Files
2019-04-06 19:35:41 +02:00

601 KiB

1ACE_Containing_EXELooks for ACE Archives containing an exe/scr file-2015-09-09 00:00:0050Florian Roth - based on Nick Hoffman' rule - Morphick IncFILE25e3ffe70795c56ef869c65149c41c71
2ALFA_SHELLDetects web shell often used by Iranian APT groupsInternal Research - APT332017-09-21 00:00:0075Florian RothAPT,WEBSHELL469453dad2fbae30d38aafa5fc8ad6a7
3APT10_Malware_Sample_GenAPT 10 / Cloud Hopper malware campaignhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-06 00:00:0080Florian RothAPT,CHINA,GEN,MAL0649cdaf2bf2c92d9b510d04f8f3bfe0
4APT12_Malware_Aug17Detects APT 12 Malwarehttp://blog.macnica.net/blog/2017/08/post-fb81.html2017-08-30 00:00:0075Florian RothAPT,EXE,FILE,MAL389a7a0aba0ca219a35d24f7cce571cc
5APT15_Malware_Mar18_BS2005Detects malware from APT 15 report by NCC Grouphttps://goo.gl/HZ5XMN2018-03-10 00:00:0075Florian RothAPT,EXE,FILE,MALf16b4312e0d0dde001dc6af87c8789b5
6APT15_Malware_Mar18_MSExchangeToolDetects malware from APT 15 report by NCC Grouphttps://goo.gl/HZ5XMN2018-03-10 00:00:0075Florian RothAPT,EXE,FILE,MAL63dd5feec94e34664b2264fdf8460484
7APT15_Malware_Mar18_RoyalCliDetects malware from APT 15 report by NCC Grouphttps://goo.gl/HZ5XMN2018-03-10 00:00:0075Florian RothAPT,EXE,FILE,MAL73c96ae158f506c87d0537333b80e3c5
8APT15_Malware_Mar18_RoyalDNSDetects malware from APT 15 report by NCC Grouphttps://goo.gl/HZ5XMN2018-03-10 00:00:0075Florian RothAPT,EXE,FILE,MAL9c2fb9f5dba2cbf05cd3a259aa9b453d
9APT17_Malware_Oct17_1Detects APT17 malwarehttps://goo.gl/puVc9q2017-10-03 00:00:0075Florian RothAPT,EXE,FILE,MAL08b41a3e2a062f8d9acd219263b7f035
10APT17_Malware_Oct17_2Detects APT17 malwarehttps://goo.gl/puVc9q2017-10-03 00:00:0075Florian RothAPT,EXE,FILE,MAL88c86ccb80f6a61690facd025dd17946
11APT17_Malware_Oct17_GenDetects APT17 malwarehttps://goo.gl/puVc9q2017-10-03 00:00:0075Florian RothAPT,EXE,FILE,GEN,MALfe6b57c0e6c98d344bb2842615a68161
12APT17_Sample_FXSST_DLLDetects Samples related to APT17 activity - file FXSST.DLLhttps://goo.gl/ZiJyQv2015-05-14 00:00:0075Florian RothAPT,EXE,FILE,MAL2ac052f29ea53de7a58b4b73502d2229
13APT17_Unsigned_Symantec_Binary_EFADetects APT17 malwarehttps://goo.gl/puVc9q2017-10-03 00:00:0075Florian RothAPT,EXE,FILE01ab888843f68b2902c7f5a69c1abe33
14APT28_CHOPSTICKDetects a malware that behaves like CHOPSTICK mentioned in APT28 reporthttps://goo.gl/v3ebal2015-06-02 00:00:0060Florian RothAPT,EXE,FILE,RUSSIA7cce8362c5381282c0df3eb6c3eb9156
15APT28_HospitalityMalware_documentYara Rule for APT28_Hospitality_Malware document identificationhttp://csecybsec.com/download/zlab/APT28_Hospitality_Malware_report.pdf1970-01-01 01:00:0075CSE CybSec Enterprise - Z-LabAPT,MAL,RUSSIA3f5c202664a898ea2c371851aae63d32
16APT28_HospitalityMalware_mvtband_fileYara Rule for mvtband.dll malwarehttp://csecybsec.com/download/zlab/APT28_Hospitality_Malware_report.pdf1970-01-01 01:00:0075CSE CybSec Enterprise - Z-LabEXTVAR,RUSSIAb8b0d2a41f42aa2529ae15ec986e1e3f
17APT28_SourFace_Malware1Detects Malware from APT28 incident - SOURFACE is a downloader that obtains a second-stage backdoor from a C2 server.https://www.fireeye.com/blog/threat-research/2014/10/apt28-a-window-into-russias-cyber-espionage-operations.html2015-06-01 00:00:0060Florian RothAPT,EXE,FILE,MAL,RUSSIA02aedce037d2125858f8e19dd988556d
18APT28_SourFace_Malware2Detects Malware from APT28 incident - SOURFACE is a downloader that obtains a second-stage backdoor from a C2 server.https://www.fireeye.com/blog/threat-research/2014/10/apt28-a-window-into-russias-cyber-espionage-operations.html2015-06-01 00:00:0060Florian RothAPT,EXE,FILE,MAL,RUSSIA05b146ef78dc991baee4121b4c702c3b
19APT28_SourFace_Malware3Detects Malware from APT28 incident - SOURFACE is a downloader that obtains a second-stage backdoor from a C2 server.https://www.fireeye.com/blog/threat-research/2014/10/apt28-a-window-into-russias-cyber-espionage-operations.html2015-06-01 00:00:0060Florian RothAPT,EXE,FILE,MAL,RUSSIA178a2c12a1bac4d04c92fae9f90f159c
20APT30_Generic_1FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENfe1d94587cebf1518cc407ffe6ab38f4
21APT30_Generic_2FireEye APT30 Report Sample - from many fileshttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN5da8fa4357c3fd250ce879b543b61a28
22APT30_Generic_3FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENbf9bb849cd6b71f57dc258a0f4c815b0
23APT30_Generic_4FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENcc1fc38876cf2475a899b4bd8260fac4
24APT30_Generic_5FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN8d9c92e796d19542b77a5f82e70f8591
25APT30_Generic_6FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN991e6f873e99c148692e9159583b73cf
26APT30_Generic_7FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN4aee9ac419c2d05737a23dfcdffd1cb4
27APT30_Generic_8FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN05b8fb856120648c596b8ceec7a510b8
28APT30_Generic_9FireEye APT30 Report Samplehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN73e89128560cf46d4230faed5a457b46
29APT30_Generic_AFireEye APT30 Report Sample - file af1c1c5d8031c4942630b6a10270d8f4https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENa9a85fb6c4a338a71e8a30716145f12f
30APT30_Generic_BFireEye APT30 Report Sample - file 29395c528693b69233c1c12bef8a64b3https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENa0534ff9c4f277fb354c2f7b3f58fbc8
31APT30_Generic_CFireEye APT30 Report Sample - file 0c4fcef3b583d0ffffc2b14b9297d3a4https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN2879b2af568ca54a3348416e449f189c
32APT30_Generic_DFireEye APT30 Report Sample - file 597805832d45d522c4882f21db800ecfhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENc33de9e37ff6277b302bb8194755c682
33APT30_Generic_EFireEye APT30 Report Sample - file 8ff473bedbcc77df2c49a91167b1abebhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENe4a30568e98b12f3718e850d7ee35d97
34APT30_Generic_E_v2FireEye APT30 Report Sample - file 71f25831681c19ea17b2f2a84a41bbfbhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN22141fbdcca6b014f9566519cd7c298a
35APT30_Generic_FFireEye APT30 Report Sample - file 4c10a1efed25b828e4785d9526507fbchttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENa20b2bce01631cdc7f5eead7244ad533
36APT30_Generic_GFireEye APT30 Report Sample - file 53f1358cbc298da96ec56e9a08851b4bhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENe9511d1a54b3a5471fb26c191793007d
37APT30_Generic_HFireEye APT30 Report Sample - file db3e5c2f2ce07c2d3fa38d6fc1ceb854https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENafec35d66fa2b1735045e03f20b988d8
38APT30_Generic_IFireEye APT30 Report Sample - file fe211c7a081c1dac46e3935f7c614549https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN3443195777e0c12a1a59b13b3def6bee
39APT30_Generic_JFireEye APT30 Report Sample - file baff5262ae01a9217b10fcd5dad9d1d5https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GENd8843c47f355a0126011a2bdf6e899b1
40APT30_Generic_KFireEye APT30 Report Sample - file b5a343d11e1f7340de99118ce9fc1bbbhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE,GEN7b54039f2298405d3426794afbe69948
41APT30_MicrofostFireEye APT30 Report Sample - file 310a4a62ba3765cbf8e8bbb9f324c503https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE8d43f03efce7c13905060a6d5239dc1d
42APT30_Sample_10FireEye APT30 Report Sample - file 8c713117af4ca6bbd69292a78069e75bhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEf1ad8a3c0803f9d74c27eacd1c96c51a
43APT30_Sample_11FireEye APT30 Report Sample - file d97aace631d6f089595f5ce177f54a39https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE14ca1d119f921ebb0a551287ab221272
44APT30_Sample_12FireEye APT30 Report Sample - file c95cd106c1fecbd500f4b97566d8dc96https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE57c8a9ade58f4b474a3d8d12c317b2ae
45APT30_Sample_13FireEye APT30 Report Sample - file 95bb314fe8fdbe4df31a6d23b0d378bchttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE177691765cc479d1d7855d08fc2aef14
46APT30_Sample_14FireEye APT30 Report Sample - file 6f931c15789d234881be8ae8ccfe33f4https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE7ba755fcc71af84a84b29a0731e455ff
47APT30_Sample_15FireEye APT30 Report Sample - file e26a2afaaddfb09d9ede505c6f1cc4e3https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE409c2c6270d7b3f5af3617fd4e84e623
48APT30_Sample_16FireEye APT30 Report Sample - file 37e568bed4ae057e548439dc811b4d3ahttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE1467c951d41899bac55e7ea7f6dfc819
49APT30_Sample_17FireEye APT30 Report Sample - file 23813c5bf6a7af322b40bd2fd94bd42ehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE349e51ebbcca4928e207d36dd92a554b
50APT30_Sample_18FireEye APT30 Report Sample - file b2138a57f723326eda5a26d2dec56851https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE0772747cbbac471913191d5291a42572
51APT30_Sample_19FireEye APT30 Report Sample - file 5d4f2871fd1818527ebd65b0ff930a77https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE0762804dab920ccca6a4463457c5824a
52APT30_Sample_1FireEye APT30 Report Sample - file 4c6b21e98ca03e0ef0910e07cef45dachttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE1b9d4a94c6f1bcb1e82a63a6365484c7
53APT30_Sample_20FireEye APT30 Report Sample - file 5ae51243647b7d03a5cb20dccbc0d561https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE4e4615a9dbefa88a3cbdd39ec25c1b54
54APT30_Sample_21FireEye APT30 Report Sample - file 78c4fcee5b7fdbabf3b9941225d95166https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEaaf852089c60a676f2337579066b53d0
55APT30_Sample_22FireEye APT30 Report Sample - file fad06d7b4450c4631302264486611ec3https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEd32e02724030536f5111eda2c4b2a515
56APT30_Sample_23FireEye APT30 Report Sample - file a5ca2c5b4d8c0c1bc93570ed13dcab1ahttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE564ecfff275f5e4a48dc5838d24bafc2
57APT30_Sample_24FireEye APT30 Report Sample - file 062fe1336459a851bd0ea271bb2afe35https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEc58c25f17ab1b86165a4fffa6272cbac
58APT30_Sample_25FireEye APT30 Report Sample - file c4c068200ad8033a0f0cf28507b51842https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE8b2bdcc232d698858b6f08cf30774b83
59APT30_Sample_26FireEye APT30 Report Sample - file 428fc53c84e921ac518e54a5d055f54ahttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEc3ab3ebe8a2505ec6567411f54b1cbfb
60APT30_Sample_27FireEye APT30 Report Sample - file d38e02eac7e3b299b46ff2607dd0f288https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEf9cadec46c18a434ddfb4f685d6ecf9d
61APT30_Sample_28FireEye APT30 Report Sample - file e62a63307deead5c9fcca6b9a2d51fb0https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEd31f17012fbb5f3982902660788945c2
62APT30_Sample_29FireEye APT30 Report Sample - file 1b81b80ff0edf57da2440456d516cc90https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE35f722d2d0fdc6212953d8c046d55a74
63APT30_Sample_2FireEye APT30 Report Sample - file c4dec6d69d8035d481e4f2c86f580e81https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE3333c6d5755d334a287d3a013c6953db
64APT30_Sample_30FireEye APT30 Report Sample - file bf8616bbed6d804a3dea09b230c2ab0chttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE1e06ca1cc167639ccac881b93e5e0eb2
65APT30_Sample_31FireEye APT30 Report Sample - file d8e68db503f4155ed1aeba95d1f5e3e4https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEa27a27964a61ad2d78eddf76eac6ab65
66APT30_Sample_33FireEye APT30 Report Sample - file 5eaf3deaaf2efac92c73ada82a651afehttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE70e471485ef80e48097b1839332faa4e
67APT30_Sample_34FireEye APT30 Report Sample - file a9e8e402a7ee459e4896d0ba83543684https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE3170af458456cb72a3a27d9e7d349767
68APT30_Sample_35FireEye APT30 Report Sample - file 414854a9b40f7757ed7bfc6a1b01250fhttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE8e4583021e94a2f804e4de286a81a011
69APT30_Sample_3FireEye APT30 Report Sample - file 59e055cee87d8faf6f701293e5830b5ahttps://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE78a32fff1fde9b722ace5ed7e10bd31e
70APT30_Sample_4FireEye APT30 Report Sample - file 6ba315275561d99b1eb8fc614ff0b2b3https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE8c85fd66417d880198fcc7237800fa69
71APT30_Sample_5FireEye APT30 Report Sample - file ebf42e8b532e2f3b19046b028b5dfb23https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEf658f116c06cac879213d69e8f669b40
72APT30_Sample_6FireEye APT30 Report Sample - file ee1b23c97f809151805792f8778ead74https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE05282a8a968e6797220b07b7b437f6c7
73APT30_Sample_7FireEye APT30 Report Sample - file 74b87086887e0c67ffb035069b195ac7https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEb35e34d35f51e98f02aa47039ea1a7f6
74APT30_Sample_8FireEye APT30 Report Sample - file 44b98f22155f420af4528d17bb4a5ec8https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILE9c3cff51e5b163f9b9a1ffda24048705
75APT30_Sample_9FireEye APT30 Report Sample - file e3ae3cbc024e39121c87d73e87bb2210https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf2015-04-13 00:00:0075Florian RothAPT,FILEc890bfe8b5df7a67ddaab42857af47a6
76APT34_Malware_ExerunerDetects APT 34 malwarehttps://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html2017-12-07 00:00:0075Florian RothAPT,EXE,FILE,MAL,MIDDLE_EAST69ada7dd7d1f48ce90aa156b84dd752b
77APT34_Malware_HTADetects APT 34 malwarehttps://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html2017-12-07 00:00:0075Florian RothAPT,MAL,MIDDLE_EAST819d957427d626ea2ec2851b1c5fe99c
78APT6_Malware_Sample_GenRule written for 2 malware samples that communicated to APT6 C2 servershttps://otx.alienvault.com/pulse/56c4d1664637f26ad04e5b73/2016-04-09 00:00:0080Florian RothAPT,EXE,FILE,GEN,MALa0fb19cb9984d92bc59db250ce6ed255
79APTGroupX_PlugXTrojanLoader_StringDecodeRule to detect PlugX Malwarehttps://t.co/4xQ8G2mNap1970-01-01 01:00:0080Jay DiMartinoMALf9300e67d61b85f3be3f9161b362d1ad
80APT_APT10_Malware_Imphash_Dec18_1Detects APT10 malware based on ImpHashesAlienVault OTX IOCs - statistical sample analysis2018-12-28 00:00:0075Florian RothAPT,CHINA,EXE,FILE,MAL6e2087b6abb48da2f67d25c43a8d95b1
81APT_APT28_Cannon_Trojan_Nov18_1Detects Cannon Trojan used by Sofacyhttps://researchcenter.paloaltonetworks.com/2018/11/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan/2018-11-20 00:00:0075Florian RothAPT,EXE,FILE,MAL,RUSSIA874b39ec14a7d1f15a0b6095ed66f33a
82APT_Area1_SSF_GoogleSend_StringsDetects send tool used in phishing campaign reported by Area 1 in December 2018https://cdn.area1security.com/reports/Area-1-Security-PhishingDiplomacy.pdf2018-12-19 00:00:0075Area 1 (modified by Florian Roth)APT,EXE,FILE0a23b99fcbf29d6e0e24d8b0487f0f93
83APT_Area1_SSF_PlugXDetects send tool used in phishing campaign reported by Area 1 in December 2018https://cdn.area1security.com/reports/Area-1-Security-PhishingDiplomacy.pdf2018-12-19 00:00:0075Area 1APTfdf36018ac3dac89649c94a139ed1539
84APT_Cloaked_PsExecLooks like a cloaked PsExec. May be APT group activity.-2014-07-18 00:00:0060Florian RothAPT,EXE,EXTVAR,FILE0443bf568d17de127ae3eaaa789a156b
85APT_Cloaked_ScanLineLooks like a cloaked ScanLine Port Scanner. May be APT group activity.-2014-07-18 00:00:0050Florian RothAPT,EXE,EXTVAR,FILE,HKTLa2b258e6701a526d5afb3850fd52083d
86APT_Cloaked_SuperScanLooks like a cloaked SuperScan Port Scanner. May be APT group activity.-2014-07-18 00:00:0050Florian RothAPT,EXE,EXTVAR,FILE,HKTL907a9e92a733e7a9d8df45fb93a0d023
87APT_CobaltStrike_Beacon_IndicatorDetects CobaltStrike beaconshttps://github.com/JPCERTCC/aa-tools/blob/master/cobaltstrikescan.py2018-11-09 00:00:0075JPCERTAPT,EXE,FILE5380485dc275908e4cac5731b8cc9a08
88APT_DarkHydrus_Jul18_1Detects strings found in malware samples in APT report in DarkHydrushttps://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/2018-07-28 00:00:0075Florian RothAPT,EXE,FILE,MIDDLE_EASTb651d033ca15b5028ad57c7886f5a343
89APT_DarkHydrus_Jul18_2Detects strings found in malware samples in APT report in DarkHydrushttps://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/2018-07-28 00:00:0075Florian RothAPT,EXE,FILE,MIDDLE_EASTf84af612bfe4e856885feaaa6c911b08
90APT_DarkHydrus_Jul18_3Detects strings found in malware samples in APT report in DarkHydrushttps://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/2018-07-28 00:00:0075Florian RothAPT,EXE,FILE,MIDDLE_EAST69b866acc6899c583919db3e7e09ebda
91APT_DarkHydrus_Jul18_4Detects strings found in malware samples in APT report in DarkHydrushttps://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/2018-07-28 00:00:0075Florian RothAPT,EXE,FILE,MIDDLE_EAST9c57a24ada5685d6e6b93ab4bfea7637
92APT_DarkHydrus_Jul18_5Detects strings found in malware samples in APT report in DarkHydrushttps://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/2018-07-28 00:00:0075Florian RothAPT,EXE,FILE,MIDDLE_EASTe84e68b7618884588bd6f776c6b0d689
93APT_DonotTeam_YTYframeworkModular malware framework with similarities to EHDevelarbornetworks.com/blog/asert/don2018-08-03 00:00:0075James E.C, ProofPointAPT,FILE136f2bdeeda5a19363961d060331947c
94APT_FIN7_EXE_Sample_Aug18_10Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAc5db62ea6f8b5e4576258bea857020fd
