SHA256 Hash File type Added Source Yara Hits
ELF 2017-10-16 03:20:43User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
ELF 2017-10-16 03:33:40User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
ELF 2017-10-16 03:37:29User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
Java 2018-03-06 20:59:10http://94.130.104.170/79e9dd35aef6558461c4b93... YRP/domain YRP/contentis_base64 YRP/JavaDropper FlorianRoth/RAT_JavaDropper [+]
Java 2018-03-06 22:05:19http://94.130.104.170/DB46ADCFAE462E7C475C171... YRP/domain YRP/contentis_base64 YRP/JavaDropper FlorianRoth/RAT_JavaDropper [+]
PE32+ 2018-05-24 02:58:05User Submission CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
ASCII 2018-06-08 17:10:17User Submission YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
data 2018-07-23 22:38:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+]
data 2019-10-25 22:21:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 [+]
ASCII 2019-10-25 22:22:56User Submission YRP/Borland YRP/domain YRP/IP YRP/url [+]
ASCII 2019-10-25 22:23:08User Submission YRP/Borland YRP/domain YRP/IP YRP/url [+]
ASCII 2019-10-26 14:41:03User Submission YRP/Borland YRP/domain YRP/IP YRP/url [+]
ASCII 2019-10-26 14:42:22User Submission YRP/Borland YRP/domain YRP/IP YRP/url [+]