SHA256 Hash File type Added Source Yara Hits
ELF 2017-10-16 03:20:43User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
ELF 2017-10-16 03:33:40User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
ELF 2017-10-16 03:37:29User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
C 2018-03-07 04:07:57http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 04:10:39http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:11:41http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:12:24http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:15:00http://167.114.128.52/im.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2018-03-07 04:17:30http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:17:39http://172.93.54.174/old/Invoke-sillykatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2018-03-07 04:18:15http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
C 2018-03-07 04:53:30http://207.148.71.41/CodeExecution-dll.jpg CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
PE32+ 2018-05-24 02:58:05User Submission CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
ASCII 2018-06-08 17:10:08User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
data 2018-07-23 22:38:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+]
ASCII 2019-02-03 13:52:11http://deforestacion.tk/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2019-05-05 03:34:44http://45.76.216.23/PowerShell/Invoke-Credent... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-05-05 03:35:26http://45.76.216.23/PowerShell/Invoke-Mimikat... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-05-05 03:36:12http://45.76.216.23/PowerShell/Invoke-NinjaCo... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
C 2019-05-05 03:36:22http://45.76.216.23/PowerShell/Invoke-Reflect... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
UTF-8 2019-06-28 19:40:01http://123.207.143.211/main.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ASCII 2019-09-16 16:14:43http://144.34.184.232/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2019-10-25 22:22:53User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2019-10-26 14:41:01User Submission YRP/powershell YRP/domain YRP/IP YRP/url [+]
ASCII 2020-01-10 18:22:37User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ASCII 2020-08-28 23:17:18User Submission CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]