95APT_FIN7_EXE_Sample_Aug18_1Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAaa76e34953d18a24728d0f4217c6586f
96APT_FIN7_EXE_Sample_Aug18_2Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA9a953dcd27e95bca8e8c062e5a748ce1
97APT_FIN7_EXE_Sample_Aug18_3Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA9a4375419e88fa4ddba9fec09d42af1f
98APT_FIN7_EXE_Sample_Aug18_4Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAebeb4eed696df08f224dad1dbb039677
99APT_FIN7_EXE_Sample_Aug18_5Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA0d28c3976fdbe57bbfd0e494374d4fe9
100APT_FIN7_EXE_Sample_Aug18_6Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAaa3c712d6085d59a241c5b25604692d0
101APT_FIN7_EXE_Sample_Aug18_7Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA8bb7bd379468c65dba3fd69188de4527
102APT_FIN7_EXE_Sample_Aug18_8Detects sample from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAcc7341764212bef3c1e1ccb7c6ab66bb
103APT_FIN7_MalDoc_Aug18_1Detects malicious Doc from FIN7 campaignhttps://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,RUSSIAb867d4a326ef36a400372e4e76462760
104APT_FIN7_Sample_Aug18_1Detects FIN7 samples mentioned in FireEye reporthttps://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,FILE,RUSSIAc2acdcf6f4989a335e0fa5dd4b31e8e0
105APT_FIN7_Sample_Aug18_2Detects FIN7 malware samplehttps://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,FILE,RUSSIA0df1456663be95d991e03d35c2a8c018
106APT_FIN7_Sample_EXE_Aug18_1Detects FIN7 Samplehttps://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,EXE,FILE,RUSSIAdfb8dcf78be259a2ff4c6db2d4ea009c
107APT_FIN7_Strings_Aug18_1Detects strings from FIN7 report in August 2018https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html2018-08-01 00:00:0075Florian RothAPT,RUSSIA130d7a4b3d12d94331598ae75184f512
108APT_FallChill_RC4_KeysDetects FallChill RC4 keyshttps://securelist.com/operation-applejeus/87553/2018-08-21 00:00:0075Florian RothAPT,EXE,FILE4b5013fcabc0b64d3e57daa4b1423436
109APT_GreyEnergy_Malware_Oct18_1Detects samples from Grey Energy reporthttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0075Florian RothAPT,EXE,FILE,MAL417bb04c18efa14ede7f2187a5e81ab1
110APT_GreyEnergy_Malware_Oct18_2Detects samples from Grey Energy reporthttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0075Florian RothAPT,EXE,FILE,MAL25494921f5c155770a1ed4d19850e2d4
111APT_GreyEnergy_Malware_Oct18_3Detects samples from Grey Energy reporthttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0075Florian RothAPT,EXE,FILE,MALa2fb0917d72762344f9526d6e7c27417
112APT_GreyEnergy_Malware_Oct18_4Detects samples from Grey Energy reporthttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0075Florian RothAPT,EXE,FILE,MAL713a4f65c36c19c4ebe7d523fe29f5ac
113APT_GreyEnergy_Malware_Oct18_5Detects samples from Grey Energy reporthttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0075Florian RothAPT,EXE,FILE,MALb7e2162f7eb8bd8aba59a91e2ac7fb43
114APT_HiddenCobra_GhostSecret_1Detects Hidden Cobra Samplehttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide/2018-08-11 00:00:0075Florian RothAPT,EXE,FILE,NK0396d3a9a2714271358ea538a2b21da2
115APT_HiddenCobra_GhostSecret_2Detects Hidden Cobra Samplehttps://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide/2018-08-11 00:00:0075Florian RothAPT,EXE,FILE,NKc03b4c575274fe92be010449bd65f112
116APT_HiddenCobra_enc_PK_headerHidden Cobra - Detects trojan with encrypted headerhttps://www.us-cert.gov/ncas/analysis-reports/AR18-165A2018-04-12 00:00:0075NCCIC trusted 3rd party - Edit: Tobias MichalskiAPT,FILE,NK2502e27de56191163efa6acc51bb1061
117APT_HiddenCobra_import_obfuscation_2Hidden Cobra - Detects remote access trojanhttps://www.us-cert.gov/ncas/analysis-reports/AR18-165A2018-04-12 00:00:0075NCCIC trusted 3rd party - Edit: Tobias MichalskiAPT,FILE,NK,OBFUSc114694e143f8cb1e511cbe3ccc28fd0
118APT_Kaspersky_Duqu2_SamsungPrintKaspersky APT Report - Duqu2 Sample - file 2a9a5afc342cde12c6eb9a91ad29f7afdfd8f0fb17b983dcfddceccfbc17af69https://goo.gl/7yKyOj2015-06-10 00:00:0075Florian RothAPT,EXE,FILE47745f831e1771d08f56c5f3f550612b
119APT_Kaspersky_Duqu2_msi3_32Kaspersky APT Report - Duqu2 Sample - file d8a849654ab97debaf28ae5b749c3b1ff1812ea49978713853333db48c3972c3https://goo.gl/7yKyOj2015-06-10 00:00:0075Florian RothAPT,EXE,FILE242dda6b6b6acbb4a231f071e30df518
120APT_Kaspersky_Duqu2_procexpKaspersky APT Report - Duqu2 Sample - Malicious MSIhttps://goo.gl/7yKyOj2015-06-10 00:00:0075Florian RothAPT,EXE,FILEe05f23fa6212b7879ad5c54ef5c567f1
121APT_Lazarus_Aug18_1Detects Lazarus Group Malwarehttps://securelist.com/operation-applejeus/87553/2018-08-24 00:00:0075Florian RothAPT,EXE,FILE,MAL,NKb968cecce9632b4f5e359819edf14bad
122APT_Lazarus_Aug18_2Detects Lazarus Group Malwarehttps://securelist.com/operation-applejeus/87553/2018-08-24 00:00:0075Florian RothAPT,EXE,FILE,MAL,NK0247f90fa9095549dc79ab5dfaa9afb9
123APT_Lazarus_Aug18_Downloader_1Detects Lazarus Group Malware Downloaderyhttps://securelist.com/operation-applejeus/87553/2018-08-24 00:00:0075Florian RothAPT,EXE,FILE,MAL,NK63151c7429dba5ee7cfb74287147456b
124APT_Lazarus_Dropper_Jun18_1Detects Lazarus Group Dropperhttps://twitter.com/DrunkBinary/status/10025875210737213462018-06-01 00:00:0075Florian RothAPT,EXE,FILE,MAL,NK2e5ab44793cc3a4f8669162213309c47
125APT_Lazarus_RAT_Jun18_1Detects Lazarus Group RAThttps://twitter.com/DrunkBinary/status/10025875210737213462018-06-01 00:00:0075Florian RothAPT,EXE,FILE,MAL,NK2f5026b3b45edf547f6b59fca5f14b22
126APT_Lazarus_RAT_Jun18_2Detects Lazarus Group RAThttps://twitter.com/DrunkBinary/status/10025875210737213462018-06-01 00:00:0075Florian RothAPT,EXE,FILE,MAL,NKe24e9743324976b49232860679e54d4d
127APT_LiudoorDetects Liudoor daemon backdoor-2015-07-23 00:00:0075RSA FirstWatchAPT,MALdf75e72b1850464de866832f0fb7e432
128APT_MAL_DNS_Hijacking_Campaign_AA19_024ADetects malware used in DNS Hijackign campaignhttps://www.us-cert.gov/ncas/alerts/AA19-024A2019-01-25 00:00:0075Florian RothAPT,EXE,FILE74a54b611b333f749e264b527b244c1a
129APT_ME_BigBang_Gen_Jul18_1Detects malware from Big Bang campaign against Palestinian authoritieshttps://research.checkpoint.com/apt-attack-middle-east-big-bang/2018-07-09 00:00:0075Florian RothAPT,EXE,FILE,GENf1e013ec5b8f6aeec6fc98391bc694cc
130APT_ME_BigBang_Mal_Jul18_1Detects malware from Big Bang reporthttps://research.checkpoint.com/apt-attack-middle-east-big-bang/2018-07-09 00:00:0075Florian RothAPT,EXE,FILE5d7a2550cfecbb2e6fa07d9509252b4b
131APT_MagicHound_MalMacroDetects malicious macro / powershell in Office documenthttps://www.secureworks.com/blog/iranian-pupyrat-bites-middle-eastern-organizations2017-02-17 00:00:0075Florian RothAPT,FILE,OFFICE768633d484dd36908416bffe638c1647
132APT_Malware_CommentCrew_MiniASPCommentCrew Malware MiniASP APTVT Analysis2015-06-03 00:00:0075Florian RothAPT,EXE,FILE,MALa3b714945a91061a9f3c15dca27f652d
133APT_Malware_PutterPanda_Gen1Detects a malware not set2015-06-03 00:00:0075YarGen Rule GeneratorAPT,EXE,FILE,MALd6393b376fd3295f10921be72475846a
134APT_Malware_PutterPanda_Gen4Detects Malware related to PutterPandaVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MAL4602e2bbe8b06d4adb03123a5db0a1eb
135APT_Malware_PutterPanda_MsUpdater_1Detects Malware related to PutterPanda - MSUpdaterVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MAL62f69d46210e12fe401e56f901fdb5af
136APT_Malware_PutterPanda_MsUpdater_2Detects Malware related to PutterPanda - MSUpdaterVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MAL87e2474c8bf0220c02a57dd0f01c5c3a
137APT_Malware_PutterPanda_MsUpdater_3Detects Malware related to PutterPanda - MSUpdaterVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MALaa99b02760344bafd1edc132a8e809ec
138APT_Malware_PutterPanda_PSAPIDetects a malware related to Putter PandaVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MAL756ceadee9087abddcefa10d379fe73e
139APT_Malware_PutterPanda_RelDetects an APT malware related to PutterPandaVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MAL83c7029886bc572d4d3152499d7b9b4f
140APT_Malware_PutterPanda_Rel_2APT Malware related to PutterPanda GroupVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,EXE,FILE,MALd8aac4d61260f18f1cf2f45b16458a37
141APT_Malware_PutterPanda_WUAUCLTDetects a malware related to Putter PandaVT Analysis2015-06-03 00:00:0070Florian RothAPT,CHINA,MAL036c84b599ab24a61b602c9435f936db
142APT_NK_AR18_165A_1Detects APT malware from AR18-165A report by US CERThttps://www.us-cert.gov/ncas/analysis-reports/AR18-165A2018-06-15 00:00:0075Florian RothAPT,EXE,FILE32b90b0c9c4fc974b03b0ec757a23457
143APT_NK_AR18_165A_HiddenCobra_import_deobHidden Cobra - Detects installed proxy module as a servicehttps://www.us-cert.gov/ncas/analysis-reports/AR18-165A2018-04-12 00:00:0075NCCIC trusted 3rd party - Edit: Tobias MichalskiAPT,FILE,NKc4200d68bb1633295b87464cb797bffb
144APT_Project_Sauron_Custom_M1Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILE4e91d0b33284ea30079ce886bdcb212a
145APT_Project_Sauron_Custom_M2Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILEdad36d29819639821437138975f2caa2
146APT_Project_Sauron_Custom_M3Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILE00e18a86832995ec47774c3ed39687b2
147APT_Project_Sauron_Custom_M4Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILE6a363a45bbf20c1dc10cc2d00ee9e495
148APT_Project_Sauron_Custom_M6Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILE7c3291cd11ef684d0ff6386d80963046
149APT_Project_Sauron_Custom_M7Detects malware from Project Sauron APThttps://goo.gl/eFoP4A2016-08-09 00:00:0075Florian RothAPT,EXE,FILE9b63e16a3ed9a07bb2abb39b063e0e1c
150APT_Project_Sauron_ScriptsDetects scripts (mostly LUA) from Project Sauron report by Kasperskyhttps://goo.gl/eFoP4A2016-08-08 00:00:0075Florian RothAPT91a9845d427b6228911040f8038da40a
151APT_Project_Sauron_arping_moduleDetects strings from arping module - Project Sauron report by Kasperskyhttps://goo.gl/eFoP4A2016-08-08 00:00:0075Florian RothAPTf03f1968bc51e724055967fb4a046a14
152APT_Project_Sauron_basex_moduleDetects strings from basex module - Project Sauron report by Kasperskyhttps://goo.gl/eFoP4A2016-08-08 00:00:0075Florian RothAPT16cf8f05aa3907e85ec798fc096479e0
153APT_Project_Sauron_dext_moduleDetects strings from dext module - Project Sauron report by Kasperskyhttps://goo.gl/eFoP4A2016-08-08 00:00:0075Florian RothAPTda2b1be9edaa32bd0aa2efaf52f7f418
154APT_Project_Sauron_kblogi_moduleDetects strings from kblogi module - Project Sauron report by Kasperskyhttps://goo.gl/eFoP4A2016-08-08 00:00:0075Florian RothAPTec07e689a011e6a31d319b3999da0bb3
155APT_Proxy_Malware_Packed_devAPT Malware - Proxy-2014-11-10 00:00:0050FRothAPT,HKTL,MAL4fd49d834248d564bdb9933ab43d17e5
156APT_PupyRAT_PYDetects Pupy RAThttps://www.secureworks.com/blog/iranian-pupyrat-bites-middle-eastern-organizations2017-02-17 00:00:0075Florian RothAPT,EXE,FILE,MAL09a191b2c03fa158d39f13231101b7e9
157APT_RANCOR_DDKONG_Malware_ExportsDetects DDKONG malwarehttps://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/2018-06-26 00:00:0075Florian RothAPT,EXE,FILE,MALd7560fb5113904c0c354f2bc4b86b911
158APT_RANCOR_JS_MalwareRancor Malwarehttps://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/2018-06-26 00:00:0075Florian RothAPT,FILE,MAL2c3ad5e74ac6c69e11c902c039ca2609
159APT_RANCOR_PLAINTEE_Malware_ExportsDetects PLAINTEE malwarehttps://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/2018-06-26 00:00:0075Florian RothAPT,EXE,FILE,MAL13916744f5dbd4b900db9b9f24fa5c06
160APT_RANCOR_PLAINTEE_VariantDetects PLAINTEE malwarehttps://researchcenter.paloaltonetworks.com/2018/06/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/2018-06-26 00:00:0075Florian RothAPT,EXE,FILE89eb8706e9b0319a15f3fe87091c69e9
161APT_Script_AUS_4Detetcs a script involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPTbbab688544d15089b70b810eed4f42ce
162APT_TA18_149A_Joanap_Sample1Detects malware from TA18-149A report by US-CERThttps://www.us-cert.gov/ncas/alerts/TA18-149A2018-05-30 00:00:0075Florian RothAPT,EXE,FILE22854bce2a4cb9668af7560676ef3f5b
163APT_TA18_149A_Joanap_Sample2Detects malware from TA18-149A report by US-CERThttps://www.us-cert.gov/ncas/alerts/TA18-149A2018-05-30 00:00:0075Florian RothAPT,EXE,FILE825dcfc720d736eb38b391ac567b8ac7
164APT_TA18_149A_Joanap_Sample3Detects malware from TA18-149A report by US-CERThttps://www.us-cert.gov/ncas/alerts/TA18-149A2018-05-30 00:00:0075Florian RothAPT,EXE,FILE41361f529408f78752ef4dafa298f688
165APT_Thrip_Sample_Jun18_10Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE5505225b0656a48ae0080f2505d5b125
166APT_Thrip_Sample_Jun18_11Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE68fbc87a090b4657e9320f4c1fdeee0c
167APT_Thrip_Sample_Jun18_12Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE310659f9e5facfca8b57015698c845f2
168APT_Thrip_Sample_Jun18_13Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE97686ef26597255211b1f013a1769fa7
169APT_Thrip_Sample_Jun18_14Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILEb3229a509922511aa17d441bcf60bd9c
170APT_Thrip_Sample_Jun18_15Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE4eafdd297e00ce45c3bda4f9fecc4ec5
171APT_Thrip_Sample_Jun18_16Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE6624479e657a33b7d8b4b9f5551e66df
172APT_Thrip_Sample_Jun18_17Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE48e6e9e05e9fd58b3e0244976ee9b947
173APT_Thrip_Sample_Jun18_18Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILEf82008ea0e930ee78eebf40fe7b06a4b
174APT_Thrip_Sample_Jun18_1Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILEbd85d955f29d90efa1892523481d92f9
175APT_Thrip_Sample_Jun18_2Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE072da4a7c4a18fed64e26f24b80e4ab8
176APT_Thrip_Sample_Jun18_3Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE681acf80e792f90a6a57a6760ab13cb0
177APT_Thrip_Sample_Jun18_4Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILEd6f4818c1ca83ffcf25ad91bffb1a41f
178APT_Thrip_Sample_Jun18_5Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE59d58dd876e31e1f0a48f76b81af0ebc
179APT_Thrip_Sample_Jun18_6Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE885b0ef5472feabc36e6adab633f2c12
180APT_Thrip_Sample_Jun18_7Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILEaa6534d29321a7604e7002e67f0c399b
181APT_Thrip_Sample_Jun18_8Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT5e0c7a650501521d8f076b6a19948892
182APT_Thrip_Sample_Jun18_9Detects sample found in Thrip report by Symantec https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets 2018-06-21 00:00:0075Florian RothAPT,EXE,FILE76cb7ecfbd2b761cfaabae73666adcc0
183APT_Tick_HomamDownloader_Jun18Detects HomamDownloader from Tick group incident - Weaponized USBhttps://researchcenter.paloaltonetworks.com/2018/06/unit42-tick-group-weaponized-secure-usb-drives-target-air-gapped-critical-systems/2018-06-23 00:00:0075Florian RothAPT,EXE,FILEaaf3cf99c4ad24675325ad060e4abfe2
184APT_Tick_Sysmon_Loader_Jun18Detects Sysmon Loader from Tick group incident - Weaponized USBhttps://researchcenter.paloaltonetworks.com/2018/06/unit42-tick-group-weaponized-secure-usb-drives-target-air-gapped-critical-systems/2018-06-23 00:00:0075Florian RothAPT,EXE,FILE2eee100ad35b654d3ba0795089b42612
185APT_Turla_Agent_BTZ_Gen_1Detects Turla Agent.BTZInternal Research2018-06-16 00:00:0080Florian RothAPT,EXE,FILE,GEN,RUSSIA954fbf13ceb44f194cdfa8f6b475133f
186APT_WebShell_AUS_4Detetcs a webshell involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPT,FILEb917ec27375f65f4d5456997b9908c85
187APT_WebShell_AUS_5Detetcs a webshell involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPT,FILEc7da99b5ca7eaea74482829f77f3774d
188APT_WebShell_AUS_JScript_3Detetcs a webshell involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPT,FILEf2f38cd4ee8bcf9bfc9850b3149e7d96
189APT_WebShell_AUS_Tiny_2Detetcs a tiny webshell involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPT,FILEe8372bb28854117dc39430efa0b534f2
190APT_WebShell_Tiny_1Detetcs a tiny webshell involved in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothAPT,FILE5290299f5b4360e6da135e2a1ee34fb7
191ASPXspy2Web shell - file ASPXspy2.aspxnot set2015-01-24 00:00:0075Florian RothWEBSHELL64bcf8b4482b74a98f0785ef682a7b43
192ASP_CmdAspWebshells Auto-generated - file CmdAsp.asp-1970-01-01 01:00:0075Florian RothWEBSHELL5b76cd35652a09169872813539f7a9f8
193ASPack_ASPACKDisclosed hacktool set (old stuff) - file ASPACK.EXE-2014-11-23 00:00:0060Florian RothHKTL61aceaec0a789fdcfca7398e1e3a7f33
194ASPack_ChineseDisclosed hacktool set (old stuff) - file ASPack Chinese.ini-2014-11-23 00:00:0060Florian RothCHINA,HKTL12b02c0b768afa6ee47a142304445ad7
195ATM_Malware_DispenserXFSDetects ATM Malware DispenserXFShttps://twitter.com/r3c0nst/status/11007758573066526732019-02-27 00:00:0080@Xylit0l @r3c0nst / Modified by Florian RothFILE,MAL1d77456406c1a337869c969ddbaa70e8
196ATM_Malware_JavaDispCashDetects ATM Malware JavaDispCashhttps://twitter.com/r3c0nst/status/11112541696236748822019-03-28 00:00:0075Frank Boldewin (@r3c0nst)FILE,MAL90d7f79970aa353033e509c1187b9290
197Acrotray_AnomalyDetects an acrotray.exe that does not contain the usual strings-1970-01-01 01:00:0075Florian RothEXE,EXTVAR,FILEbffe62c85ccfa49006d6bbe06d9baf84
198Agent_BTZ_Aug17Detects Agent.BTZhttp://www.intezer.com/new-variants-of-agent-btz-comrat-found/2017-08-07 00:00:0075Florian RothEXE,FILE9db09505061381f676cbb90f6bdfcdb7
