MD5 Hash File type Added Source Yara Hits
c4de6f3bba661a7fc3922ff938619725 ASCII 2018-03-07 03:07:54http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
0d416f8cd599c029f28344f288c73caf C 2018-03-07 03:07:57http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
af17a2c4c38621b78d2714dc18dae5e2 ASCII 2018-03-07 03:07:59http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]
9fb0dd54c5b2abae77f1943ff5dd6076 ASCII 2018-03-07 03:08:02http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
d82be5ccb9416958abeb59506d112af7 ASCII 2018-03-07 03:09:43http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
36622ac07149595796f8ec7e5cb3b9bc ASCII 2018-03-07 03:09:45http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
80dd1344d788763f85cf034380b1111a ASCII 2018-03-07 03:10:39http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
db979c04a99b96d370988325bb5a8b21 ASCII 2018-03-07 03:11:41http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
712a51ba3742dc9855d069c689ac7a20 ASCII 2018-03-07 03:12:24http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
ee886cd71de14b7f51c6a89f781b783c ASCII 2018-03-07 03:12:27http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
45a418848bfd7cd5d330dc63dd71a59e ASCII 2018-03-07 03:12:47http://172.104.107.30/PowerSploit/Privesc/Get... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
f130de5609bdef156d0f32e2c2ecb1f4 ASCII 2018-03-07 03:15:00http://167.114.128.52/im.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
e78a0935c33bf8f1f0e91a05e427c473 ASCII 2018-03-07 03:17:30http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
1c1a986f48160010c53a618167795cd7 ASCII 2018-03-07 03:17:39http://172.93.54.174/old/Invoke-sillykatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
ea03c66ea6311902b614c01380f5b40b ASCII 2018-03-07 03:18:15http://172.104.107.30/nishang/Gather/Invoke-M... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
51f1a9743572fd5f2a40198e623b5222 C 2018-03-07 03:53:30http://207.148.71.41/CodeExecution-dll.jpg CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
6f5648ea4ca8a65c36c328c5ae8ac096 ASCII 2018-06-22 12:15:15 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen4 FlorianRoth/ps1_toolkit_Invoke_Shellcode
2e048e53dc6b3c27f5f7e72606102cfd ASCII 2018-11-14 17:43:51 CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
c3a2f2c8d1a4bc9c0cc1dde4b67536fc ASCII 2019-02-03 12:52:11http://deforestacion.tk/Invoke-Mimikatz.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 FlorianRoth/Empire_PowerShell_Framework_Gen3 [+]
f2f36d8cc4b5f5a15f87d41b613b37ac ASCII 2019-05-04 23:51:42http://196.52.9.47/Invoke--Shellcode.ps1 CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]
5d6589c7ff58d89f08c6854b3794d178 ASCII 2019-05-05 01:34:44http://45.76.216.23/PowerShell/Invoke-Credent... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
a09639208ce794ec515a1f04346fc5ef ASCII 2019-05-05 01:35:26http://45.76.216.23/PowerShell/Invoke-Mimikat... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
555675d92c585673d9cf57f7b6a2116e ASCII 2019-05-05 01:36:12http://45.76.216.23/PowerShell/Invoke-NinjaCo... CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
a875e14f20afb3a8e37e1447d920466e C 2019-05-05 01:36:22http://45.76.216.23/PowerShell/Invoke-Reflect... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
8e8c6170d49926e5fe1e2c71e7cbfab1 ASCII 2019-05-05 01:36:27http://45.76.216.23/PowerShell/Invoke-TokenMa... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
db26a9937355e7d4f2b6cd41bff19679 UTF-8 2019-06-28 17:40:01http://123.207.143.211/main.ps1 CuckooSandbox/embedded_win_api FlorianRoth/Empire_Invoke_Mimikatz_Gen FlorianRoth/Empire_PowerShell_Framework_Gen1 FlorianRoth/Empire_PowerShell_Framework_Gen2 [+]
415f903673236e2b08241a240fe68019 ASCII 2019-07-17 12:11:31 CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]