MD5 Hash File type Added Source Yara Hits
84e3ad0d62d21739d632d2106864e79e ELF 2017-10-16 03:20:43User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
b3d26632c4077e731ef2da329974519d ELF 2017-10-16 03:33:40User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
24734ef952fe363415cd4c2f7322276f ELF 2017-10-16 03:37:29User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
38aec0ac2b0d8fdeaa22bda66b94926d Zip 2018-03-07 03:07:38http://94.130.104.170/Surtr//Surtr.zip YRP/domain YRP/contentis_base64 YRP/Big_Numbers3 YRP/SurtrStrings [+]
f901c645188f9c80afa8f49174f065ce PE32+ 2018-05-24 02:58:05User Submission CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
0e6cd39d6ed6ba223fadf017a161bdf6 PE32 2018-10-25 03:45:35https://bitbucket.org/trainee_lemon/lemon/dow... YRP/Microsoft_Visual_Studio_NET YRP/Microsoft_Visual_C_v70_Basic_NET_additional YRP/Microsoft_Visual_C_Basic_NET YRP/Microsoft_Visual_Studio_NET_additional [+]
c6a11b469ff6f262623c94ed477b5b57 C 2018-12-28 18:32:41User Submission YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
d92b779ad3e8dfd26705cc812596ea17 PE32 2019-04-25 01:24:02https://www.itecwh.com.ng/wp-admin/2_B/ YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
ad5e64f0f64eebb86f021aac38faf699 ELF 2019-09-10 14:00:07http://23.254.165.208/Ouija_P.pc YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
65946e0281abe5ca7c0abf8443dd3632 ELF 2019-09-10 14:00:09http://23.254.165.208/Ouija_x.86 YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
270c00dd8efea95f81ce4037c15b74d6 ELF 2019-09-10 14:00:11http://23.254.165.208/Ouija_M.psl YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
57891b3aafeb9866690afc5280a2d826 ELF 2019-09-10 14:00:13http://23.254.165.208/Ouija_I.586 YRP/maldoc_getEIP_method_1 YRP/domain YRP/IP YRP/url [+]
36d4fe77b753fd3bb0fcb4554412365a ELF 2019-09-22 08:43:36http://23.254.165.208/Ouija_P.pc YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
49b90935d37b96c21f5c6ed065e1804f ELF 2019-09-22 08:43:38http://23.254.165.208/Ouija_x.86 YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
455e7d9bf8be00eb9dd0a914737c64fc ELF 2019-09-22 08:43:40http://23.254.165.208/Ouija_M.psl YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
49a8920382c02bbc4998b6d01f5161a1 ELF 2019-09-22 08:43:42http://23.254.165.208/Ouija_I.586 YRP/maldoc_getEIP_method_1 YRP/domain YRP/IP YRP/url [+]
84060342fb329662e612b1ebf90d2a1c ELF 2019-10-21 02:00:06http://192.99.55.18/Ouija_x.86 YRP/domain YRP/IP YRP/url YRP/contentis_base64 [+]
8b4d398435a8cf2403f0c1b26f774a65 PE32+ 2019-10-25 14:49:38Zemana Submission YRP/Microsoft_Visual_Cpp_80_DLL YRP/IsPE64 YRP/IsDLL YRP/IsWindowsGUI [+]
de3607d4b47898014eb1da724fff4e04 ASCII 2019-10-25 22:21:32User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/IP YRP/url [+]
84514715e1689ccac734a6c1a9759d34 ASCII 2019-10-25 22:22:16User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/url YRP/contentis_base64 [+]
0582b6d7d0e9c6990d657d1ea3407eda PE32 2019-11-24 11:42:38User Submission YRP/Borland_Delphi_40_additional YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Borland_Delphi_30_additional YRP/Borland_Delphi_30_ [+]
4ae450678c1a11dba3fc4ee33e04b372 PE32 2019-12-26 03:05:59User Submission YRP/IsPE32 YRP/IsDLL YRP/IsConsole YRP/IsPacked [+]
8f8e929a0bd44a1e10e1290e1f68e264 PE32 2019-12-26 03:20:23User Submission YRP/IsPE32 YRP/IsDLL YRP/IsConsole YRP/IsPacked [+]
d0324eae74939bc2131087a5ad5b7f5b PE32 2020-01-20 03:01:58User Submission YRP/Microsoft_Visual_C_Basic_NET YRP/NETDLLMicrosoft YRP/IsPE32 YRP/IsNET_DLL [+]
bbc0f519f2814a66e1d5bff8dc49a091 PE32 2020-01-25 03:25:28User Submission YRP/Microsoft_Visual_C_Basic_NET YRP/NETDLLMicrosoft YRP/IsPE32 YRP/IsNET_DLL [+]
efb81ea3ac8d2035e13ef43269b2dbf8 PE32+ 2020-02-08 17:00:05User Submission YRP/Microsoft_Visual_Cpp_80_DLL YRP/IsPE64 YRP/IsConsole YRP/HasOverlay [+]
dc8bfe72e4d5adf584cd5b5e27f8f442 PE32 2020-02-12 03:24:29User Submission YRP/Microsoft_Visual_C_Basic_NET YRP/NETDLLMicrosoft YRP/IsPE32 YRP/IsNET_DLL [+]
fe8f17003018cf469f2b5d0bd19ba80e data 2020-03-18 01:55:14User Submission CuckooSandbox/shellcode CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/possible_includes_base64_packed_functions [+]