199Agent_BTZ_Proxy_DLL_1Detects Agent-BTZ Proxy DLL - activeds.dllhttp://www.intezer.com/new-variants-of-agent-btz-comrat-found/2017-08-07 00:00:0075Florian RothEXE,FILE,HKTLad36e572a62c1642d912690452103068
200Agent_BTZ_Proxy_DLL_2Detects Agent-BTZ Proxy DLL - activeds.dllhttp://www.intezer.com/new-variants-of-agent-btz-comrat-found/2017-08-07 00:00:0075Florian RothEXE,FILE,HKTLf23df0c672663c34a2c745a84efe8ae6
201Ajan_aspSemi-Auto-generated - file Ajan.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL454801e1476bd8a169f89833af7730f8
202Ajax_PHP_Command_Shell_phpSemi-Auto-generated - file Ajax_PHP Command Shell.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLfbfeda165a7c223e59fd3cedd9cc74c1
203AllTheThingsDetects AllTheThingshttps://github.com/subTee/AllTheThings2017-07-27 00:00:0075Florian RothEXE,FILE,HKTL641ea753af7653c454a326ee62e9596b
204Ammyy_Admin_AA_v3Remote Admin Tool used by APT group Anunak (ru) - file AA_v3.4.exe and AA_v3.5.exehttp://goo.gl/gkAg2E2014-12-22 00:00:0055Florian RothAPT,HKTLd420ca5201d66d9d520a658a4dbe421f
205Amplia_Security_ToolAmplia Security Tool-1970-01-01 01:00:0060Florian Roth (auto-filled)HKTL9b1a75a703b0f2ce629b8cae55b6594a
206Andromeda_MalBot_Jun_1ADetects a malicious Worm Andromeda / RETADUPhttp://blog.trendmicro.com/trendlabs-security-intelligence/information-stealer-found-hitting-israeli-hospitals/2017-06-30 00:00:0075Florian RothEXE,FILE,MALa026ee9dacea76c4e319616f81223bce
207Angry_IP_Scanner_v2_08_ipscanAuto-generated rule on file ipscan.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL5047ae4a89e4f291100a9407d1a3a322
208Antichat_Shell_v1_3_phpSemi-Auto-generated - file Antichat Shell v1.3.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLc45847d7c44ffa336e1cc042dd7bb829
209Antichat_Socks5_Server_php_phpSemi-Auto-generated - file Antichat Socks5 Server.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLb31085b3df7027f11b9044933dfa0900
210Antiy_Ports_1_21Disclosed hacktool set (old stuff) - file Antiy Ports 1.21.exe-2014-11-23 00:00:0060Florian RothHKTL7c320a796fe2ad5238b6901938d0c44d
211Apolmy_Privesc_TrojanApolmy Privilege Escalation Trojan used in APT Terracottahttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/2015-08-04 00:00:0080Florian RothAPT,EXE,FILE,MAL6b74ccbc60c1398e63ef6a08a5e74924
212AppInitHookAppInitGlobalHooks-Mimikatz - Hide Mimikatz From Process Lists - file AppInitHook.dllhttps://goo.gl/Z292v62015-07-15 00:00:0070Florian RothEXE,FILE,HKTLd1019ac2912b8dc185a884d738c56031
213Armitage_MeterpreterSession_StringsDetects Armitage componentInternal Research2017-12-24 00:00:0075Florian Roth30ddf234bd6521e9641f3164ae0e3a57
214Armitage_OSXDetects Armitage componentInternal Research2017-12-24 00:00:0075Florian RothMACOSd179b9817be60dfa8d671b125ce552f8
215Armitage_msfconsoleDetects Armitage componentInternal Research2017-12-24 00:00:0075Florian RothFILE70c4348204b5d70da56e3005fb97a85d
216Arp_EMP_v1_0Chinese Hacktool Set - file Arp EMP v1.0.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL7b7c9bff655595ce612c9ba2993eda01
217ArtTrayHookDllDisclosed hacktool set (old stuff) - file ArtTrayHookDll.dll-2014-11-23 00:00:0060Florian RothHKTLc8c4e0071a7f51d430e4f17fdc684064
218ArtTray_zip_Folder_ArtTrayDisclosed hacktool set (old stuff) - file ArtTray.exe-2014-11-23 00:00:0060Florian RothHKTL68be83e66535003ab310d4b07b9ef3bb
219Asmodeus_v0_1_plSemi-Auto-generated - file Asmodeus v0.1.pl.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLe2a204a3975937fc43b7f0a264677bf0
220Ayyildiz_Tim___AYT__Shell_v_2_1_Biz_htmlSemi-Auto-generated - file Ayyildiz Tim -AYT- Shell v 2.1 Biz.html.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLd3b0d31d04723d2407bc273d51288458
221BIN_ClientWebshells Auto-generated - file Client.exe-1970-01-01 01:00:0075Florian RothWEBSHELL3581a479b97449413919a77999f89e69
222BIN_ServerWebshells Auto-generated - file Server.exe-1970-01-01 01:00:0075Florian RothWEBSHELLff54c9b589e2004f77543d679f32364a
223BKDR_Snarasite_Oct17Auto-generated rule - file 36ba92cba23971ca9d16a0b4f45c853fd5b3108076464d5f2027b0f56054fd62Internal Research2017-10-07 00:00:0075Florian RothEXE,FILE,MALb66f9a61f42f8e2ed7eb9ea2f2f7d1c0
224BTC_Miner_lsass1_chrome_2Detects a Bitcoin MinerInternal Research - CN Actor2017-06-22 00:00:0060Florian RothEXE,FILEf7838095e37a2ad5a410e418e87e214c
225BackDooR__fr_Webshells Auto-generated - file BackDooR (fr).php-1970-01-01 01:00:0075Florian RothWEBSHELLd58fa9e597031b1609f3bd02d8f59009
226Backdoor_Naikon_APT_Sample1Detects backdoors related to the Naikon APThttps://goo.gl/7vHyvh2015-05-14 00:00:0075Florian RothAPT,EXE,FILE,MAL22e277065a8ea627431a93c28ea6bdc4
227Backdoor_Nitol_Jun17Detects malware backdoor Nitol - file wyawou.exe - Attention: this rule also matches on Upatre Downloaderhttps://goo.gl/OOB3mH2017-06-04 00:00:0075Florian RothEXE,FILE,MAL5d207e77c56ebc6b53574b09bd29c83b
228Backdoor_Redosdru_Jun17Detects malware Redosdru - file systemHome.exehttps://goo.gl/OOB3mH2017-06-04 00:00:0075Florian RothEXE,FILE,MAL4acdec50c06c0e961b3f1b76531dbd7b
229BadRabbit_GenDetects BadRabbit Ransomwarehttps://pastebin.com/Y7pJv3tK2017-10-25 00:00:0075Florian RothCRIME,EXE,FILE,GEN,MAL,RANSOMe4f9f3800e9d0ed564396a1dee1742c1
230BadRabbit_Mimikatz_CompAuto-generated rule - file 2f8c54f9fa8e47596a3beff0031f85360e56840c77f71c6a573ace6f46412035https://pastebin.com/Y7pJv3tK2017-10-25 00:00:0075Florian RothEXE,FILE5021ac0ae32441f76b7784a2f2754269
231Base64_PS1_ShellcodeDetects Base64 encoded PS1 Shellcodehttps://twitter.com/ItsReallyNick/status/10626016845668433922018-11-14 00:00:0065Nick Carr, David Ledbetter0fa56395f5fa2df0e145645835549b93
232Base64_encoded_ExecutableDetects an base64 encoded executable (often embedded)-2015-05-28 00:00:0040Florian RothEXE,EXTVAR,FILE7f4f57c927eafb70f2cbd872d218161b
233Batch_Powershell_Invoke_InveighDetects malicious batch file from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSC6d1232425d9698d507def223dd5deaea
234Batch_Script_To_Run_PsExecDetects malicious batch file from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSC3c21092795a11e46e0020a1748a0da79
235Beacon_K5omDetects Meterpreter Beacon - file K5om.dllhttps://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html2017-06-07 00:00:0075Florian RothEXE,FILE,HKTL,METASPLOIT362807b09d5d4d1589b723f1d0279264
236Beastdoor_BackdoorDetects the backdoor Beastdoor-1970-01-01 01:00:0055Florian RothHKTL,MALb8047562af97b679d7737b840eea7423
237BeepService_HacktoolDetects BeepService Hacktool used by Chinese APT groupshttps://goo.gl/p32Ozf2016-05-12 00:00:0085Florian RothAPT,CHINA,EXE,FILE,HKTLeee10cf930f59c6d6c602cd8f5ead919
238BergSilva_MalwareDetects a malware from the same author as the Indetectables RAT-2015-10-01 00:00:0075Florian RothEXE,FILE,MAL8a14ff87bf0cee341fbd91e26ec1018d
239BernhardPOSBernhardPOS Credit Card dumping toolhttp://morphick.com/blog/2015/7/14/bernhardpos-new-pos-malware-discovered-by-morphick1970-01-01 01:00:0070Nick Hoffman / Jeremy Humble45b85f33ec36b1f79e77cebedce319b6
240BeyondExec_RemoteAccess_ToolDetects BeyondExec Remote Access Tool - file rexesvr.exehttps://goo.gl/BvYurS2017-03-17 00:00:0075Florian RothEXE,FILE,HKTLb145fc4bff367d228070fec8fa8bd768
241Binary_Drop_CertutilDrop binary as base64 encoded cert trickhttps://goo.gl/9DNn8q2015-07-15 00:00:0070Florian Rothd502940b293d654bdeee13591b073b9d
242BlackEnergy_BE_2Detects BlackEnergy 2 Malwarehttp://goo.gl/DThzLz2015-02-19 00:00:0075Florian RothEXE,FILE,MAL2f5f6b04b803cc0613663c94389f819a
243BlackEnergy_BackdoorPass_DropBear_SSHDetects the password of the backdoored DropBear SSH Server - BlackEnergyhttp://feedproxy.google.com/~r/eset/blog/~3/BXJbnGSvEFc/2016-01-03 00:00:0075Florian RothEXE,FILE,MAL,RUSSIA9006c661b82b57c4b78be4d572bd23cc
244BlackEnergy_Driver_AMDIDEBlack Energy Malwarehttp://www.welivesecurity.com/2016/01/03/blackenergy-sshbeardoor-details-2015-attacks-ukrainian-news-media-electric-industry/2016-01-04 00:00:0075Florian RothEXE,FILE,MAL66749239f5e86e51ba5642ffcc860ace
245BlackEnergy_Driver_USBMDMBlack Energy Driverhttp://www.welivesecurity.com/2016/01/03/blackenergy-sshbeardoor-details-2015-attacks-ukrainian-news-media-electric-industry/2016-01-04 00:00:0075Florian RothEXE,FILE8105b175ff7021c6bfd299865035b4b8
246BlackEnergy_KillDisk_1Detects KillDisk malware from BlackEnergyhttp://feedproxy.google.com/~r/eset/blog/~3/BXJbnGSvEFc/2016-01-03 00:00:0080Florian RothEXE,FILE0f82d70aa823c7979fff6fdae63ab257
247BlackEnergy_KillDisk_2Detects KillDisk malware from BlackEnergyhttp://feedproxy.google.com/~r/eset/blog/~3/BXJbnGSvEFc/2016-01-03 00:00:0080Florian RothEXE,FILE3540a51991bc17152f1e5df9d98bb070
248BlackEnergy_VBS_AgentDetects VBS Agent from BlackEnergy Report - file Dropbearrun.vbshttp://feedproxy.google.com/~r/eset/blog/~3/BXJbnGSvEFc/2016-01-03 00:00:0075Florian RothSCRIPT4e0812bd7c3d633c684786bac9a93078
249Bladabindi_Malware_B64Detects Bladabindi Malware using Base64 encoded stringsInternal Research2016-10-08 00:00:0075Florian RothEXE,FILE,MAL7bd16a86033da5e89b23b61cfc4457a3
250BluenoroffPoS_DLLBluenoroff POS malware - hkp.dllhttp://blog.trex.re.kr/3?category=7376852018-06-07 00:00:0075http://blog.trex.re.kr/2c7b87f2746930c23d2fca6babad2e4d
251BluesPortScanAuto-generated rule on file BluesPortScan.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL725827b7340608a867594bf5edb215c3
252BronzeButler_DGet_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILE3b5549ec6b153894c021a310df7d2058
253BronzeButler_Daserf_C_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILEcd3f100b48000b1e7276424860810dfa
254BronzeButler_Daserf_Delphi_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILEddadd4533f93cd48f77be59c93460e4a
255BronzeButler_RarStar_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILE8ed981eff7e57049b08b35413d0e283c
256BronzeButler_UACBypass_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILEaca0e50e1464769ea69977f38db697cf
257BronzeButler_xxmm_1Detects malware / hacktool sample from Bronze Butler incidenthttps://www.secureworks.com/research/bronze-butler-targets-japanese-businesses2017-10-14 00:00:0075Florian RothEXE,FILEb7cc810e10efbb03e74bb37cf07f105b
258Buckeye_OsinfoDetects OSinfo tool used by the Buckeye APT grouphttp://www.symantec.com/connect/blogs/buckeye-cyberespionage-group-shifts-gaze-us-hong-kong2016-09-05 00:00:0075Florian RothAPT,EXE,FILE2878db44d4806f50798dc3b3efbe5f31
259ByPassFireWall_zip_Folder_IeDisclosed hacktool set (old stuff) - file Ie.dll-2014-11-23 00:00:0060Florian RothHKTLb614d8ce1d5e567a7c7e639d10fbb903
260ByPassFireWall_zip_Folder_InjectDisclosed hacktool set (old stuff) - file Inject.exe-2014-11-23 00:00:0060Florian RothHKTL9ae2bdcc15a37f3849526beec96c1908
261BypassUac2Auto-generated rule - file BypassUac2.zip-1970-01-01 01:00:0075yarGen Yara Rule GeneratorHKTL76cec79554cf69393cf128bad0404d69
262BypassUacDll_6Auto-generated rule - file BypassUacDll.aps-1970-01-01 01:00:0075yarGen Yara Rule GeneratorHKTLb37846ddcd5757a2964f221e73e78eea
263BypassUac_3Auto-generated rule - file BypassUacDll.dll-1970-01-01 01:00:0075yarGen Yara Rule GeneratorHKTLacf4676382220e6b41607459e05f6ea9
264BypassUac_9Auto-generated rule - file BypassUac.zip-1970-01-01 01:00:0075yarGen Yara Rule GeneratorHKTLffe0807e2c151c9637b3eacdaaa4a4d0
265BypassUac_EXEAuto-generated rule - file BypassUacDll.aps-1970-01-01 01:00:0075yarGen Yara Rule GeneratorHKTLf12d02db4924c1e3eb66ec4638e25e2d
266Bytes_used_in_AES_key_generationDetects Backdoor.goodorhttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSCEXE,FILE,MAL5d10ba093b9589452f603283b84a5a34
267CACTUSTORCHDetects CactusTorch Hacktoolhttps://github.com/mdsecactivebreach/CACTUSTORCH2017-07-31 00:00:0075Florian RothHKTLbe4a3fbf04b523384d73af5a2bab07a7
268CGISscan_CGIScanAuto-generated rule on file CGIScan.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLa40c46c59696d4103a7748b0b93d9d05
269CHAOS_PayloadDetects a CHAOS back connect payloadhttps://github.com/tiagorlampert/CHAOS2017-07-15 00:00:0080Florian RothEXE,FILE0c72ad990063eb233e99e87093e91aff
270CMStar_Malware_Sep17Detects CMStar Malwarehttps://goo.gl/pTffPA2017-10-03 00:00:0075Florian RothEXE,FILE,MALdae69b504e654dae8f4fcef08685d695
271CN_APT_ZeroT_extracted_GoChinese APT by Proofpoint ZeroT RAT - file Go.exehttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-04 00:00:0075Florian RothAPT,CHINA,EXE,FILE,MAL43282f950d27bb23f7dbe98fb1dd98a4
272CN_APT_ZeroT_extracted_McutilChinese APT by Proofpoint ZeroT RAT - file Mcutil.dllhttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-04 00:00:0075Florian RothAPT,CHINA,EXE,FILE,MAL4367593873fb45197e435f13afc80b26
273CN_APT_ZeroT_extracted_ZlhChinese APT by Proofpoint ZeroT RAT - file Zlh.exehttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-04 00:00:0075Florian RothAPT,CHINA,EXE,FILE,MALbb9184371f1ae21f1ce712e9167f4598
274CN_APT_ZeroT_nfloggerChinese APT by Proofpoint ZeroT RAT - file nflogger.dllhttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-04 00:00:0075Florian RothAPT,CHINA,EXE,FILE,HKTL,MALc6da9a3b5b6b098b5264b526aa963a83
275CN_Actor_AmmyyAdminDetects Ammyy Admin DownloaderInternal Research - CN Actor2017-06-22 00:00:0060Florian RothEXE,FILE796cf7ca3dc1476711f6d6354387e64a
276CN_Actor_RA_Tool_Ammyy_mscorsvwDetects Ammyy remote access toolInternal Research - CN Actor2017-06-22 00:00:0075Florian RothEXE,FILEe24a151b42a02c90d321abaae2d01a04
277CN_GUI_ScannerDetects an unknown GUI scanner tool - CN background-2014-04-10 00:00:0065Florian RothHKTL185809c6a094deaa89fe2db8e5642c13
278CN_Hacktool_1433_ScannerDetects a chinese MSSQL scanner-2014-12-10 00:00:0040Florian RothEXE,FILE,HKTL7f59ccb8b168f9e0a3ef2cbf00092fe0
279CN_Hacktool_1433_Scanner_Comp2Detects a chinese MSSQL scanner - component 2-2014-12-10 00:00:0040Florian RothEXE,FILE,HKTL0e12d0e502789cf30f84daae14f2c811
280CN_Hacktool_BAT_PortsOpenDetects a chinese BAT hacktool for local port evaluation-2014-12-10 00:00:0060Florian RothHKTL8ef582b067a26e9cdf7519d0852087e2
281CN_Hacktool_MilkT_BATDetects a chinese Portscanner named MilkT - shipped BAT-2014-12-10 00:00:0070Florian RothHKTL08ed5dd7133b3dd666844d7a828eda3c
282CN_Hacktool_MilkT_ScannerDetects a chinese Portscanner named MilkT-2014-12-10 00:00:0060Florian RothHKTL6a2b71583c732208457e1a8459e433e4
283CN_Hacktool_SSPort_PortscannerDetects a chinese Portscanner named SSPort-2014-12-10 00:00:0070Florian RothHKTLeaec49fce24482fc8a60b22e4adcc3d1
284CN_Hacktool_S_EXE_PortscannerDetects a chinese Portscanner named s.exe-2014-12-10 00:00:0070Florian RothHKTLca871abc82d2d9db972ab9f1b0669fce
285CN_Hacktool_ScanPort_PortscannerDetects a chinese Portscanner named ScanPort-2014-12-10 00:00:0070Florian RothHKTL2ad0de002a7d863790547c239bea9359
286CN_Honker_ACCESS_bruteSample from CN Honker Pentest Toolset - file ACCESS_brute.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE0ba83ecd051bd8ac80cb4558062fd3be
287CN_Honker_ASP_wshellSample from CN Honker Pentest Toolset - file wshell.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE37333cf7858bfcad17ba308d63d0adc3
288CN_Honker_Acunetix_Web_Vulnerability_Scanner_8_x_Enterprise_Edition_KeyGenSample from CN Honker Pentest Toolset - file Acunetix_Web_Vulnerability_Scanner_8.x_Enterprise_Edition_KeyGen.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,GEN,HKTL33943f1f75ac0f452de5dacd926b9136
289CN_Honker_Alien_DScript from disclosed CN Honker Pentest Toolset - file D.ASPDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT7c5ecfd00ad39dcfa31acd54230ada7e
290CN_Honker_Alien_commandScript from disclosed CN Honker Pentest Toolset - file command.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTa578d7d9d9c982c9e1826b11e9116770
291CN_Honker_Alien_eeSample from CN Honker Pentest Toolset - file ee.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEbe9ff7a78d6c4021d645109d1ea277de
292CN_Honker_Alien_iispwdSample from CN Honker Pentest Toolset - file iispwd.vbsDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian Roth0092b5dbe604d712a1465a8ecf29296a
293CN_Honker_Arp_EMP_v1_0Sample from CN Honker Pentest Toolset - file Arp EMP v1.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEce29d74ae10b5e690dab5d8f0fb824ed
294CN_Honker_AspxClientSample from CN Honker Pentest Toolset - file AspxClient.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEcf69320f9c51dd1993eadeb70f933380
295CN_Honker_Baidu_Extractor_Ver1_0Sample from CN Honker Pentest Toolset - file Baidu_Extractor_Ver1.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEb227d56319f6d926ef63e9e1c96f5d8a
296CN_Honker_COOKIE_CooKieSample from CN Honker Pentest Toolset - file CooKie.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEabc063f2415e933d473b5f14c8842e3b
297CN_Honker_ChinaChopperSample from CN Honker Pentest Toolset - file ChinaChopper.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothCHINA,EXE,FILE5aab5d6df224c27bc323d3a4ad52e5aa
298CN_Honker_ChinaChopper_dbScript from disclosed CN Honker Pentest Toolset - file db.mdbDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT6917ae4530eb350a4906a19520e7847a
299CN_Honker_ChurrascoSample from CN Honker Pentest Toolset - file Churrasco.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf9eac44e10432afe187c3d824126571e
300CN_Honker_CleanIISLogSample from CN Honker Pentest Toolset - file CleanIISLog.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE63cfc341fc4697b6acf796a4f509f791
