MD5 Hash File type Added Source Yara Hits
84e3ad0d62d21739d632d2106864e79e ELF 2017-10-16 01:20:43User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
b3d26632c4077e731ef2da329974519d ELF 2017-10-16 01:33:40User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
24734ef952fe363415cd4c2f7322276f ELF 2017-10-16 01:37:29User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
f901c645188f9c80afa8f49174f065ce PE32+ 2018-05-24 00:58:05User Submission CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
bc52fad365ad5bde0a21c360c059a183 ASCII 2018-06-08 15:10:05User Submission YRP/suspicious_version YRP/invalid_trailer_structure YRP/invalid_xref_numbers YRP/header_evasion [+]
27f54e0271e4f58b7d3c8ddc5c6d617f data 2018-07-23 20:38:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect FlorianRoth/Empire_Get_SecurityPackages [+]
c86050690e0575e952a75840d815c0bf data 2019-10-25 20:21:42User Submission CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 [+]
84514715e1689ccac734a6c1a9759d34 ASCII 2019-10-25 20:22:16User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/url YRP/contentis_base64 [+]
ce3294c6b171b33148252bf58d84236e ASCII 2019-10-25 20:22:23User Submission YRP/suspicious_version YRP/invalid_trailer_structure YRP/invalid_xref_numbers YRP/header_evasion [+]
9fd1ff0423c6508b444ec0e5fa2f610b ASCII 2019-10-25 20:22:39User Submission YRP/suspicious_version YRP/invalid_trailer_structure YRP/invalid_xref_numbers YRP/header_evasion [+]
b1c935ad3b4d38161e2f3d3059245c76 ASCII 2019-10-25 20:22:39User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Misc_Suspicious_Strings [+]
2fc5303dc65dc4a860f879e996d247ad ASCII 2019-10-25 20:24:04User Submission YRP/domain YRP/url YRP/contentis_base64 YRP/Misc_Suspicious_Strings [+]