SHA256 Hash File type Added Source Yara Hits
ELF 2017-10-16 03:20:43User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
ELF 2017-10-16 03:33:40User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
PE32 2018-05-19 02:51:53http://aspmailcenter2.com/test.exe YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
DOS 2018-06-22 09:20:35User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Dropper_Strings [+]
DOS 2018-06-22 13:11:33User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Dropper_Strings [+]
PE32 2018-06-23 13:19:02User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/IsPE32 YRP/IsConsole YRP/HasDebugData [+]
Composite 2018-06-23 15:36:44User Submission YRP/office_document_vba YRP/Contains_VBA_macro_code YRP/domain YRP/contentis_base64 [+]
ASCII 2018-08-20 15:58:22User Submission YRP/domain YRP/url YRP/contentis_base64 FlorianRoth/Certutil_Decode_OR_Download
ASCII 2018-09-05 10:48:00User Submission FlorianRoth/Certutil_Decode_OR_Download
ASCII 2018-09-05 10:48:59User Submission CuckooSandbox/vmdetect FlorianRoth/Certutil_Decode_OR_Download
MS-DOS 2018-11-13 15:12:26User Submission CuckooSandbox/vmdetect YRP/possible_includes_base64_packed_functions YRP/powershell YRP/maldoc_find_kernel32_base_method_1 [+]
ASCII 2018-11-13 16:04:42User Submission YRP/domain YRP/contentis_base64 FlorianRoth/Certutil_Decode_OR_Download
ASCII 2018-11-13 22:31:52User Submission FlorianRoth/Certutil_Decode_OR_Download
ASCII 2018-11-14 03:23:07User Submission FlorianRoth/Certutil_Decode_OR_Download
PE32 2019-05-03 21:04:03User Submission YRP/Armadillo_v171 YRP/Microsoft_Visual_Cpp_v60 YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional YRP/Microsoft_Visual_Cpp_50 [+]
PE32 2019-05-18 06:12:24User Submission YRP/Armadillo_v171 YRP/Microsoft_Visual_Cpp_v60 YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional YRP/Microsoft_Visual_Cpp_50 [+]
PE32 2019-05-29 19:22:19User Submission YRP/Armadillo_v171 YRP/Microsoft_Visual_Cpp_v60 YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional YRP/Microsoft_Visual_Cpp_50 [+]
PE32 2019-09-15 16:00:20User Submission YRP/Armadillo_v1xx_v2xx_additional YRP/Microsoft_Visual_Cpp_v70_DLL YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_60_DLL_Debug [+]
ASCII 2019-10-25 22:22:54User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2019-10-25 22:22:57User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Base64d_PE [+]
ASCII 2019-10-26 14:40:56User Submission YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
ASCII 2019-10-26 14:41:02User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2019-10-26 14:41:04User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Base64d_PE [+]
ASCII 2019-10-26 14:42:22User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Base64d_PE [+]
ASCII 2019-10-26 15:00:49User Submission YRP/powershell YRP/domain YRP/url YRP/contentis_base64 [+]
ASCII 2019-11-21 17:21:28User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
XML 2020-03-22 19:33:53User Submission CuckooSandbox/vmdetect YRP/powershell YRP/domain YRP/IP [+]
Little-endian 2020-04-21 10:47:16User Submission YRP/domain FlorianRoth/Certutil_Decode_OR_Download
ASCII 2020-07-08 00:49:50User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
PE32 2020-07-08 01:34:09User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2020-08-16 00:44:15User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2020-08-16 00:47:23User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
Composite 2020-10-23 22:08:09User Submission YRP/office_document_vba YRP/Contains_VBA_macro_code YRP/domain YRP/url [+]
PE32 2021-02-25 19:40:05User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
ASCII 2021-04-06 23:27:17User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/System_Tools [+]
DOS 2021-06-11 23:35:06User Submission YRP/domain YRP/contentis_base64 FlorianRoth/Certutil_Decode_OR_Download
PE32 2021-06-29 09:00:58User Submission YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
PE32 2021-07-10 03:25:03Zemana Submission FlorianRoth/Certutil_Decode_OR_Download
ASCII 2021-08-06 13:01:18User Submission YRP/domain YRP/IP YRP/contentis_base64 YRP/Base64d_PE [+]