301CN_Honker_CnCerT_CCdoor_CMDSample from CN Honker Pentest Toolset - file CnCerT.CCdoor.CMD.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE709cdcf7d1a0abc7b96c93d520de10aa
302CN_Honker_CnCerT_CCdoor_CMD_2Sample from CN Honker Pentest Toolset - file CnCerT.CCdoor.CMD.dll2Disclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE534fe9c30f350b66295abcb0847d14a5
303CN_Honker_Codeeer_ExplorerSample from CN Honker Pentest Toolset - file Codeeer Explorer.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE0d3610de1495e4e0b6d8d4ffe3ff8ed5
304CN_Honker_CookiesViewSample from CN Honker Pentest Toolset - file CookiesView.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE33813419c8cd14cfda1914650e0c6748
305CN_Honker_CoolScan_scanSample from CN Honker Pentest Toolset - file scan.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE25b73bc9ccf106df29619f08b40a135b
306CN_Honker_Cracker_SHELLSample from CN Honker Pentest Toolset - file SHELL.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE725197e74af4919e16df721f4b58d988
307CN_Honker_DLL_passive_privilege_escalation_ws2helpSample from CN Honker Pentest Toolset - file ws2help.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE85683ed5bdabcc546f5eb02ef5e840f2
308CN_Honker_D_injection_V2_32Sample from CN Honker Pentest Toolset - file D_injection_V2.32.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE30d27a67dfea907898bc4d17fd038230
309CN_Honker_DictionaryGeneratorSample from CN Honker Pentest Toolset - file DictionaryGenerator.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,GEN9e54b083f3d7fc056f95a6cab4dcd533
310CN_Honker_F4ck_Team_F4ck_3Sample from CN Honker Pentest Toolset - file F4ck_3.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEadc11db30010802e079cce7816c7c296
311CN_Honker_F4ck_Team_f4ckScript from disclosed CN Honker Pentest Toolset - file f4ck.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT116fbc118986d06d05c04007a1d0c2a7
312CN_Honker_F4ck_Team_f4ck_2Sample from CN Honker Pentest Toolset - file f4ck_2.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE7341c701a805864a08ac846304a7a2e0
313CN_Honker_F4ck_Team_f4ck_3Sample from CN Honker Pentest Toolset - file f4ck.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEce98a559271a5f3af6cf48e7e9308b7b
314CN_Honker_FTP_scanningSample from CN Honker Pentest Toolset - file FTP_scanning.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEdc61afde68d2f40fc81775fa34354e31
315CN_Honker_FckeditorSample from CN Honker Pentest Toolset - file Fckeditor.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE35455a9bd02f374b512dec9c532734d6
316CN_Honker_Fpipe_FPipeSample from CN Honker Pentest Toolset - file FPipe.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0050Florian RothEXE,FILE5a2b53dad5c0be22c1d9e908d23a053f
317CN_Honker_GetHashesSample from CN Honker Pentest Toolset - file GetHashes.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE98ac9a4f9310b810f439fcb3d0beba41
318CN_Honker_GetHashes_2Sample from CN Honker Pentest Toolset - file GetHashes.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE4755daad11cb1caa9bda85a66aaf965e
319CN_Honker_GetPass_GetPassSample from CN Honker Pentest Toolset - file GetPass.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE298b250f6e3588957d93f92d461abae0
320CN_Honker_GetSyskeySample from CN Honker Pentest Toolset - file GetSyskey.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd41d6e0c95fa2041f348a294c1ee678d
321CN_Honker_GetWebShellSample from CN Honker Pentest Toolset - file GetWebShell.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEe72415d4469e9cd7b4fbf1e077524d9d
322CN_Honker_GroupPolicyRemoverSample from CN Honker Pentest Toolset - file GroupPolicyRemover.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE702d419238ff9841698cf170abe08f41
323CN_Honker_HASH_32Sample from CN Honker Pentest Toolset - file 32.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE77443d6628cb4327734abef4422f7742
324CN_Honker_HASH_PwDump7Sample from CN Honker Pentest Toolset - file PwDump7.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTL63f0eea5b7e7e91787125c37b9f31985
325CN_Honker_HASH_pwhashSample from CN Honker Pentest Toolset - file pwhash.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf57fad9853b222ff63d75cc6b7987495
326CN_Honker_HTran2_4Sample from CN Honker Pentest Toolset - file HTran2.4.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE485c7ba9360ac853fb6342e1fc26f7bd
327CN_Honker_Happy_HappySample from CN Honker Pentest Toolset - file Happy.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE3e1e4f32a2b1b23d734a3be3c344b608
328CN_Honker_Havij_HavijSample from CN Honker Pentest Toolset - file Havij.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5b7f98f2c4aacf70b623ac7f644b4115
329CN_Honker_HconSTFportableSample from CN Honker Pentest Toolset - file HconSTFportable.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE2d0a051ac4095cd33efbc232b1984585
330CN_Honker_HookmsginaSample from CN Honker Pentest Toolset - file Hookmsgina.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEda7c330671f33f9c211d8bfc559706b8
331CN_Honker_Htran_V2_40_htran20Sample from CN Honker Pentest Toolset - file htran20.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEa21c7eef73ccad5230afa55d8df1b0c9
332CN_Honker_IIS6_iis6Sample from CN Honker Pentest Toolset - file iis6.comDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE437b2c6158616f1f2b11b7eae0d7649a
333CN_Honker_IIS_logcleaner1_0_readmeScript from disclosed CN Honker Pentest Toolset - file readme.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTb2cc05e476d13ae0015581dfca3d978e
334CN_Honker_InjectionSample from CN Honker Pentest Toolset - file Injection.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTL18ed84592b8951c153d4572ee113f03f
335CN_Honker_Injection_Transit_jmCookScript from disclosed CN Honker Pentest Toolset - file jmCook.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT5873bdba9841ca92c9c737d8a4698c1b
336CN_Honker_Injection_transitSample from CN Honker Pentest Toolset - file Injection_transit.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTLa3a4d3446d3c748c5e6e82d6b993d295
337CN_Honker_Interception3389_setupSample from CN Honker Pentest Toolset - file setup.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE529115e3b9d6323686e16990c5b336d7
338CN_Honker_InterceptionSample from CN Honker Pentest Toolset - file Interception.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf59f2b0644100a79abcd672a10c52b85
339CN_Honker_Intersect2_BetaScript from disclosed CN Honker Pentest Toolset - file Intersect2-Beta.pyDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,SCRIPTe6cbd448e86b77de2092cda606e7b7fb
340CN_Honker_InvasionErasorSample from CN Honker Pentest Toolset - file InvasionErasor.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEa69cf82c9dce437aaa742a15b7d1a86e
341CN_Honker_LPK2_0_LPKSample from CN Honker Pentest Toolset - file LPK.DATDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE530b0426dc70cc5d524258fe336221f9
342CN_Honker_Layer_LayerSample from CN Honker Pentest Toolset - file Layer.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEac46b7991324278c02444bb41184c251
343CN_Honker_LogCleanerSample from CN Honker Pentest Toolset - file LogCleaner.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5447c248ca996e84b711084586b8b5e0
344CN_Honker_MAC_IPMACSample from CN Honker Pentest Toolset - file IPMAC.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE21154473a107a2b505ab3dbcb440809e
345CN_Honker_MSTSC_can_direct_copySample from CN Honker Pentest Toolset - file MSTSC_can_direct_copy.EXEDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEfb8f3095b24159c6bf1425801e0be147
346CN_Honker_ManualInjectionSample from CN Honker Pentest Toolset - file ManualInjection.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTLcb7c40645a36cf9b58cb220632717606
347CN_Honker_Master_beta_1_7Sample from CN Honker Pentest Toolset - file Master_beta_1.7.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEc19c927e5213ec1b44ee482b4497592f
348CN_Honker_MatriXay1073Sample from CN Honker Pentest Toolset - file MatriXay1073.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE48922735ec60a65a88f5fbe058d1c98e
349CN_Honker_Md5CrackToolsSample from CN Honker Pentest Toolset - file Md5CrackTools.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEda0c623f332e24c73af0ade9787662cd
350CN_Honker_NBSI_3_0Sample from CN Honker Pentest Toolset - file NBSI 3.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE45684e0e6077bd3956b5143c63fdbe2d
351CN_Honker_NetFuke_NetFukeSample from CN Honker Pentest Toolset - file NetFuke.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEbd5b0c14ce9dbce6628dcfaa8697274f
352CN_Honker_Oracle_v1_0_OracleSample from CN Honker Pentest Toolset - file Oracle.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEe3156d6334bfd7ab5ca2650ce93f7ad1
353CN_Honker_PHP_php11Sample from CN Honker Pentest Toolset - file php11.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian Roth4b8bc6d91639ca05aeacacd3fb1d48d9
354CN_Honker_Perl_serv_UScript from disclosed CN Honker Pentest Toolset - file Perl-serv-U.plDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT717ab117c0d613876c524d2a5095ebcd
355CN_Honker_Pk_PkerSample from CN Honker Pentest Toolset - file Pker.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE37998c302f50eb27ec8a4543a5fde53e
356CN_Honker_PostgreSQLSample from CN Honker Pentest Toolset - file PostgreSQL.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE7dcac70ccb9036600f4dfbbe64ae311b
357CN_Honker_Pwdump7_Pwdump7Script from disclosed CN Honker Pentest Toolset - file Pwdump7.batDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT6d6cfcc099fba5c1021a862f05e0dbbf
358CN_Honker_SAMInsideSample from CN Honker Pentest Toolset - file SAMInside.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEcdf45a0f8a7430fb6a83376a00824459
359CN_Honker_SQLServer_inject_CreakedSample from CN Honker Pentest Toolset - file SQLServer_inject_Creaked.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE97a31a7acfad1aa61155be30274ebe9f
360CN_Honker_Safe3WVSSample from CN Honker Pentest Toolset - file Safe3WVS.EXEDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE8d964640a5aa679e6260eca4b807a66e
361CN_Honker_ScanHistorySample from CN Honker Pentest Toolset - file ScanHistory.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd705b3bc1cff610d9a5617ba79395551
362CN_Honker_SegmentWeaponSample from CN Honker Pentest Toolset - file SegmentWeapon.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf14a56e4544b6ff3f1d47dd54c54ab36
363CN_Honker_ShiftBackdoor_ServerSample from CN Honker Pentest Toolset - file Server.datDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEfbab62529574271c1f0fd39f5234aa4f
364CN_Honker_SkinHRootkit_SkinHSample from CN Honker Pentest Toolset - file SkinH.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEeeddc2d7068b723067314c57bd3501b4
365CN_Honker_SqlMap_Python_RunSample from CN Honker Pentest Toolset - file Run.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,SCRIPT13f071e1e6d6f638a71bf996a45084c6
366CN_Honker_Sword1_5Sample from CN Honker Pentest Toolset - file Sword1.5.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEc74a1ed4feceb96cc06b293af211e62d
367CN_Honker_SwordCollEditionSample from CN Honker Pentest Toolset - file SwordCollEdition.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd18590d24fab2fd82061b94fad22c200
368CN_Honker_SwordHonkerEditionSample from CN Honker Pentest Toolset - file SwordHonkerEdition.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE0bc47a1415a2fa65062fb2786cf226d2
369CN_Honker_T00ls_Lpk_Sethc_v2Sample from CN Honker Pentest Toolset - file T00ls Lpk Sethc v2.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf2b9bcdc6295316a723efbe2525ac2c3
370CN_Honker_T00ls_Lpk_Sethc_v3_0Sample from CN Honker Pentest Toolset - file T00ls Lpk Sethc v3.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEffa996c9560dbfe61835b14d6cbf1ed6
371CN_Honker_T00ls_Lpk_Sethc_v3_LPKSample from CN Honker Pentest Toolset - file LPK.DATDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE81efebbb34ef4b68c8429a32a128b836
372CN_Honker_T00ls_Lpk_Sethc_v4_0Sample from CN Honker Pentest Toolset - file T00ls Lpk Sethc v4.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE9633dc7435a4a6f0202f290313815a2c
373CN_Honker_T00ls_Lpk_Sethc_v4_LPKSample from CN Honker Pentest Toolset - file LPK.DATDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE49be95e0441b40be0fb356744bc7f2be
374CN_Honker_T00ls_scannerSample from CN Honker Pentest Toolset - file T00ls_scanner.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE285059811f71b2432b52f9978d1e274a
375CN_Honker_Tuoku_script_MSSQL_Script from disclosed CN Honker Pentest Toolset - file MSSQL_.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT0aa5ec33cf0f847fa8486d04028448b9
376CN_Honker_Tuoku_script_oracle_2Sample from CN Honker Pentest Toolset - file oracle.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian Roth65b6e9adc57175ed265261248c316103
377CN_Honker_WebCruiserWVSSample from CN Honker Pentest Toolset - file WebCruiserWVS.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf70fbef149ea29ec3ba1d8d15c1c0806
378CN_Honker_WebRobotSample from CN Honker Pentest Toolset - file WebRobot.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5d65b7bd1f89d17c3f4299c59ac3879c
379CN_Honker_WebScan_WebScanSample from CN Honker Pentest Toolset - file WebScan.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE9dd00450569944d5e114999eeea76c12
380CN_Honker_WebScan_wwwscanSample from CN Honker Pentest Toolset - file wwwscan.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE3aefdc951cd3da15997b74de60c1e6bf
381CN_Honker_WebshellSample from CN Honker Pentest Toolset - file Webshell.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,WEBSHELL3a463250b2f6301c7ccd431248213ace
382CN_Honker_Webshell_ASPX_aspx2Webshell from CN Honker Pentest Toolset - file aspx2.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELLaaf413b173a1ef71108c35a3afc55707
383CN_Honker_Webshell_ASPX_aspx3Webshell from CN Honker Pentest Toolset - file aspx3.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLf5932323d5a2f114282b3ea74814217f
384CN_Honker_Webshell_ASPX_aspx4Webshell from CN Honker Pentest Toolset - file aspx4.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL640e3bb33af58f44f379ac6bb5335a2b
385CN_Honker_Webshell_ASPX_aspxWebshell from CN Honker Pentest Toolset - file aspx.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL91a5fde1c904dee16213bafca75a4139
386CN_Honker_Webshell_ASPX_shell_shellWebshell from CN Honker Pentest Toolset - file shell.aspxDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL94d4b00d75529500587278f7f2d10363
387CN_Honker_Webshell_ASPX_sniffWebshell from CN Honker Pentest Toolset - file sniff.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL04db1cf71c388468cb010057cbddf1e1
388CN_Honker_Webshell_ASP_asp1Webshell from CN Honker Pentest Toolset - file asp1.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL38b0f54720a2459d021fa259c36820c3
389CN_Honker_Webshell_ASP_asp2Webshell from CN Honker Pentest Toolset - file asp2.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLf1720f106131e2a0842d3cec21b79e2b
390CN_Honker_Webshell_ASP_asp3Webshell from CN Honker Pentest Toolset - file asp3.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL08fb4030c1c50809ce721bae37622c3a
391CN_Honker_Webshell_ASP_asp404Webshell from CN Honker Pentest Toolset - file asp404.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL8a292acef66c78b80b106967c9c4fe1c
392CN_Honker_Webshell_ASP_asp4Webshell from CN Honker Pentest Toolset - file asp4.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL418616d5a4715987c68072356c270e43
393CN_Honker_Webshell_ASP_hy2006aWebshell from CN Honker Pentest Toolset - file hy2006a.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLc150317c32e43f7996e39ba58961fdc5
394CN_Honker_Webshell_ASP_rootkitWebshell from CN Honker Pentest Toolset - file rootkit.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL03d5f36cbbff2392cbc2c08a929403ab
395CN_Honker_Webshell_ASP_shellWebshell from CN Honker Pentest Toolset - file shell.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL22d088360fcee75cd26f136ddf694dd3
396CN_Honker_Webshell_ASP_web_aspWebshell from CN Honker Pentest Toolset - file web.asp.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL898b2f97937ef7b0113064d23bd70299
397CN_Honker_Webshell_FTP_MYSQL_MSSQL_SSHWebshell from CN Honker Pentest Toolset - file FTP MYSQL MSSQL SSH.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL45a467944b060919e29626dfdbe15634
398CN_Honker_Webshell_Injection_Transit_jmPostWebshell from CN Honker Pentest Toolset - file jmPost.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL2d01631f3d672c338fef8209002676dd
399CN_Honker_Webshell_Interception3389_getWebshell from CN Honker Pentest Toolset - file get.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLcf73446922e0cb36bbc296bb3506bc00
400CN_Honker_Webshell_JSPMSSQLWebshell from CN Honker Pentest Toolset - file JSPMSSQL.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL2258ce83c8b65b102c8dc96ed0d17c14
401CN_Honker_Webshell_JSP_jspWebshell from CN Honker Pentest Toolset - file jsp.htmlDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLf82abad2e367b5fda729170e30e6774e
