MD5 Hash File type Added Source Yara Hits
84e3ad0d62d21739d632d2106864e79e ELF 2017-10-16 01:20:43 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
b3d26632c4077e731ef2da329974519d ELF 2017-10-16 01:33:40 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
24734ef952fe363415cd4c2f7322276f ELF 2017-10-16 01:37:29 CuckooSandbox/shellcode CuckooSandbox/embedded_pe CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect [+]
91f25b52d9bf833b9ac36e7258e44807 PE32 2018-03-07 02:37:38http://94.130.104.170/dumped.exe YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
7a649649dcbd67b1d0cf4a94cfeb776f UTF-8 2018-03-18 03:07:00 CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/domain YRP/url [+]
f901c645188f9c80afa8f49174f065ce PE32+ 2018-05-24 00:58:05 CuckooSandbox/vmdetect YRP/webshell_iMHaPFtp_2 YRP/webshell_caidao_shell_guo YRP/webshell_cihshell_fix [+]
563fb5eb06e3973674fb28ff8e9fc97c ASCII 2018-06-08 15:10:17 CuckooSandbox/embedded_win_api YRP/Borland YRP/domain YRP/IP [+]
8482556f9867a41cb87e53ea0f84a8d3 ASCII 2018-06-21 13:49:13 YRP/domain YRP/contentis_base64 YRP/System_Tools YRP/Antivirus [+]
b987c15d839fe7440a77566cf240d18e PE32 2018-06-22 17:52:20 YRP/Microsoft_Visual_Cpp_v60_Debug_Version_additional YRP/Microsoft_Visual_Cpp_v50v60_MFC YRP/Microsoft_Visual_Cpp_v60_Debug_Version YRP/Armadillo_v4x [+]
dc97f7dac9c7a06f4297baa9749ed141 PE32 2018-06-23 10:23:45 YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsConsole [+]
40285df2866158b9a1ae3f2c69933ef2 PE32 2018-06-23 10:26:47 YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/Visual_Cpp_2008_Release_Microsoft YRP/IsPE32 [+]
9ebe77b22bd00404a784fbed762780b0 PE32 2018-07-24 12:13:24 YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
00bf88ca5829863f72817984519b1c55 PE32 2018-09-10 13:03:16 CuckooSandbox/vmdetect YRP/Visual_Cpp_2005_Release_Microsoft YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 [+]
aa09b4f4ccd73ab1c447913d8fe8b131 PE32 2018-09-24 01:05:21http://www.heikc.com:2018/arp.exe YRP/IsPE32 YRP/IsConsole YRP/HasRichSignature YRP/domain [+]
ce398550802490629b47b3d771e43951 PE32 2018-09-29 13:36:04 CuckooSandbox/vmdetect YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 [+]
21b4e5f338913037c5a1806f2501a443 PE32 2018-11-13 09:57:30 YRP/IsPE32 YRP/IsConsole YRP/IsBeyondImageSize YRP/Cygwin [+]
1e8c675313160f57f22fe985a36770a2 PE32 2018-12-12 00:49:31 YRP/IsPE32 YRP/IsWindowsGUI YRP/IsBeyondImageSize YRP/HasRichSignature [+]
057d299836ecec09f72a53282bd5910b PE32 2018-12-12 00:49:50 YRP/Armadillo_v171 YRP/Microsoft_Visual_Cpp_v60 YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional YRP/Microsoft_Visual_Cpp_50 [+]
5b54cc63849265c2b76bd118a27d8850 PE32 2019-01-20 12:54:57 YRP/VC8_Microsoft_Corporation YRP/Microsoft_Visual_Cpp_8 YRP/IsPE32 YRP/IsWindowsGUI [+]
46e65c01e995879ad7067d2eff6d8c00 ASCII 2019-03-25 20:44:26 CuckooSandbox/embedded_win_api YRP/domain YRP/url YRP/contentis_base64 [+]
1b76f45f00f2931a55ddef1f5dc09226 exported 2019-06-02 17:28:02 CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/domain YRP/url [+]
68855f4b18fa09e9023ddd9c1b2fdcd0 data 2019-06-05 07:44:50 YRP/Borland YRP/domain YRP/IP YRP/url [+]
148b2fdbc3b67df57c6c9a0fba2e8bcb PE32 2019-07-09 12:12:10http://111.30.107.131:228/Windows.exe YRP/IsPE32 YRP/IsWindowsGUI YRP/IsPacked YRP/HasDebugData [+]
7f0ac1b4e169edc62856731953dad126 PE32 2019-07-30 19:45:51 YRP/IsPE32 YRP/IsWindowsGUI YRP/HasRichSignature YRP/domain [+]
516ad28f8fa161f086be7ca122351edf PE32 2019-07-30 19:49:01 YRP/Microsoft_Visual_Cpp_V80_Debug YRP/Microsoft_Visual_Cpp_80_Debug_ YRP/Microsoft_Visual_Cpp_80_Debug YRP/IsPE32 [+]
b2f8c9ce955d4155d466fbbb7836e08b PE32 2019-07-30 20:00:10 YRP/Microsoft_Visual_Cpp_V80_Debug YRP/Microsoft_Visual_Cpp_80_Debug_ YRP/Microsoft_Visual_Cpp_80_Debug YRP/IsPE32 [+]
4bb3c7fcd43b6a598dd9c44fc1ccef9f PE32 2019-09-16 02:38:44 CuckooSandbox/vmdetect YRP/Visual_Cpp_2003_DLL_Microsoft YRP/IsPE32 YRP/IsConsole [+]
9fa7ddf5382bcdadcb8a9e15ae852bb4 exported 2019-09-18 21:05:24 CuckooSandbox/embedded_win_api CuckooSandbox/vmdetect YRP/domain YRP/url [+]