:02User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
ASCII 2022-03-10 11:03:45User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus [+]
PE32 2022-03-09 22:01:56User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ YRP/Borland_Delphi_v40_v50 [+]
ISO-8859 2022-03-09 15:07:45User Submission YRP/powershell YRP/domain YRP/IP YRP/contentis_base64 [+]
Composite 2022-03-09 15:05:26User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/office_document_vba YRP/Contains_VBA_macro_code [+]
ASCII 2022-03-09 15:02:11User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2022-03-09 15:02:04User Submission YRP/powershell YRP/domain YRP/contentis_base64 FlorianRoth/PowerShell_Case_Anomaly
ASCII 2022-03-09 15:01:58User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2022-03-09 15:01:51User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2022-03-09 15:01:45User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
ISO 2022-03-09 14:01:08User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api YRP/powershell YRP/domain [+]
ASCII 2022-03-09 10:46:51User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ISO 2022-03-09 10:13:07User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2022-03-09 02:14:12User Submission YRP/NETexecutableMicrosoft YRP/IsPE32 YRP/IsNET_EXE YRP/IsWindowsGUI [+]
HTML 2022-03-08 23:00:46https://blogs.blackberry.com/ja/jp/2022/01/th... YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2022-03-08 22:01:20User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
PE32 2022-03-08 19:07:35User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2022-03-08 18:08:47User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
ASCII 2022-03-08 18:07:48User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2022-03-08 18:07:43User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
PE32+ 2022-03-08 18:07:26User Submission YRP/Microsoft_Visual_Cpp_80_DLL YRP/IsPE64 YRP/IsConsole YRP/HasDebugData [+]
UTF-8 2022-03-08 13:04:07User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64
MS 2022-03-08 13:02:38User Submission YRP/powershell YRP/domain YRP/contentis_base64 YRP/Antivirus
HTML 2022-03-08 11:00:38https://blogs.blackberry.com/ja/jp/2022/01/th... YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2022-03-08 10:14:56User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:55User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:53User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:51User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:50User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:49User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:48User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:47User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:46User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:44User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2022-03-08 10:14:42User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]