402CN_Honker_Webshell_Linux_2_6_ExploitWebshell from CN Honker Pentest Toolset - file 2.6.9Disclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothLINUX,WEBSHELL8379bc937b1c32e11dc8da041a5bda9d
403CN_Honker_Webshell_PHP_BlackSkyWebshell from CN Honker Pentest Toolset - file php6.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL69aad7f19dd615165972e98dba9cabd3
404CN_Honker_Webshell_PHP_linuxWebshell from CN Honker Pentest Toolset - file linux.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELLf861b2c73ca4a08ded7705140b5c8128
405CN_Honker_Webshell_PHP_php10Webshell from CN Honker Pentest Toolset - file php10.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL08790a6dd5536d8193f408274f91aae2
406CN_Honker_Webshell_PHP_php1Webshell from CN Honker Pentest Toolset - file php1.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLe6837a2376c2e42971ce188c33adfaf2
407CN_Honker_Webshell_PHP_php2Webshell from CN Honker Pentest Toolset - file php2.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLc6c863c37de115d62be86a1680b7a25e
408CN_Honker_Webshell_PHP_php3Webshell from CN Honker Pentest Toolset - file php3.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL229ab7524e2e13f82b54edb28ed3a053
409CN_Honker_Webshell_PHP_php4Webshell from CN Honker Pentest Toolset - file php4.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELLb827db8fee745099ecebef6a02a01805
410CN_Honker_Webshell_PHP_php5Webshell from CN Honker Pentest Toolset - file php5.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELLdf6383045b488026ef60e5ba88e2d64c
411CN_Honker_Webshell_PHP_php7Webshell from CN Honker Pentest Toolset - file php7.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL9071ed4b38b2255ad4c85d471eee752e
412CN_Honker_Webshell_PHP_php8Webshell from CN Honker Pentest Toolset - file php8.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL959caab162bee77587db7eef6177d8ea
413CN_Honker_Webshell_PHP_php9Webshell from CN Honker Pentest Toolset - file php9.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL075b5e6cae3cccbacaa810068cb3a280
414CN_Honker_Webshell_Serv_U_2_admin_by_lake2Webshell from CN Honker Pentest Toolset - file Serv-U 2 admin by lake2.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLa926cd12ac308ecbe12773b04d759aad
415CN_Honker_Webshell_Serv_U_aspWebshell from CN Honker Pentest Toolset - file Serv-U asp.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLf44bff7ab4dfcb6dcf1146159e37b11c
416CN_Honker_Webshell_Serv_U_by_GoldsunWebshell from CN Honker Pentest Toolset - file Serv-U_by_Goldsun.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL4e52db4c36c7497495373be28f1ef815
417CN_Honker_Webshell_Serv_U_serv_uWebshell from CN Honker Pentest Toolset - file serv-u.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL40eb8b08a07ab052832df9ce42a9392a
418CN_Honker_Webshell_Serv_U_servuWebshell from CN Honker Pentest Toolset - file servu.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLbf405239eb1bb547242c0232c9ddb08c
419CN_Honker_Webshell_T00ls_Lpk_Sethc_v4_mailWebshell from CN Honker Pentest Toolset - file mail.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL3a823be7813d09f5fc4b62b88ff8bcb3
420CN_Honker_Webshell_Tuoku_script_mssql_2Webshell from CN Honker Pentest Toolset - file mssql.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL86937beb9172026e1c5ba1ae4953f420
421CN_Honker_Webshell_Tuoku_script_mysqlWebshell from CN Honker Pentest Toolset - file mysql.aspxDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL1ef12ac14ad1ceece57644df7872751b
422CN_Honker_Webshell_Tuoku_script_oracleWebshell from CN Honker Pentest Toolset - file oracle.jspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL69c97ebb72f7c9a6f26e2cc32a9846c3
423CN_Honker_Webshell_Tuoku_script_xxWebshell from CN Honker Pentest Toolset - file xx.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL4051f21e2485c1a641974d19cbe2681b
424CN_Honker_Webshell_WebShellWebshell from CN Honker Pentest Toolset - file WebShell.cgiDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLec3eebd747fec5497c6eb49b8edfe7ba
425CN_Honker_Webshell__Injection_jmCook_jmPost_ManualInjectionWebshell from CN Honker Pentest Toolset - from files Injection.exe, jmCook.asp, jmPost.asp, ManualInjection.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothHKTL,WEBSHELL288816741449920a7f3b25af00c3bae1
426CN_Honker_Webshell__Serv_U_by_Goldsun_asp3_Serv_U_aspWebshell from CN Honker Pentest Toolset - from files Serv-U_by_Goldsun.asp, asp3.txt, Serv-U asp.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL029026d1374edc7806c0cca7a4758b59
427CN_Honker_Webshell__asp4_asp4_MSSQL__MSSQL_Webshell from CN Honker Pentest Toolset - from files asp4.txt, asp4.txt, MSSQL_.asp, MSSQL_.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL3c83cc5c75d439f2ffa3fd7594a9e653
428CN_Honker_Webshell__php1_php7_php9Webshell from CN Honker Pentest Toolset - from files php1.txt, php7.txt, php9.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL81329e8036a09526e86b08954d85c7ac
429CN_Honker_Webshell_assemblyWebshell from CN Honker Pentest Toolset - file assembly.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL2893c5e2507731134aff00f3dd4bc713
430CN_Honker_Webshell_cfmShellWebshell from CN Honker Pentest Toolset - file cfmShell.cfmDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL38b2a94e1aa4c262146136fd3d5f2d2f
431CN_Honker_Webshell_cfm_listWebshell from CN Honker Pentest Toolset - file list.cfmDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLb4514250f1e4f98b5b4d761d5e5c4431
432CN_Honker_Webshell_cfm_xlWebshell from CN Honker Pentest Toolset - file xl.cfmDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELLa28723579c031ad6c6af224ab9fe2f53
433CN_Honker_Webshell_cmfshellWebshell from CN Honker Pentest Toolset - file cmfshell.cmfDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLdf2fd2279e055420ee226f0afba3ab2c
434CN_Honker_Webshell_dz_phpcms_phpbbWebshell from CN Honker Pentest Toolset - file dz_phpcms_phpbb.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL37393d52ccedd6e3e3c0998023148197
435CN_Honker_Webshell_jspshell2Webshell from CN Honker Pentest Toolset - file jspshell2.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL662840942d199064bcdd7a0cfe88c126
436CN_Honker_Webshell_jspshellWebshell from CN Honker Pentest Toolset - file jspshell.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL6665eb5948075be73ca4ebbef2aa162b
437CN_Honker_Webshell_mycode12Webshell from CN Honker Pentest Toolset - file mycode12.cfmDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLac5bd6a53982801ac062db53eef6dd5d
438CN_Honker_Webshell_nc_1Webshell from CN Honker Pentest Toolset - file 1.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLb4f52fb3a5b15a693d6a94ebbdefd1f1
439CN_Honker_Webshell_offlibraryWebshell from CN Honker Pentest Toolset - file offlibrary.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL2f99903844128d4f5d4bcbac0b5cd096
440CN_Honker_Webshell_phpwebbackupWebshell from CN Honker Pentest Toolset - file phpwebbackup.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELL14c997486b4724106ae0d812a9ccf6bf
441CN_Honker_Webshell_picloaked_1Webshell from CN Honker Pentest Toolset - file 1.gifDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLcbe4826769a0f4f7e4f34189d9bf1d65
442CN_Honker_Webshell_portRecall_jsp2Webshell from CN Honker Pentest Toolset - file jsp2.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLa40caaa5e0215867a762e2839a810e07
443CN_Honker_Webshell_portRecall_jspWebshell from CN Honker Pentest Toolset - file jsp.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLae68cb8e0176a18f2e7dcd9c1af51dc6
444CN_Honker_Webshell_su7_x_9_xWebshell from CN Honker Pentest Toolset - file su7.x-9.x.aspDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLe4ce90a5c8ade05dbe99f70e72ffb1ac
445CN_Honker_Webshell_test3693Webshell from CN Honker Pentest Toolset - file test3693.warDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,WEBSHELL781125768081bd83b5a75af14f6801d7
446CN_Honker_Webshell_udf_udfWebshell from CN Honker Pentest Toolset - file udf.phpDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELLc72e6fefc40369bcb4fe3e4fb6edecc2
447CN_Honker_Webshell_wshell_aspWebshell from CN Honker Pentest Toolset - file wshell-asp.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothWEBSHELL9be67af6b50e623b06068697bbf64b6f
448CN_Honker_Without_a_trace_WywzSample from CN Honker Pentest Toolset - file Wywz.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE9c39120de4a95dabb8d666fce325e830
449CN_Honker_WordpressScannerSample from CN Honker Pentest Toolset - file WordpressScanner.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTL,OFFICEf8f42be172af03cf8b80ecd8e76d2a42
450CN_Honker_Xiaokui_conversion_toolSample from CN Honker Pentest Toolset - file Xiaokui_conversion_tool.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE460b9625969b3082b56fa1714fe52e6b
451CN_Honker__D_injection_V2_32_D_injection_V2_32_D_injection_V2_32Sample from CN Honker Pentest Toolset - from files D_injection_V2.32.exe, D_injection_V2.32.exe, D_injection_V2.32.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE7bcc6f54a188188b2adeef4a95396ce6
452CN_Honker__LPK_LPK_LPKSample from CN Honker Pentest Toolset - from files LPK.DAT, LPK.DAT, LPK.DATDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE9574d12023fc461414b245f68fa4ca62
453CN_Honker__PostgreSQL_mysql_injectV1_1_Creak_Oracle_SQLServer_inject_CreakedSample from CN Honker Pentest ToolsetDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEe16d7e0d0d89ed385c4fe126d5315cc1
454CN_Honker__builder_shift_SkinHSample from CN Honker Pentest Toolset - from files builder.exe, shift.exe, SkinH.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5011eee543a6c934cd6681fc80ed1e1d
455CN_Honker__lcx_HTran2_4_htran20Sample from CN Honker Pentest Toolset - from files lcx.exe, HTran2.4.exe, htran20.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE77dbcb4648695c0d7db307a8f77fddcc
456CN_Honker__wwwscan_wwwscan_wwwscan_guiSample from CN Honker Pentest Toolset - from files wwwscan.exe, wwwscan.exe, wwwscan_gui.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf2f4765ceb4885ed54cce9831d44b8ef
457CN_Honker_arp3_7_arp3_7Sample from CN Honker Pentest Toolset - file arp3.7.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE8d18a2a51cf8b588d973fa350b60ad84
458CN_Honker_cleaner_cl_2Sample from CN Honker Pentest Toolset - file cl.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEcc0582d0fa73d9ff905a3d8765faf7e7
459CN_Honker_cleaniisSample from CN Honker Pentest Toolset - file cleaniis.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE7dcfca1e09be9a1352b7324a85139193
460CN_Honker_clearlogsSample from CN Honker Pentest Toolset - file clearlogs.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE814cadd46cb70d03da4a4c2a882c52a0
461CN_Honker_dedecms5_7Sample from CN Honker Pentest Toolset - file dedecms5.7.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE29958cfee298b2e20271ed4cddbb1240
462CN_Honker_dirdown_dirdownSample from CN Honker Pentest Toolset - file dirdown.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE908cf15b45a5a37e5cf6e10144c1f440
463CN_Honker_exp_iis7Sample from CN Honker Pentest Toolset - file iis7.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEe8d661ec9f1384e25abc1d97e759b076
464CN_Honker_exp_ms11011Sample from CN Honker Pentest Toolset - file ms11011.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf1e3a65c1ead550703dbd12ebd889593
465CN_Honker_exp_ms11046Sample from CN Honker Pentest Toolset - file ms11046.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEefbf8ef2183257bdfbd6671cd2f1a2e2
466CN_Honker_exp_ms11080Sample from CN Honker Pentest Toolset - file ms11080.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE4b16ac9bbb013f6ca72a1b82e2850b4c
467CN_Honker_exp_win2003Sample from CN Honker Pentest Toolset - file win2003.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE57877205700e1f0aec0f7f4fbe7a973f
468CN_Honker_getlsasrvaddrSample from CN Honker Pentest Toolset - file getlsasrvaddr.exe - WCE Amplia SecurityDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE04e8ad7e8a82bd2ea47b677efbae7188
469CN_Honker_hashq_HashqSample from CN Honker Pentest Toolset - file Hashq.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEb83a9109328f3cf293efa2c0924a7a5f
470CN_Honker_hkmjjiis6Sample from CN Honker Pentest Toolset - file hkmjjiis6.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE7585795c55063bafdf19bb44177d1e74
471CN_Honker_hxdef100Sample from CN Honker Pentest Toolset - file hxdef100.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE6574c840494aeb244be4a06ed5341386
472CN_Honker_lcx_lcxSample from CN Honker Pentest Toolset - HTRAN - file lcx.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEfb31d2996245cd3958b7ab631dd01fca
473CN_Honker_linux_binScript from disclosed CN Honker Pentest Toolset - file linux_binDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT92fc599b5df44958c8aad0e00c29ce89
474CN_Honker_mafix_rootScript from disclosed CN Honker Pentest Toolset - file rootDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTd2a64ee4d8881f70988ee2c22bb51bb5
475CN_Honker_mempodipper2_6Sample from CN Honker Pentest Toolset - file mempodipper2.6.39Disclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian Roth8f8e9b9100ead0a07ad0767b341a1fec
476CN_Honker_ms10048_x64Sample from CN Honker Pentest Toolset - file ms10048-x64.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf6760e07ba0dc657b6c9acdb1ac912e8
477CN_Honker_ms10048_x86Sample from CN Honker Pentest Toolset - file ms10048-x86.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEfdadccb72ff3c5195f480d6fec02f837
478CN_Honker_ms11080_withcmdSample from CN Honker Pentest Toolset - file ms11080_withcmd.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEbef6cc93c9187bbc5a92a138cf263a7d
479CN_Honker_mssqlpw_scanScript from disclosed CN Honker Pentest Toolset - file mssqlpw scan.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT6373161c00c79b67bf029bef1d7450fe
480CN_Honker_mysql_injectV1_1_CreakSample from CN Honker Pentest Toolset - file mysql_injectV1.1_Creak.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE8a2e7acbcb75725dee4fb4cd5f8eec6c
481CN_Honker_nc_MOVEScript from disclosed CN Honker Pentest Toolset - file MOVE.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTef67fd7b388cf8b92ff956ed506c4192
482CN_Honker_net_packet_captSample from CN Honker Pentest Toolset - file net_packet_capt.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEa98c295ee39f1d4c3fd6f58063c7db61
483CN_Honker_net_priv_esc2Sample from CN Honker Pentest Toolset - file net-priv-esc2.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE915fa4c9f8beff55765cea116d7fc342
484CN_Honker_no_net_priv_esc_AddUserSample from CN Honker Pentest Toolset - file AddUser.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE474639638926f8a42b921da56c74421b
485CN_Honker_passwd_dict_3389Script from disclosed CN Honker Pentest Toolset - file 3389.txtDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTcd476a35630f7d29f4fa0a5b7378ba40
486CN_Honker_portRecall_bcScript from disclosed CN Honker Pentest Toolset - file bc.plDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT87669dde2d5deeec17bb86b1190bbce6
487CN_Honker_portRecall_prScript from disclosed CN Honker Pentest Toolset - file prDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTf275a63ce0042fa2a25a643f57985217
488CN_Honker_pr_debugSample from CN Honker Pentest Toolset - file debug.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE3644fcded9c45045362400d3b87dfa75
489CN_Honker_safe3wvs_cgiscanSample from CN Honker Pentest Toolset - file cgiscan.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5f8b90d2fa5e89e046d93068f1e7629e
490CN_Honker_shell_brute_toolSample from CN Honker Pentest Toolset - file shell_brute_tool.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd9100ccc8489432b491f187588cf7b96
491CN_Honker_sig_3389_2_3389Sample from CN Honker Pentest Toolset - file 3389.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEa2d508cab567356683739635427f1504
492CN_Honker_sig_3389_3389Script from disclosed CN Honker Pentest Toolset - file 3389.vbsDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPTa3e2f198db19c42b44f22a9647f354d2
493CN_Honker_sig_3389_3389_2Script from disclosed CN Honker Pentest Toolset - file 3389.batDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT6644e1a3673082c51786e89cd0ad75f2
494CN_Honker_sig_3389_3389_3Script from disclosed CN Honker Pentest Toolset - file 3389.batDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothSCRIPT3442dd1d18df5f878605345ac7ae6f03
495CN_Honker_sig_3389_80_AntiFWSample from CN Honker Pentest Toolset - file AntiFW.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE5ad4bf63586cec24fe3fcf6e6b15efc4
496CN_Honker_sig_3389_DUBrute_v3_0_RC3_2_0Sample from CN Honker Pentest Toolset - file 2.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf201dd5920e62ff692b5045dee9bda1b
497CN_Honker_sig_3389_DUBrute_v3_0_RC3_3_0Sample from CN Honker Pentest Toolset - file 3.0.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE173dc7094664c72cad3a32afdea62c0c
498CN_Honker_sig_3389_mstsc_MSTSCAXSample from CN Honker Pentest Toolset - file MSTSCAX.DLLDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEcfd023364590a80fdf5c9a6484356a7f
