84e3ad0d62d21739d632d2106864e79e |
ELF |
2017-10-16 03:20:43 | User Submission | CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+] |
b3d26632c4077e731ef2da329974519d |
ELF |
2017-10-16 03:33:40 | User Submission | CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+] |
24734ef952fe363415cd4c2f7322276f |
ELF |
2017-10-16 03:37:29 | User Submission | CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+] |
0d416f8cd599c029f28344f288c73caf |
C |
2018-03-07 04:07:57 | http://172.104.107.30/PowerSploit/CodeExecuti... | CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+] |
80dd1344d788763f85cf034380b1111a |
ASCII |
2018-03-07 04:10:39 | http://172.104.107.30/PowerSploit/Exfiltratio... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
db979c04a99b96d370988325bb5a8b21 |
ASCII |
2018-03-07 04:11:41 | http://172.104.107.30/PowerSploit/Exfiltratio... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
712a51ba3742dc9855d069c689ac7a20 |
ASCII |
2018-03-07 04:12:24 | http://172.104.107.30/PowerSploit/Exfiltratio... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
e55ce0a39308f104fa6a6b0f060a441a |
ASCII |
2018-03-07 04:14:01 | http://52.53.132.25/v1.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
f130de5609bdef156d0f32e2c2ecb1f4 |
ASCII |
2018-03-07 04:15:00 | http://167.114.128.52/im.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
e78a0935c33bf8f1f0e91a05e427c473 |
ASCII |
2018-03-07 04:17:30 | http://172.104.107.30/nishang/Gather/Invoke-M... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
1c1a986f48160010c53a618167795cd7 |
ASCII |
2018-03-07 04:17:39 | http://172.93.54.174/old/Invoke-sillykatz.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
ea03c66ea6311902b614c01380f5b40b |
ASCII |
2018-03-07 04:18:15 | http://172.104.107.30/nishang/Gather/Invoke-M... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
51f1a9743572fd5f2a40198e623b5222 |
C |
2018-03-07 04:53:30 | http://207.148.71.41/CodeExecution-dll.jpg | CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+] |
f901c645188f9c80afa8f49174f065ce |
PE32+ |
2018-05-24 02:58:05 | User Submission | CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+] |
27f54e0271e4f58b7d3c8ddc5c6d617f |
data |
2018-07-23 22:38:42 | User Submission | CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+] |
fce31d7f7aa9f4c15267bb43afc8526f |
ASCII |
2018-12-20 01:58:45 | https://pastebin.com/raw/UDJxdggR | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
3f50a58b4e4bdb16c9d0efc796e55d3a |
ASCII |
2019-01-05 01:47:05 | https://pastebin.com/raw/FkyichTu | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
c3a2f2c8d1a4bc9c0cc1dde4b67536fc |
ASCII |
2019-02-03 13:52:11 | http://deforestacion.tk/Invoke-Mimikatz.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
aaddd2378dad079904b58063f6b6bfe8 |
ASCII |
2019-02-23 01:49:04 | http://pastebin.com/raw/jkBxauyv | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
5d6589c7ff58d89f08c6854b3794d178 |
ASCII |
2019-05-05 03:34:44 | http://45.76.216.23/PowerShell/Invoke-Credent... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
a09639208ce794ec515a1f04346fc5ef |
ASCII |
2019-05-05 03:35:26 | http://45.76.216.23/PowerShell/Invoke-Mimikat... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
555675d92c585673d9cf57f7b6a2116e |
ASCII |
2019-05-05 03:36:12 | http://45.76.216.23/PowerShell/Invoke-NinjaCo... | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
a875e14f20afb3a8e37e1447d920466e |
C |
2019-05-05 03:36:22 | http://45.76.216.23/PowerShell/Invoke-Reflect... | CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+] |
a08de44a9b17db1d4d4272e7daf1251e |
ASCII |
2019-06-22 02:11:32 | https://pastebin.com/raw/1w6BLxha | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
db26a9937355e7d4f2b6cd41bff19679 |
UTF-8 |
2019-06-28 19:40:01 | http://123.207.143.211/main.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
1da978138d17115245f1b6fe9d26b678 |
ASCII |
2019-07-09 14:15:56 | https://pastebin.com/raw/yJnNFtb9 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
931778f778ea3257e61c1221f34422bb |
ASCII |
2019-07-17 14:03:09 | https://pastebin.com/raw/CY2EEMJN | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
f579d8f8bac96123fd6d1adf7239a4c8 |
HTML |
2019-08-06 14:50:11 | https://pastebin.com/gUJMLv20 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
69ab6aa89a9ac6803f6d6a83118fdff1 |
HTML |
2019-08-06 14:50:46 | https://pastebin.com/2q8dT2n3 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
f0f4bc53d852e0647dd7efd6d03386e2 |
ASCII |
2019-09-16 16:14:43 | http://144.34.184.232/Invoke-Mimikatz.ps1 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
f451a6ae7152553589b7967217e96678 |
ASCII |
2019-10-25 22:22:53 | User Submission | YRP/powershell YRP/domain YRP/IP YRP/url [+] |
2401613d11276e67eae857826bd00337 |
ASCII |
2019-12-04 01:18:46 | https://pastebin.com/raw/Ukz4qARy | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
1c844368d231ef1c7e9310d4a8b4549d |
ASCII |
2019-12-20 12:25:58 | https://pastebin.com/raw/e8kSryaf | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
a1be5c533c0fa372fb376a8acab22e4f |
ASCII |
2019-12-20 12:28:20 | https://pastebin.com/raw/vJrm3cs2 | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
badf243ffdaac060c91ead976eff0d59 |
ASCII |
2019-12-25 12:00:51 | https://pastebin.com/raw/phS7sDeA | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
d420b7594eb33790d12ad5e55f0329b0 |
ASCII |
2020-01-10 18:22:37 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+] |
22528dfebae57319a5557449f48eec68 |
ASCII |
2020-04-18 16:43:29 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
8b4f2c49d896fd02e3f8e1661b014c0d |
ASCII |
2020-07-07 16:54:37 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
a2aa164728ed974bb96509317ea4c7e0 |
ASCII |
2020-07-10 18:37:05 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
afefaf9f113747c411c7e977c2773a11 |
ASCII |
2020-07-10 22:16:25 | User Submission | CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+] |
c869957ae5105684d89a1d94ad935085 |
ASCII |
2020-07-10 23:50:12 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |
9c1be35a7a8c20b09012d76a2d5a7c65 |
ASCII |
2020-08-28 23:17:18 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+] |
0fd79f4c60593f6aae69ff22086c3bb0 |
ASCII |
2020-11-01 00:05:38 | User Submission | CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_Invoke_CredentialInjection_Invoke_Mimikatz_Gen FlorianRoth/Empire_Invoke_Gen [+] |