SHA256 Hash File type Added Source Yara Hits
PE32+ 2018-05-24 02:58:05User Submission CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
ASCII 2018-06-08 17:10:05User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/System_Tools [+]
data 2018-07-23 22:38:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+]
PE32+ 2018-11-14 21:37:51User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2018-11-14 21:38:38User Submission YRP/IsPE32 YRP/IsConsole YRP/HasRichSignature YRP/domain [+]
data 2019-10-25 22:21:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 [+]
ASCII 2019-10-25 22:22:38User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/System_Tools [+]
ASCII 2019-10-25 22:22:38User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/System_Tools [+]
ASCII 2019-10-26 14:40:57User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/System_Tools [+]
PE32+ 2020-03-15 21:04:39User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2020-03-15 21:05:06User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_70_DLL YRP/Microsoft_Visual_Cpp_70_DLL_additional YRP/Microsoft_Visual_Cpp_v60_DLL [+]
PE32+ 2020-03-15 21:05:08User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2020-03-15 21:05:09User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_70_DLL YRP/Microsoft_Visual_Cpp_70_DLL_additional YRP/Microsoft_Visual_Cpp_v60_DLL [+]
PE32+ 2020-03-15 21:05:14User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasDebugData [+]
PE32+ 2020-03-15 21:05:21User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32+ 2020-11-01 19:19:53User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32+ 2020-11-01 19:19:55User Submission YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2020-11-01 19:19:57User Submission CuckooSandbox/vmdetect YRP/IsPE32 YRP/IsWindowsGUI YRP/HasRichSignature [+]
PE32 2020-11-01 19:20:00User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_70_DLL YRP/Microsoft_Visual_Cpp_70_DLL_additional YRP/Microsoft_Visual_Cpp_v60_DLL [+]
PE32 2020-11-01 19:20:02User Submission YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_70_DLL YRP/Microsoft_Visual_Cpp_70_DLL_additional YRP/Microsoft_Visual_Cpp_v60_DLL [+]