499CN_Honker_sig_3389_xp3389Sample from CN Honker Pentest Toolset - file xp3389.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf5827f3836f600caad3858c61cc09b62
500CN_Honker_smsniff_smsniffSample from CN Honker Pentest Toolset - file smsniff.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEb10d74ff4efd20167e6450b88d979972
501CN_Honker_struts2_catboxSample from CN Honker Pentest Toolset - file catbox.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEf33544fe893891cffaaa49400806dfa5
502CN_Honker_super_Injection1Sample from CN Honker Pentest Toolset - file super Injection1.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE,HKTL5962cfaad69bb42c5073db5b22e40f98
503CN_Honker_syconfigScript from disclosed CN Honker Pentest Toolset - file syconfig.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothFILE,SCRIPT4ffcd67bbc0a56ff358c2ff7be7f3157
504CN_Honker_termsrvhackSample from CN Honker Pentest Toolset - file termsrvhack.dllDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd886c2ee4fc694cd4b61bd9c2322e10a
505CN_Honker_windows_expSample from CN Honker Pentest Toolset - file exp.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILE8ac1bacebfe7f053811f70110c8dd9e6
506CN_Honker_windows_mstsc_enhanced_RMDSTCSample from CN Honker Pentest Toolset - file RMDSTC.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEad1194c36618063093da7a662c855d4e
507CN_Honker_wwwscan_1_wwwscanSample from CN Honker Pentest Toolset - file wwwscan.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEd81a41bb742536080fc7c167784fc520
508CN_Honker_wwwscan_guiSample from CN Honker Pentest Toolset - file wwwscan_gui.exeDisclosed CN Honker Pentest Toolset2015-06-23 00:00:0070Florian RothEXE,FILEbaed62509ab3e7b641e83d5a62f0aaaa
509CN_Packed_ScannerSuspiciously packed executable-2014-06-10 00:00:0040Florian RothHKTL6a6489a5466ee1517b1203e098e2547b
510CN_PortscanCN Port Scanner-2013-11-29 00:00:0070Florian RothFILE,HKTL85336c14ce9f8f9cb7f167fd3de24346
511CN_Tools_MyUPnPChinese Hacktool Set - file MyUPnP.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL4d369fd10ed5c1d9ee59a72b93c9a732
512CN_Tools_PcShareChinese Hacktool Set - file PcShare.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLed3e2aa5e63c07dd3c0b0f24b672e89d
513CN_Tools_ShiellChinese Hacktool Set - file Shiell.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLc40e9fcdb94240211451f0c92b0e4637
514CN_Tools_TempChinese Hacktool Set - file Temp.warhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,FILE,HKTL,SCRIPT2d4e6926c4de49d9996463134c21f800
515CN_Tools_VNCLinkChinese Hacktool Set - file VNCLink.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1ac82ac690135e9e67a115d80d83ff13
516CN_Tools_VscanChinese Hacktool Set - file Vscan.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1b51b7d1044fbc72c6b18a4b1e6d7c19
517CN_Tools_hscanChinese Hacktool Set - file hscan.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL4aec92428d99072ed269f1110d2ce84b
518CN_Tools_itemChinese Hacktool Set - file item.phphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL93704793e0011d3894f59c312864cf40
519CN_Tools_oldChinese Hacktool Set - file old.phphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL5ed4bdc5d6d5b3de84ecce1287423c37
520CN_Tools_pcChinese Hacktool Set - file pc.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL6983d62951572beadc80e6510f3926f1
521CN_Tools_srssChinese Hacktool Set - file srss.bathttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,SCRIPT9fbb518dcd86fc0e06393116565b264a
522CN_Tools_srss_2Chinese Hacktool Set - file srss.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL3d7aee664114204904d55b4e22c4ec36
523CN_Tools_xbatChinese Hacktool Set - file xbat.vbshttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,FILE,HKTL,SCRIPT79fcc34418a66945907ddabfa59a8c2a
524CN_Tools_xsniffChinese Hacktool Set - file xsniff.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL81e842044f2f98649d79f4a27463daef
525CN_Toolset_LScanPortss_2Detects a Chinese hacktool from a disclosed toolset - file LScanPortss.exehttp://qiannao.com/ls/905300366/33834c0c/2015-03-30 00:00:0070Florian RothCHINA,HKTL0ddc973cf63fc297a209e287dae9d459
526CN_Toolset_NTscan_PipeCmdDetects a Chinese hacktool from a disclosed toolset - file PipeCmd.exehttp://qiannao.com/ls/905300366/33834c0c/2015-03-30 00:00:0070Florian RothCHINA,HKTL4df9c32d374e9b326b7c84136ce1d5a8
527CN_Toolset__XScanLib_XScanLib_XScanLibDetects a Chinese hacktool from a disclosed toolset - from files XScanLib.dll, XScanLib.dll, XScanLib.dllhttp://qiannao.com/ls/905300366/33834c0c/2015-03-30 00:00:0070Florian RothCHINA,HKTL49c5f68941cf3c37a02313e44d0f53cc
528CN_Toolset_sig_1433_135_sqlrDetects a Chinese hacktool from a disclosed toolset - file sqlr.exehttp://qiannao.com/ls/905300366/33834c0c/2015-03-30 00:00:0070Florian RothCHINA,HKTL196fdd5c3f2190e74b80abb73fc5c9a5
529CN_disclosed_20180208_KeyLogger_1Detects malware from disclosed CN malware sethttps://www.virustotal.com/graph/#/selected/n120z79z208z189/drawer/graph-details2018-02-08 00:00:0075Florian RothEXE,FILEce3aabef2fbe748d6253546c5caae118
530CN_disclosed_20180208_Mal1Detects malware from disclosed CN malware sethttps://www.virustotal.com/graph/#/selected/n120z79z208z189/drawer/graph-details2018-02-08 00:00:0075Florian RothEXE,FILE3101e9f2544751c5f474e1ea29796d97
531CN_disclosed_20180208_Mal4Detects malware from disclosed CN malware sethttps://www.virustotal.com/graph/#/selected/n120z79z208z189/drawer/graph-details2018-02-08 00:00:0075Florian RothEXE,FILE74c9e534cb34e029f3644d02818d7433
532CN_disclosed_20180208_Mal5Detects malware from disclosed CN malware sethttps://www.virustotal.com/graph/#/selected/n120z79z208z189/drawer/graph-details2018-02-08 00:00:0075Florian RothEXE,FILEe85aeaa15f1e8b82d5b0b95c0f9a90f2
533CN_disclosed_20180208_System3Detects malware from disclosed CN malware sethttps://twitter.com/cyberintproject/status/9617141655503421462018-02-08 00:00:0075Florian RothEXE,FILE9bcb5792841fded27d0d4c42d007a3b2
534CN_disclosed_20180208_cDetects malware from disclosed CN malware sethttps://twitter.com/cyberintproject/status/9617141655503421462018-02-08 00:00:0075Florian RothEXE,FILEc372c0976ae31d89902c755293eea83c
535CN_disclosed_20180208_lslsDetects malware from disclosed CN malware sethttps://twitter.com/cyberintproject/status/9617141655503421462018-02-08 00:00:0075Florian RothFILEf8a614a236ca6786dd77dd410ea6857a
536COZY_FANCY_BEAR_HuntDetects Cozy Bear / Fancy Bear C2 Server IPshttps://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/2016-06-14 00:00:0075Florian RothEXE,FILE,RUSSIA8625a07b826c1f692d660335c0d88c38
537COZY_FANCY_BEAR_modified_VmUpgradeHelperDetects a malicious VmUpgradeHelper.exe as mentioned in the CrowdStrike reporthttps://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/2016-06-14 00:00:0075Florian RothEXE,EXTVAR,FILE,RUSSIA7afa3db027f0568fec52ea7d757d87f4
538COZY_FANCY_BEAR_pagemgr_HuntDetects a pagemgr.exe as mentioned in the CrowdStrike reporthttps://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/2016-06-14 00:00:0075Florian RothEXE,FILE,RUSSIA60373e22d0f11c0c647932105e5f5735
539CVE_2014_4076_ExploitcodeDetects an exploit code for CVE-2014-4076https://github.com/Neo23x0/yarGen2018-04-04 00:00:0075Florian RothEXE,EXPLOIT,FILE00f42062a6535dee548150ea846e1904
540CVE_2015_1674_CNGSYSDetects exploits for CVE-2015-1674http://www.binvul.com/viewthread.php?tid=5082015-05-14 00:00:0075Florian RothEXE,EXPLOIT,FILEe836fcc4432f2ecf8f45da76bd8f9304
541CVE_2015_1701_TaihouCVE-2015-1701 compiled exploit codehttp://goo.gl/W4nU0q2015-05-13 00:00:0070Florian RothEXE,EXPLOIT,FILE4f0ae821c6a1fd5990289a3bc506f3a0
542CVE_2017_11882_RTFDetects suspicious Microsoft Equation OLE contents as used in CVE-2017-11882Internal Research2018-02-13 00:00:0060Florian RothEXPLOIT,FILEef27d0b93df82ef201724ade2ae2273b
543CVE_2017_8759_Mal_DocDetects malicious files related to CVE-2017-8759 - file Doc1.dochttps://github.com/Voulnet/CVE-2017-8759-Exploit-sample2017-09-14 00:00:0075Florian RothEXPLOIT,FILE5c93520f209dcfe349912c9463b43c29
544CVE_2017_8759_Mal_HTADetects malicious files related to CVE-2017-8759 - file cmd.htahttps://github.com/Voulnet/CVE-2017-8759-Exploit-sample2017-09-14 00:00:0075Florian RothEXPLOIT,FILE91ac33411ecb33ce0b04f5a12af01c46
545CVE_2017_8759_SOAP_ExcelDetects malicious files related to CVE-2017-8759https://twitter.com/buffaloverflow/status/9084550533458698252017-09-15 00:00:0060Florian RothEXPLOIT,OFFICEe31482bbeea9488a2661118446a35eb8
546CVE_2017_8759_SOAP_txtDetects malicious file in releation with CVE-2017-8759 - file exploit.txthttps://github.com/Voulnet/CVE-2017-8759-Exploit-sample2017-09-14 00:00:0075Florian RothEXPLOITcd2cd96573c20de5e68cfab5330d1a86
547CVE_2017_8759_SOAP_via_JSDetects SOAP WDSL Download via JavaScripthttps://twitter.com/buffaloverflow/status/9077283642780876802017-09-14 00:00:0060Florian RothEXPLOIT2be3f1a0db3bc48b7d3efcf756f2e479
548CVE_2017_8759_WSDL_in_RTFDetects malicious RTF file related CVE-2017-8759https://twitter.com/xdxdxdxdoa/status/9086652781999964162017-09-15 00:00:0075Security Doggo @xdxdxdxdoaEXPLOIT,EXTVAR,REQ_PRIVATEb3f31f437a181fd6536dee0780a794af
549Casper_Backdoor_x86Casper French Espionage Malware - Win32/ProxyBot.B - x86 Payload http://goo.gl/VRJNLohttp://goo.gl/VRJNLo2015-03-05 00:00:0080Florian RothHKTL,MALa63c3d2858b183e62c352efb0660bd52
550Casper_EXE_DropperCasper French Espionage Malware - Win32/ProxyBot.B - Dropper http://goo.gl/VRJNLohttp://goo.gl/VRJNLo2015-03-05 00:00:0080Florian RothHKTL,MALc36beb35fb4dfd49b45fa1036763409f
551Casper_Included_StringsCasper French Espionage Malware - String Match in File - http://goo.gl/VRJNLohttp://goo.gl/VRJNLo2015-03-06 00:00:0050Florian RothEXE,FILE,MAL508b869f2e152518fb5d439b8a4b20a2
552Casper_SystemInformation_OutputCasper French Espionage Malware - System Info Output - http://goo.gl/VRJNLohttp://goo.gl/VRJNLo2015-03-06 00:00:0070Florian RothMALfc27fd8f4cc505734516241907b065b2
553Casus15_php_phpSemi-Auto-generated - file Casus15.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL33eca24f2752efd245ddb57581a3071d
554Certutil_Decode_OR_DownloadCertutil DecodeInternal Research2017-08-29 00:00:0040Florian RothEXTVAR,REQ_PRIVATE,SCRIPTd3951a7bf1c5c6c2d00de10b9c440953
555Chafer_Exploit_Copyright_2017Detects Oilrig Internet Server Extension with Copyright (C) 2017 Exploithttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Markus NeisEXE,FILE,MIDDLE_EASTa8e4b99feb76c0df7a72b3b748679c5a
556Chafer_Mimikatz_CustomDetects Custom Mimikatz Versionhttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Florian Roth / Markus NeisEXE,FILE,MIDDLE_EAST166ac77cb3969436b74d66d7f8b97c70
557Chafer_Packed_MimikatzDetects Oilrig Packed Mimikatz also detected as Chafer_WSC_x64 by FRhttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Florian Roth / Markus NeisEXE,FILE,MIDDLE_EASTa7db6463555c66249169c9de91d77e13
558Chafer_PortscannerDetects Custom Portscanner used by Oilrighttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Markus NeisEXE,FILE,MIDDLE_EAST9a3b7aac5d412481c090713f894ac069
559CheshireCat_Gen1Auto-generated rule - file ec41b029c3ff4147b6a5252cb8b659f851f4538d4af0a574f7e16bc1cd14a300https://malware-research.org/prepare-father-of-stuxnet-news-are-coming/2015-08-08 00:00:0090Florian RothEXE,FILE54048ad5f41479c363b1ec1c1a48a589
560CheshireCat_Gen2Cheshire Cat Malwarehttps://malware-research.org/prepare-father-of-stuxnet-news-are-coming/2015-08-08 00:00:0070Florian RothEXE,FILE,MAL33fcd67aee2118149a54cb3b1dfd042b
561CheshireCat_Sample2Auto-generated rule - file dc18850d065ff6a8364421a9c8f9dd5fcce6c7567f4881466cee00e5cd0c7aa8https://malware-research.org/prepare-father-of-stuxnet-news-are-coming/2015-08-08 00:00:0070Florian RothEXE,FILE328474022f4d377f6192bed6dcc9c790
562ChinaChopper_GenericChina Chopper Webshells - PHP and ASPXhttps://www.fireeye.com/content/dam/legacy/resources/pdfs/fireeye-china-chopper-report.pdf2015-03-10 00:00:0075Florian RothCHINA,GEN,WEBSHELL4bb7e96a7be18d17ddcfe1c0f6298010
563ChinaChopper_caidaoChinese Hacktool Set - file caidao.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLc674185bb6f318e42175194828218eff
564ChinaChopper_oneChinese Hacktool Set - file one.asphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELLfe64735d438250cbad7c9723c14ba3b9
565ChinaChopper_tempChinese Hacktool Set - file temp.asphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL50d4e00b16beaf29f2af408e7b84f881
566ChinaChopper_temp_2Chinese Hacktool Set - file temp.phphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL57b56a3e726baee47dc69ea1c5559b34
567ChinaChopper_temp_3Chinese Hacktool Set - file temp.aspxhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,FILE,HKTL,WEBSHELLe7f2bf33da8a1d7d5252f29a112bea50
568Chinese_Hacktool_1014Detects a chinese hacktool with unknown use-2014-10-10 00:00:0060Florian RothCHINA,HKTL3a8d7b2852c971ea8810ed090e3d0151
569ChromePassDetects a tool used by APT groups - file ChromePass.exehttp://goo.gl/igxLyF2016-09-08 00:00:0075Florian RothAPT,EXE,FILE0058dc2c95cd61621ae7587c74518982
570CleanIISLogDisclosed hacktool set (old stuff) - file CleanIISLog.exe-2014-11-23 00:00:0060Florian RothHKTLf7f9246b1d12d6211c58261747cc8fbc
571Cloaked_RAR_FileRAR file cloaked by a different extension-1970-01-01 01:00:0075Florian RothEXTVAR,FILE175814794e324e345606ea6bd535b1a4
572Cloaked_as_JPGDetects a cloaked file as JPG-2015-02-28 00:00:0040Florian Roth (eval section from Didier Stevens)EXTVAR,FILE90d470799467e72c928763273235d079
573CloudDuke_MalwareDetects CloudDuke Malwarehttps://www.f-secure.com/weblog/archives/00002822.html2015-07-22 00:00:0060Florian RothEXE,FILE,MAL,RUSSIA81b63ced2b77709e2a93ee79e161b16c
574CmdAsp_aspSemi-Auto-generated - file CmdAsp.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLb407964cce301d5b119c24db06a2acb2
575CmdShell64Chinese Hacktool Set - file CmdShell64.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL37efdfc1d967c7ca77311447873612c9
576Cmdshell32Chinese Hacktool Set - file Cmdshell32.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLf5fa9d17853739cc4f6e74041ea4e4f8
577CobaltGang_Malware_Aug17_1Detects a Cobalt Gang malwarehttps://sslbl.abuse.ch/intel/6ece5ece4192683d2d84e25b0ba7e04f9cb7eb7c2017-08-09 00:00:0075Florian RothEXE,FILE,MALb2b8fe82b87faa1d62c290ca18422c8a
578CobaltGang_Malware_Aug17_2Detects a Cobalt Gang malwarehttps://sslbl.abuse.ch/intel/6ece5ece4192683d2d84e25b0ba7e04f9cb7eb7c2017-08-09 00:00:0075Florian RothEXE,FILE,MALd36380a856a0ab9616fec8184cc90c66
579CobaltStrike_CN_Group_BeaconDropper_Aug17Detects Script Dropper of Cobalt Gang used in August 2017Internal Research2017-08-09 00:00:0075Florian RothMAL4b85986fe24cde65221cff42ad3f7694
580Cobaltgang_PDF_Metadata_Rev_AFind documents saved from the same potential Cobalt Gang PDF templatehttps://researchcenter.paloaltonetworks.com/2018/10/unit42-new-techniques-uncover-attribute-cobalt-gang-commodity-builders-infrastructure-revealed/2018-10-25 00:00:0075Palo Alto Networks Unit 42d771a9e6ba5d11e23c565b52cfe785e5
581Codoso_CustomTCPCodoso CustomTCP Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothEXE,FILE,MAL48804fe32fbd66aed10af689fb8674dc
582Codoso_CustomTCP_2Detects Codoso APT CustomTCP Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL4fa1d49cc232579873942453b4ff6b61
583Codoso_CustomTCP_3Detects Codoso APT CustomTCP Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALc897622b6e3d8872838289ca239b4b5d
584Codoso_CustomTCP_4Detects Codoso APT CustomTCP Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALa9091c669a08690781265ee544cb29be
585Codoso_Gh0st_1Detects Codoso APT Gh0st Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL1ec0a5233de3da78e24990102e7aa52c
586Codoso_Gh0st_2Detects Codoso APT Gh0st Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL40e20a03cf14131b8c37cf4165175ed0
587Codoso_Gh0st_3Detects Codoso APT Gh0st Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL26900d91b40bfff57536a4a1232f17b3
588Codoso_PGV_PVID_1Detects Codoso APT PGV PVID Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALab3225ed535e8054ca44aab333c5cdbf
589Codoso_PGV_PVID_2Detects Codoso APT PGV PVID Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL71ed1da911b8adc4b985688cee96c054
590Codoso_PGV_PVID_3Detects Codoso APT PGV PVID Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,MAL39fdae689352b0e9377979baa644bfb2
591Codoso_PGV_PVID_4Detects Codoso APT PlugX Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALaad90017d970742a8b4a6c1dbb2e99fb
592Codoso_PGV_PVID_5Detects Codoso APT PGV PVID Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALaf012cf9fa6625b5d5b596bf1e952030
593Codoso_PGV_PVID_6Detects Codoso APT PGV_PVID Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MALf89c491439b2b95b22ec8dff6c671610
594Codoso_PlugX_1Detects Codoso APT PlugX Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL090a294c779e483207798a6a9fdd5d1e
595Codoso_PlugX_2Detects Codoso APT PlugX Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL7c0891b7ecde320280fe3a0999cd45c9
596Codoso_PlugX_3Detects Codoso APT PlugX Malwarehttps://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks2016-01-30 00:00:0075Florian RothAPT,EXE,FILE,MAL517258b3800f860bde2b8db59ad3a8f6
597CoinHive_Javascript_MoneroMinerDetects CoinHive - JavaScript Crypto Minerhttps://coinhive.com/documentation/miner2018-01-04 00:00:0050Florian Rotha63b91b52e08cf7061223fc7d140e180
598CoinMiner_StringsDetects mining pool protocol string in Executablehttps://minergate.com/faq/what-pool-address2018-01-04 00:00:0050Florian Roth0376a5f767eae520701d2f90d49a36f7
599CookieTools2Chinese Hacktool Set - file CookieTools2.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL623d621cd7c34eac94c21ae4f9cc67b2
600CookieToolsChinese Hacktool Set - file CookieTools.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd3eec543cf2344d13b0bd2d1fb274e64
601CoreImpact_sysdll_exeDetects a malware sysdll.exe from the Rocket Kitten APT-2014-12-27 00:00:0070Florian RothAPT,MIDDLE_EASTe758e0de0674ded55ae4e035dc4a1641
602CorkowDLLRule to detect the Corkow DLL files-2016-02-06 00:00:0075Group IBEXE,FILE6865fc797565280ff4806c0db15428ac
603Crackmapexec_EXEDetects CrackMapExec hack toolInternal Research2018-04-06 00:00:0085Florian RothEXE,FILE,HKTLacc5c292d36402509047e152546bc5cb
604CredentialStealer_Generic_BackdoorDetects credential stealer byed on many strings that indicate password store accessInternal Research2017-06-07 00:00:0075Florian RothEXE,FILE,GEN,MAL8783d298ba001abc08aa5dc32383f3ee
605CrimsonRAT_Mar18_1Detects CrimsonRAT malwareInternal Research2018-03-06 00:00:0075Florian RothEXE,FILE,MALb94ecf53d3bcae109df1414b9f27486a
606CrowdStrike_Shamoon_DroppedFileRule to detect Shamoon malware http://goo.gl/QTxohNhttp://www.rsaconference.com/writable/presentations/file_upload/exp-w01-hacking-exposed-day-of-destruction.pdf1970-01-01 01:00:0075Florian Roth (auto-filled)MIDDLE_EASTe067c46be7cfee1bde054614d5d6b7a2
607CrunchRATDetects CrunchRAT - file CrunchRAT.exehttps://github.com/t3ntman/CrunchRAT2017-11-03 00:00:0075Florian RothEXE,FILE,MAL2f44455075167c17b144dc3a70b2f094
608CustomizeChinese Hacktool Set - file Customize.aspxhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL00e8c27ceb39d9d30d176fa274657d30
609Customize_2Chinese Hacktool Set - file Customize.jsphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL332988e785373430636837524c1e80c7
610DKShell_f0772be3c95802a2d1e7a4a3f5a45dcdef6997f3Detects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL7955b61923d939e26295faebf5f08997
611DK_BrutePoS Scammer Toolbox - http://goo.gl/xiIphp - file DK Brute.exehttp://goo.gl/xiIphp2014-11-22 00:00:0070Florian RothHKTLd34d983c28f36c9977ed2472176d5142
612DLL_Injector_LynxDetects Lynx DLL InjectorInternal Research2017-08-20 00:00:0075Florian RothEXE,FILE,HKTL072ab30488dc228516251ee898963fc2
613DTool_Pro_phpSemi-Auto-generated - file DTool Pro.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL8a9f14ff23d04617165a2134803a9fd7
614DTools2_02_DToolsChinese Hacktool Set - file DTools.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL0c586d0a4945d0b6c50e7edb911b33b8
615DUBrute_DUBruteChinese Hacktool Set - file DUBrute.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLe7d7d00f997f01103453538072d10647
616DarkComet_Keylogger_FileLooks like a keylogger file created by DarkComet Malware-2014-07-25 00:00:0050Florian RothFILE,HKTL,MAL02e873f4adf37c54594a9e34c65b3f91
617DarkEYEv3_CryptorRule to detect DarkEYEv3 encrypted executables (often malware)http://darkeyev3.blogspot.fi/2015-05-24 00:00:0055Florian RothEXE,FILE0dbe69f1711caa056c04ea022a2f94d8
618DarkSecurityTeam_WebshellDark Security Team Webshell-1970-01-01 01:00:0050Florian RothWEBSHELL287d0d9b079e437164326890200251bb
619DarkSpy105Webshells Auto-generated - file DarkSpy105.exe-1970-01-01 01:00:0075Florian RothWEBSHELL34bd97e8d696022dd48e695db79efda0
620Daserf_Nov1_BronzeButlerDetects Daserf malware used by Bronze Butlerhttps://goo.gl/ffeCfd2017-11-08 00:00:0075Florian RothEXE,FILE1a2e59a16103002c417ebd9405777a79
621Datper_BackdoorDetects Datper Malwarehttp://blog.jpcert.or.jp/2017/08/detecting-datper-malware-from-proxy-logs.html2017-08-21 00:00:0075Florian RothEXE,FILE,MAL3cb4f12c84f36ac49b64842222f56d8b
622Debug_BDoorWebshells Auto-generated - file BDoor.dll-1970-01-01 01:00:0075Florian RothMAL,WEBSHELL3a8188f48535d9f046ccd9ae585b94b8
623Debug_cressWebshells Auto-generated - file cress.exe-1970-01-01 01:00:0075Florian RothWEBSHELL853ad7a1ad2ffc0ce705811ce06df956
624Debug_dllTest_2Webshells Auto-generated - file dllTest.dll-1970-01-01 01:00:0075Florian RothWEBSHELL183ad1a70b017fb8403a0ad6b2c99830
625DeepPanda_Trojan_KakfumHack Deep Panda - Trojan.Kakfum sqlsrv32.dll-2015-02-08 00:00:0075Florian RothCHINA,MAL4dcd758d4ec3ae58da77ba1b594db1f0
626DeepPanda_htran_exeHack Deep Panda - htran-exe-2015-02-08 00:00:0075Florian RothCHINAb945cd4ac408326375d2788d5a10b76f
627DeepPanda_lot1Hack Deep Panda - lot1.tmp-pwdump-2015-02-08 00:00:0075Florian RothCHINA81138d1ebad2ed4de9c93f6196797858
628DeepPanda_sl_txt_packedHack Deep Panda - ScanLine sl-txt-packed-2015-02-08 00:00:0075Florian RothCHINAfc53e2d0d744abfe0b47fe0c02e96892
629DefaceKeeper_0_2_phpSemi-Auto-generated - file DefaceKeeper_0.2.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLe381cba4bbf69722a703222f6e19c9ca
630Derusbi_Backdoor_Mar17_1Detects a variant of the Derusbi backdoorInternal Research2017-03-03 00:00:0075Florian RothEXE,FILE,MAL840583059cdfc5e3f0d1885e40a9cb2f
631Derusbi_Code_Signing_CertDetects an executable signed with a certificate also used for Derusbi Trojan - suspicioushttp://blog.airbuscybersecurity.com/post/2015/11/Newcomers-in-the-Derusbi-family2015-12-15 00:00:0060Florian RothEXE,FILE,MAL6825d00a1f11e7fdaab6f6b4f9a49ae9
632Derusbi_Kernel_Driver_WD_UDFSDetects Derusbi Kernel Driverhttp://blog.airbuscybersecurity.com/post/2015/11/Newcomers-in-the-Derusbi-family2015-12-15 00:00:0080Florian RothEXE,FILE3cad4591c7165b723bd639e657ab52aa
633Destructive_Ransomware_Gen1Detects destructive malwarehttp://blog.talosintelligence.com/2018/02/olympic-destroyer.html2018-02-12 00:00:0075Florian RothCRIME,EXE,FILEb62321e394fe16b344868a2b3409fd1c
634DeviceGuard_WDS_EvasionDetects WDS file used to circumvent Device Guardhttp://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html1970-01-01 01:00:0080Florian RothOBFUScb4573bc612bc3be444cb037b0dabb1d
635Dexter_MalwareDetects the Dexter Trojan/Agent http://goo.gl/oBvy8bhttp://goo.gl/oBvy8b2015-02-10 00:00:0070Florian RothMALd2dfa50d329079da20d64cdf9e7201be
636Disclosed_0day_POCs_InjectDllDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTL71df2c5acf52c49393584fcedae2afe8
637Disclosed_0day_POCs_exploitDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTLab9c0a5da96179e02861c7ec580ff7f3
638Disclosed_0day_POCs_injectorDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTLdabae5526b4e238ab1fd3763dfb9e36f
639Disclosed_0day_POCs_lpeDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTLdaf7f29073ea3c2cb8c18403e9345790
640Disclosed_0day_POCs_lpe_2Detects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTL4be7ec131429441e2e73969fa43fa0c4
641Disclosed_0day_POCs_payload_MSIDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXPLOIT,FILE,HKTLc200000f11f46c9b86319c7010c30465
642Disclosed_0day_POCs_shellcodegeneratorDetects POC code from disclosed 0day hacktool setDisclosed 0day Repos2017-07-07 00:00:0075Florian RothEXE,EXPLOIT,FILE,HKTLd2e46d9a7e3e67b0c92b076af823b794
643Dive_Shell_1_0___Emperor_Hacking_Team_phpSemi-Auto-generated - file Dive Shell 1.0 - Emperor Hacking Team.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL9fb8c63b434029f4c253afae5d136503
644DkShell_4000bd83451f0d8501a9dfad60dce39e55ae167dDetects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL5725a6161ef6ab41f3415acd28bbe171
645DllInjectionWebshells Auto-generated - file DllInjection.exe-1970-01-01 01:00:0075Florian RothHKTL,WEBSHELL3784c3b2a24c82d2429640857ad8c03d
646Dll_LoadExChinese Hacktool Set - file Dll_LoadEx.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLe350443a78dbea2e37af1c0eed6155cf
647Docm_in_PDFDetects an embedded DOCM in PDF combined with OpenActionInternal Research2017-05-15 00:00:0075Florian RothFILE8591203da3bb272c29e9b084e9db1b4b
648DomainScanV1_0Auto-generated rule on file DomainScanV1_0.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLdb400263a64c6890331b1ac664ab41df
649Dorkbot_Injector_MalwareDetects Darkbot InjectorInternal Research2016-10-08 00:00:0075Florian RothEXE,FILE,HKTL,MALbf7ca70ea15e0f2efa023931c793950d
650Dos_1Chinese Hacktool Set - file 1.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd0725a81879d3308ac7518179bfd1f0b
651Dos_Down32Chinese Hacktool Set - file Down32.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL736febecdb790c495ceb24d188b0750a
652Dos_Down64Chinese Hacktool Set - file Down64.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL7bee9f6409898b7e6cb32f4f89432771
653Dos_GetPassChinese Hacktool Set - file GetPass.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLaa6e1d90f2e7aed657b99e383b323f85
654Dos_NtGodChinese Hacktool Set - file NtGod.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL2e5533b6c0e50cd56016e5132146ee79
655Dos_cChinese Hacktool Set - file c.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLb16928f4f2a406788a99e90b933afae5
656Dos_chChinese Hacktool Set - file ch.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd42a9077eb29661a2680863348992d45
657Dos_fpChinese Hacktool Set - file fp.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1f88d629ef127a20298070ae85d16902
658Dos_iis7Chinese Hacktool Set - file iis7.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL573a12eb9749981f13f13e44f5251747
659Dos_iisChinese Hacktool Set - file iis.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1bf9342b909fb80fe5efe5c0391c1f87
660Dos_lcxChinese Hacktool Set - file lcx.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL60f1c514beeda7798fe7b94a80881cc6
661Dos_lookChinese Hacktool Set - file look.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLb42d4ad1d0136cbaf5ee1e0f9e211ccd
662Dos_netstatChinese Hacktool Set - file netstat.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL84a38f46dc22c0feb0fe7bae1a5ed5ba
663Dos_sysChinese Hacktool Set - file sys.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd83d40b264e8f142eced140de3777737
664DragonFly_APT_Sep17_1Detects malware from DrqgonFly APT reporthttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group2017-09-12 00:00:0075Florian RothAPT,EXE,FILE041389263d30bea7f856e6489fa72aae
665DragonFly_APT_Sep17_2Detects malware from DrqgonFly APT reporthttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group2017-09-12 00:00:0075Florian RothAPT,EXE,FILE2bf6250527b5d68ad5a5d96a9cf751ca
666DragonFly_APT_Sep17_3Detects malware from DrqgonFly APT reporthttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group2017-09-12 00:00:0075Florian RothAPT,EXE,FILEf1d6e70129f7341627c6d1b688214034
667DragonFly_APT_Sep17_4Detects malware from DrqgonFly APT reporthttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group2017-09-12 00:00:0075Florian RothAPT,EXE,FILE8884eaf6d00828032e2b42941b94f937
668Dridex_Trojan_XMLDridex Malware in XML Documenthttps://threatpost.com/dridex-banking-trojan-spreading-via-macros-in-xml-files/1115032015-03-08 00:00:0075Florian Roth @4nc4pMAL5a60b02253161fcb1335f0cc4674fc14
669DropBear_SSH_ServerDetects DropBear SSH Server (not a threat but used to maintain access)http://feedproxy.google.com/~r/eset/blog/~3/BXJbnGSvEFc/2016-01-03 00:00:0050Florian RothEXE,FILE,RUSSIAc5d92dd2239d05b6ab8544cfa0f093f8
670Dropper_DeploysMalwareViaSideLoadingDetect a dropper used to deploy an implant via side loading. This dropper has specifically been observed deploying REDLEAVES & PlugXhttps://www.us-cert.gov/ncas/alerts/TA17-117A1970-01-01 01:00:0075USGMAL14a3885d08ca41b61841483ee4bd92cc
671Dubnium_Sample_1Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILEcc337bbc7abd167e2e3e34a439a51847
672Dubnium_Sample_2Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILE96e4ba0245bbb1298ca68e102a38556c
673Dubnium_Sample_3Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILE8470ed9aaa85e62ec098196f89f20a70
674Dubnium_Sample_5Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILE2ec97c979ec36f70de8602f425272178
675Dubnium_Sample_6Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILE8b4afa47172c15876d2a122c47469fad
676Dubnium_Sample_7Detects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILEd842e5cd26af008835fcbd4c12b56749
677Dubnium_Sample_SSHOpenSSLDetects sample mentioned in the Dubnium Reporthttps://goo.gl/AW9Cuu2016-06-10 00:00:0075Florian RothEXE,FILEa56308d4ac87c8e82ac8c55864b5dbfd
678Duqu2_Generic1Kaspersky APT Report - Duqu2 Sample - Generic Rulehttps://goo.gl/7yKyOj2015-06-10 00:00:0075Florian RothAPT,EXE,FILE,GEN1abe669252467f4730656dba316cbe52
679Duqu2_Sample1Detects malware - Duqu2 (cross-matches with IronTiger malware and Derusbi)https://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/2016-07-02 00:00:0080Florian RothEXE,FILE,INDIA42a3dce0826282a67267950b43dcbb08
680Duqu2_Sample2Detects Duqu2 Malwarehttps://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/2016-07-02 00:00:0080Florian RothEXE,FILE,MAL858bc8ad641fd659cc416020e315d44f
681Duqu2_Sample3Detects Duqu2 Malwarehttps://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/2016-07-02 00:00:0080Florian RothEXE,FILE,MAL20ab712d5a884aa49b5c8e39a1fa5103
682Duqu2_Sample4Detects Duqu2 Malwarehttps://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/2016-07-02 00:00:0080Florian RothEXE,FILE,MAL792e67995304dc4b9a06b2039b561512
683Duqu2_UAsDetects Duqu2 Executable based on the specific UAs in the filehttps://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/2016-07-02 00:00:0080Florian RothEXE,FILE71c00df0e48e2f62ee4667642347c535
684DxShell_php_phpSemi-Auto-generated - file DxShell.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL5517579d243a70a985430bf4e7c34cf2
685Dx_php_phpSemi-Auto-generated - file Dx.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL3a164b5bfba340b5026c2421eae2004b
686EFSO_2_aspSemi-Auto-generated - file EFSO_2.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL8bf184090f9a6aa3d31a54dd60f489a6
687EQGRP_1212Detects tool from EQGRP toolset - file 1212.plResearch2016-08-15 00:00:0075Florian Roth7c6979d6da9ddd08509e6d43db635609
688EQGRP_1212_dehexDetects tool from EQGRP toolset - from files 1212.pl, dehex.plResearch2016-08-15 00:00:0075Florian RothFILE17f2525df3dd9f20d6d7897592f157bd
689EQGRP_BARPUNCH_BPICKEREQGRP Toolset Firewall - from files BARPUNCH-3110, BPICKER-3100Research2016-08-16 00:00:0075Florian RothFILEb1c6840d77de5a0af6134d5438661e49
690EQGRP_BBALLEQGRP Toolset Firewall - file BBALL_E28F6-2201.exeResearch2016-08-16 00:00:0075Florian RothFILEe5ff07052dc73cccc612b4a13a592e4e
691EQGRP_BBALL_M50FW08_2201EQGRP Toolset Firewall - file BBALL_M50FW08-2201.exeResearch2016-08-16 00:00:0075Florian RothFILEc88c2f9cdaf2fa9ef9a2bce3fdcc5d19
692EQGRP_BBANJOEQGRP Toolset Firewall - file BBANJO-3011.exeResearch2016-08-16 00:00:0075Florian RothFILEcfa5dedbe2cebe0bf69b3a7f1893030b
693EQGRP_BFLEA_2201EQGRP Toolset Firewall - file BFLEA-2201.exeResearch2016-08-16 00:00:0075Florian RothFILEd2e7e34a5f431f1a059a8276e563f30a
694EQGRP_BICECREAMEQGRP Toolset Firewall - file BICECREAM-2140Research2016-08-16 00:00:0075Florian RothFILE2e12f1c7de4d5b14113b639d8c81a5d6
695EQGRP_BLIAR_BLIQUEREQGRP Toolset Firewall - from files BLIAR-2110, BLIQUER-2230Research2016-08-16 00:00:0075Florian RothFILEa7bf69ed4d7a0ce38e1d38fc7d976b6f
696EQGRP_BPATROL_2201EQGRP Toolset Firewall - file BPATROL-2201.exeResearch2016-08-16 00:00:0075Florian RothFILE9e1cb52fe08587705d4e210ef3f37cd0
697EQGRP_BPIEEQGRP Toolset Firewall - file BPIE-2201.exeResearch2016-08-16 00:00:0075Florian RothFILE89181d624030f60cda8ded63d04125d6
698EQGRP_BUSURPER_2211_724EQGRP Toolset Firewall - file BUSURPER-2211-724.exeResearch2016-08-16 00:00:0075Florian Rothd321ea7b77f23d0a23b3c5828563ad91
699EQGRP_BUSURPER_3001_724EQGRP Toolset Firewall - file BUSURPER-3001-724.exeResearch2016-08-16 00:00:0075Florian RothFILE06ee316e9ebb05dbd793779766196127
700EQGRP_BananaAidEQGRP Toolset Firewall - file BananaAidResearch2016-08-16 00:00:0075Florian Rothfff10477e6dbfdfb7727fecf0cbf2e85
701EQGRP_BananaUsurper_writeJetPlowEQGRP Toolset Firewall - from files BananaUsurper-2120, writeJetPlow-2130Research2016-08-16 00:00:0075Florian RothFILE1ecb55168ddd3eccea357b97c48c6f43
702EQGRP_BpfCreator_RHEL4EQGRP Toolset Firewall - file BpfCreator-RHEL4Research2016-08-16 00:00:0075Florian RothFILE147bc90bc93754d48cc794c96c8236f6
703EQGRP_EPBAEQGRP Toolset Firewall - file EPBA.scriptResearch2016-08-16 00:00:0075Florian RothFILEca90782a116c335cf29a738146018259
704EQGRP_Extrabacon_OutputEQGRP Toolset Firewall - Extrabacon exploit outputResearch2016-08-16 00:00:0075Florian Roth1a6483adc2dbc283120ccb518119d749
705EQGRP_Implants_Gen1EQGRP Toolset FirewallResearch2016-08-16 00:00:0075Florian RothFILE75bd3ae3ea69b6241f986183ff8896c1
706EQGRP_Implants_Gen2EQGRP Toolset FirewallResearch2016-08-16 00:00:0075Florian RothFILE9e81c11386ca1c7e6fcfa1cf4f935860
707EQGRP_Implants_Gen3EQGRP Toolset FirewallResearch2016-08-16 00:00:0075Florian RothFILEd40aa3e5d8e87cf6a6c0d865ba9f4d57
708EQGRP_Implants_Gen4EQGRP Toolset Firewall - from files BLIAR-2110, BLIQUER-2230, BLIQUER-3030, BLIQUER-3120Research2016-08-16 00:00:0075Florian RothFILE14e9c9bada21f8d6fe7c231038779bda
709EQGRP_Implants_Gen5EQGRP Toolset FirewallResearch2016-08-16 00:00:0075Florian RothFILE4aa479e184f933d8cb4dad20d1a38ef2
710EQGRP_Implants_Gen6EQGRP Toolset FirewallResearch2016-08-16 00:00:0075Florian RothFILE389e11e9aec54aff67796e7e077132d5
711EQGRP_MixTextEQGRP Toolset Firewall - file MixText.pyResearch2016-08-16 00:00:0075Florian Rothe5ff327d23b429d8eb0f8da9647c08c9
712EQGRP_RC5_RC6_OpcodeEQGRP Toolset Firewall - RC5 / RC6 opcodehttps://securelist.com/blog/incidents/75812/the-equation-giveaway/2016-08-17 00:00:0075Florian Rothb38cb20b42b04d579fa9b8eef3c2b076
713EQGRP_SecondDate_2211EQGRP Toolset Firewall - file SecondDate-2211.exeResearch2016-08-16 00:00:0075Florian RothFILE4980391841b856e9e16e9873e70586e2
714EQGRP_StoreFcEQGRP Toolset Firewall - file StoreFc.pyResearch2016-08-16 00:00:0075Florian Roth210b02d6530b8718fffa89ad530fcd0d
715EQGRP_Unique_StringsEQGRP Toolset Firewall - Unique stringsResearch2016-08-16 00:00:0075Florian Roth5d187740298457865db568d7659e6b50
716EQGRP_bc_parserDetects tool from EQGRP toolset - file bc-parserResearch2016-08-15 00:00:0075Florian RothFILE82acaef9436942eae235375f0889a971
717EQGRP_boEQGRP Toolset Firewall - file boResearch2016-08-16 00:00:0075Florian RothFILEce90861e83f3bd08475173409c8e65ea
718EQGRP_callbacksEQGRP Toolset Firewall - Callback addressesResearch2016-08-16 00:00:0075Florian Rothdf044b137e069c5d842e58e48499317e
719EQGRP_config_jp1_UAEQGRP Toolset Firewall - file config_jp1_UA.plResearch2016-08-16 00:00:0075Florian Roth8d4924e8e020a13f3b2e1e4d5e231864
720EQGRP_create_dns_injectionEQGRP Toolset Firewall - file create_dns_injection.pyResearch2016-08-16 00:00:0075Florian Roth40f64937508bec4cf5247484111f1cc3
721EQGRP_create_http_injectionEQGRP Toolset Firewall - file create_http_injection.pyResearch2016-08-16 00:00:0075Florian RothFILE30c5f17a31115d9bf3ec176894765b38
722EQGRP_dn_1_0_2_1Detects tool from EQGRP toolset - file dn.1.0.2.1.linuxResearch2016-08-15 00:00:0075Florian RothFILEbfface3706e55e7e9fd04ac768904589
723EQGRP_durablenapkin_solaris_2_0_1Detects tool from EQGRP toolset - file durablenapkin.solaris.2.0.1.1Research2016-08-15 00:00:0075Florian RothFILE11eca751993ecf7a56917767fafba597
724EQGRP_eligiblebombshell_genericEQGRP Toolset Firewall - from files eligiblebombshell_1.2.0.1.py, eligiblebombshell_1.2.0.1.pyResearch2016-08-16 00:00:0075Florian Roth8c33e5cc0110299bfa280e9aff62071d
725EQGRP_eligiblecandidateEQGRP Toolset Firewall - file eligiblecandidate.pyResearch2016-08-16 00:00:0075Florian Roth55d542a53d2169b25bdb0bcbc385c1fd
726EQGRP_epicbanana_2_1_0_1EQGRP Toolset Firewall - file epicbanana_2.1.0.1.pyResearch2016-08-16 00:00:0075Florian Roth0143e3e7de8d23cc48400394874ebe9a
727EQGRP_extrabaconEQGRP Toolset Firewall - file extrabacon_1.1.0.1.pyResearch2016-08-16 00:00:0075Florian Roth962c67327ad32f344713237f8b1ef52f
728EQGRP_falseDetects tool from EQGRP toolset - file false.exeResearch2016-08-15 00:00:0075Florian RothEXE,FILEd46b5d5ba85dcaae28d2e05e813a0cb2
729EQGRP_hexdumpEQGRP Toolset Firewall - file hexdump.pyResearch2016-08-16 00:00:0075Florian RothFILE38a52d2892755d6c5d269008b20a1377
730EQGRP_installdateDetects tool from EQGRP toolset - file installdate.plResearch2016-08-15 00:00:0075Florian Rothc537182739153ad9b88acaf20be76ca4
731EQGRP_jetplow_SHEQGRP Toolset Firewall - file jetplow.shResearch2016-08-16 00:00:0075Florian Roth3879f43ed991cc40dc0095c98b2059da
732EQGRP_morelDetects tool from EQGRP toolset - file morel.exeResearch2016-08-15 00:00:0075Florian RothEXE,FILE67eecc3f25eef7efe54081fbed28a4c0
733EQGRP_networkProfiler_orderScansEQGRP Toolset Firewall - file networkProfiler_orderScans.shResearch2016-08-16 00:00:0075Florian Rothf23017fa5a89bd2b5138d21b9f390229
734EQGRP_noclient_3_0_5Detects tool from EQGRP toolset - file noclient-3.0.5.3Research2016-08-15 00:00:0075Florian RothFILE28a7849171571982c700e7e74512b48c
735EQGRP_pandarockEQGRP Toolset Firewall - from files pandarock_v1.11.1.1.bin, pitResearch2016-08-16 00:00:0075Florian RothFILE9f219785ef69da5d69946d5cc8598a2c
736EQGRP_payloadEQGRP Toolset Firewall - file payload.pyResearch2016-08-16 00:00:0075Florian Rothdb7972df2a542c87dab866c324c89754
737EQGRP_screamingplowEQGRP Toolset Firewall - file screamingplow.shResearch2016-08-16 00:00:0075Florian Roth97617c6c734f56af00f141ef70808b1a
738EQGRP_shellcodeEQGRP Toolset Firewall - file shellcode.pyResearch2016-08-16 00:00:0075Florian Roth49ce5d8476c4b999f6e35bb059d362c6
739EQGRP_sniffer_xml2pcapEQGRP Toolset Firewall - file sniffer_xml2pcapResearch2016-08-16 00:00:0075Florian Roth0d119859efc7d96ad9b9029bd0083211
740EQGRP_sploitEQGRP Toolset Firewall - from files sploit.py, sploit.pyResearch2016-08-16 00:00:0075Florian RothFILE14faa51b9a7825311f23230571632abd
741EQGRP_sploit_pyEQGRP Toolset Firewall - file sploit.pyResearch2016-08-16 00:00:0075Florian Roth75392d2c415fd57df243f0e1f7999af7
742EQGRP_ssh_telnet_29EQGRP Toolset Firewall - from files ssh.py, telnet.pyResearch2016-08-16 00:00:0075Florian Roth6630ce60a4d71641f638818614caec6d
743EQGRP_teflondoorDetects tool from EQGRP toolset - file teflondoor.exeResearch2016-08-15 00:00:0075Florian RothEXE,FILE6ff5825dd6b1b225f60f3e131a1947e5
744EQGRP_teflonhandleDetects tool from EQGRP toolset - file teflonhandle.exeResearch2016-08-15 00:00:0075Florian RothEXE,FILEe2d3f7a6f37f35eb02c5eaefe137b018
745EQGRP_tinyexecEQGRP Toolset Firewall - from files tinyexecResearch2016-08-16 00:00:0075Florian RothFILE6c9162cf7f4d1da8645b10b8293e3854
746EQGRP_tinyhttp_setupEQGRP Toolset Firewall - file tinyhttp_setup.shResearch2016-08-16 00:00:0075Florian RothFILEf05e8b4242e4da5bf1460d42072387bb
747EQGRP_tunnel_state_readerEQGRP Toolset Firewall - file tunnel_state_readerResearch2016-08-16 00:00:0075Florian Roth3933c0823eb49d7f12d91216fbc27220
748EQGRP_uninstallPBDEQGRP Toolset Firewall - file uninstallPBD.batResearch2016-08-16 00:00:0075Florian Roth030aa292729c501d6b51cf53d8414f8f
749EQGRP_userscriptEQGRP Toolset Firewall - file userscript.FWResearch2016-08-16 00:00:0075Florian Rothc302f2fc10e4368c37baefd0498a7b9a
750EQGRP_workitEQGRP Toolset Firewall - file workit.pyResearch2016-08-16 00:00:0075Florian Roth3cdddd5f4ee23019238eaed2d86cfa0e
751EXE_cloaked_as_TXTExecutable with TXT extension-1970-01-01 01:00:0075Florian RothEXE,EXTVAR,FILE576f24d95b92db4276dfda4f947323cf
752EXE_extension_cloakingExecutable showing different extension (Windows default 'hide known extension')-1970-01-01 01:00:0075Florian RothEXTVARb6fa473cf0fad20a26af3401f5d35ddf
753EXP_DriveCrypt_1Detects DriveCrypt exploitInternal Research2018-08-21 00:00:0075Florian RothEXE,FILEe1bc3892d05a54250758c939008d8690
754EXP_DriveCrypt_x64passldrDetects DriveCrypt exploitInternal Research2018-08-21 00:00:0075Florian RothEXE,FILE2aec493ab46702c51af2a9dc5a6df802
755EXP_Libre_Office_CVE_2018_16858RCE in Libre Office with crafted ODT file (CVE-2018-16858)https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html2019-02-01 00:00:0075John Lambert @JohnLaTwC / modified by Florian RothEXPLOIT,FILE,OFFICE72f61f72487cc2d22901f609faf540ca
756EXP_potential_CVE_2017_11882-https://www.reversinglabs.com/newsroom/news/reversinglabs-yara-rule-detects-cobalt-strike-payload-exploiting-cve-2017-11882.html1970-01-01 01:00:0075ReversingLabsEXPLOIT,FILE0252985f2de0e1d9c79626b9e8c35d9e
757EditKeyLogDisclosed hacktool set (old stuff) - file EditKeyLog.exe-2014-11-23 00:00:0060Florian RothHKTLae5fe4e5125c7bb016a1ceec9b59d5f5
758EditKeyLogReadMeDisclosed hacktool set (old stuff) - file EditKeyLogReadMe.txt-2014-11-23 00:00:0060Florian RothHKTL724df4898eca7886c1988c434674c3ec
759EditServerDisclosed hacktool set (old stuff) - file EditServer.exe-2014-11-23 00:00:0060Florian RothHKTL76eca2bb98f8b5fbeeb81b78610d8f78
760EditServer_2Webshells Auto-generated - file EditServer.exe-1970-01-01 01:00:0075Florian RothWEBSHELLd7f376503813ec00f7098ee317b40a68
761EditServer_EXEWebshells Auto-generated - file EditServer.exe-1970-01-01 01:00:0075Florian RothWEBSHELLf7c34844a075488f569775e1fb74bcaf
762EldoS_RawDiskEldoS Rawdisk Device Driver (Commercial raw disk access driver - used in Operation Shamoon 2.0)https://goo.gl/jKIfGB2016-12-01 00:00:0050Florian Roth (with Binar.ly)EXE,FILE,MIDDLE_EASTce1afeb11c3dfbc0d48b5820678fece6
763Elise_Jan18_1Detects Elise malware samples - fake Norton Security NavShExt.dllhttps://twitter.com/blu3_team/status/9559717423291351052018-01-24 00:00:0075Florian RothEXE,FILE93ed708cddd7fb5b7017e3e2573e8502
764Embedded_EXE_CloakingDetects an embedded executable in a non-executable file-2015-02-27 00:00:0065Florian RothEXTVAR5d0c8c79c9da3ffe4c788b52d30e605e
765Emdivi_Gen1Detects Emdivi Malwarehttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/2015-08-20 00:00:0080Florian Roth @Cyber0psEXE,FILE,MALd6b91e3d623099ffa3c7194b70079ccc
766Emdivi_Gen2Detects Emdivi Malwarehttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/2015-08-20 00:00:0080Florian Roth @Cyber0psEXE,FILE,MAL56b8a6bb85f18f2c60e4d69a7d835207
767Emdivi_Gen3Detects Emdivi Malwarehttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/2015-08-20 00:00:0080Florian Roth @Cyber0psEXE,FILE,MAL18547d6ad5a9b859dfd85397e8acc331
768Emdivi_Gen4Detects Emdivi Malwarehttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/2015-08-20 00:00:0080Florian Roth @Cyber0psEXE,FILE,MAL6b8302e3e12d1559845c42cbda8d05db
769Emdivi_SFXDetects Emdivi malware in SFX Archivehttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/2015-08-20 00:00:0070Florian Roth @Cyber0psEXE,FILE48a1d72e13349fc01487383b03314c23
770Emissary_APT_Malware_1Detect Emissary Malware - from samples A08E81B411.DAT, ishelp.dllhttp://goo.gl/V0epcf2016-01-02 00:00:0075Florian RothAPT,EXE,FILE,MAL6d7ed0cef7d27fe0c21b39c84e1cf2a5
771Empire_Agent_GenDetects Empire component - from files agent.ps1, agent.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GEN6a64c71600326b1464ea33dbde73d751
772Empire_Exploit_JBossDetects Empire component - file Exploit-JBoss.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE431a913047e22558fba85862c81399fc
773Empire_Exploit_JenkinsDetects Empire component - file Exploit-Jenkins.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILEfcc7c2ff213cbd95e99615bc0e098309
774Empire_Get_GPPPasswordDetects Empire component - file Get-GPPPassword.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILEf2f1c775c6199ebe1619c2a28597e7f6
775Empire_Get_KeystrokesDetects Empire component - file Get-Keystrokes.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE8d02d71ef33099cc0ef4475eefef83cc
776Empire_Get_SecurityPackagesDetects Empire component - file Get-SecurityPackages.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILEf38f2c0ac0404985c807792c27bba37a
777Empire_Install_SSPDetects Empire component - file Install-SSP.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE21f3004f4cdd85bd32619be69e642f8d
778Empire_Invoke_BypassUACEmpire - a pure PowerShell post-exploitation agent - file Invoke-BypassUAC.ps1https://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPT87f4ffc5ca0f06a2680abeb6b903837a
779Empire_Invoke_CredentialInjection_Invoke_Mimikatz_GenDetects Empire component - from files Invoke-CredentialInjection.ps1, Invoke-Mimikatz.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GEN,HKTL782ea2bed8abd6414f4528c7546eb9eb
780Empire_Invoke_DllInjectionDetects Empire component - file Invoke-DllInjection.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,HKTLf108fb4a477ead407fe348cba725fc8e
781Empire_Invoke_EgressCheckDetects Empire component - file Invoke-EgressCheck.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE8a180036af68dafdad3d4bf02db4bd65
782Empire_Invoke_GenDetects Empire component - from files Invoke-DCSync.ps1, Invoke-PSInject.ps1, Invoke-ReflectivePEInjection.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GEN,HKTL6781b86147aadec0c02a9039bbf2991d
783Empire_Invoke_InveighRelay_GenDetects Empire component - from files Invoke-InveighRelay.ps1, Invoke-InveighRelay.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GEN131e679e53548de96c292de22359297b
784Empire_Invoke_MetasploitPayloadDetects Empire component - file Invoke-MetasploitPayload.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,METASPLOITf374984d4a9a8d9e693de479f61fe26d
785Empire_Invoke_MimikatzEmpire - a pure PowerShell post-exploitation agent - file Invoke-Mimikatz.ps1https://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTb0c42663a2a80661439d90c51a62f223
786Empire_Invoke_Mimikatz_GenDetects Empire component - file Invoke-Mimikatz.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GEN855e91608d96c7da83e97696ba2f857f
787Empire_Invoke_Portscan_GenDetects Empire component - from files Invoke-Portscan.ps1, Invoke-Portscan.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GENc379621c0d96792eb56aa47627f53b04
788Empire_Invoke_PostExfilDetects Empire component - file Invoke-PostExfil.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE8cc9c8f05018561c93ed9808d63a1102
789Empire_Invoke_PowerDumpDetects Empire component - file Invoke-PowerDump.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,HKTLbd9fa7c5e957bff85c98a5cdb7bfdef6
790Empire_Invoke_PsExecDetects Empire component - file Invoke-PsExec.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE9fc5d8f8ca4a3d93041eccb517bc3d3b
791Empire_Invoke_SMBAutoBruteDetects Empire component - file Invoke-SMBAutoBrute.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILEaff6eb5f253f644054f3122bc585ee17
792Empire_Invoke_SSHCommandDetects Empire component - file Invoke-SSHCommand.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILEd9e2e6b3d8b64db9c17d3cc60e5a0477
793Empire_Invoke_ShellcodeEmpire - a pure PowerShell post-exploitation agent - file Invoke-Shellcode.ps1https://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTa178ed59a274ef7e78c009befbd1c8ba
794Empire_Invoke_ShellcodeMSILDetects Empire component - file Invoke-ShellcodeMSIL.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE05e723bc6cae299a10241a2d62423a6b
795Empire_Invoke_SmbScannerDetects Empire component - file Invoke-SmbScanner.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,HKTL3c09e2ec7c54701e54380ceb0423278f
796Empire_KeePassConfigDetects Empire component - file KeePassConfig.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE44a7600026242ad544d18e5f49a81578
797Empire_KeePassConfig_GenDetects Empire component - from files KeePassConfig.ps1, KeePassConfig.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GENe14e3424e95f68ec98d0885315fa3800
798Empire_Out_MinidumpDetects Empire component - file Out-Minidump.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE0d96fa4ec66cf2f06dc81ce481a04d42
799Empire_PersistenceEmpire - a pure PowerShell post-exploitation agent - file Persistence.psm1https://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTacca598ff463e33990aa88ea85273d16
800Empire_PowerShell_Framework_Gen1Detects Empire componenthttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,SCRIPTce57580e6bba3b35bed995db63469f29
801Empire_PowerShell_Framework_Gen2Detects Empire componenthttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,SCRIPTafa4d5f7c2d033218bcffeb89d1193c8
802Empire_PowerShell_Framework_Gen3Detects Empire componenthttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,SCRIPT570768ef633b1b31a213b3310aba4263
803Empire_PowerShell_Framework_Gen4Detects Empire componenthttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,SCRIPT553b1863ae5837fc321b7dd940ce1ba9
804Empire_PowerShell_Framework_Gen5Detects Empire componenthttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,SCRIPT151d6468b086f58766c1c23cbd393f53
805Empire_PowerUp_GenDetects Empire component - from files PowerUp.ps1, PowerUp.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE,GENaad5425b0b6ae494d8b5ee30eb1cfada
806Empire_ReflectivePick_x64_origDetects Empire component - file ReflectivePick_x64_orig.dllhttps://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothEXE,FILEfff228861d89a014b39875e95262224f
807Empire_Write_HijackDllEmpire - a pure PowerShell post-exploitation agent - file Write-HijackDll.ps1https://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPT46af379772268b1fb3f062c07bb47773
808Empire__Users_neo_code_Workspace_Empire_4sigs_PowerUpDetects Empire component - file PowerUp.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE0a149cc203710721cb9b7fe06ebfa24d
809Empire_dumpCredStoreDetects Empire component - file dumpCredStore.ps1https://github.com/adaptivethreat/Empire2016-11-05 00:00:0075Florian RothFILE66e299e00a39a39816860d5e2432e466
810Empire_invoke_wmiEmpire - a pure PowerShell post-exploitation agent - file invoke_wmi.pyhttps://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTfae411c5405ca0609834ac83cc74f497
811Empire_lib_modules_credentials_mimikatz_pthEmpire - a pure PowerShell post-exploitation agent - file pth.pyhttps://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTc5e17daffaf8721d2fd0460251b0eede
812Empire_lib_modules_trollsploit_messageEmpire - a pure PowerShell post-exploitation agent - file message.pyhttps://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPTc67c8a7679e2a9f0eebc00d6c9655201
813Empire_portscanEmpire - a pure PowerShell post-exploitation agent - file portscan.pyhttps://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPT18a34460b5845afbdce198aed2fc0c73
814Empire_skeleton_keyEmpire - a pure PowerShell post-exploitation agent - file skeleton_key.pyhttps://github.com/PowerShellEmpire/Empire2015-08-06 00:00:0070Florian RothSCRIPT36fc680ade21f8fa5f57e972b31f9900
815Enfal_MalwareDetects a certain type of Enfal Malwarenot set2015-02-10 00:00:0060Florian RothMALe8d78d2acb0206721d19546f7a5538af
816Enfal_Malware_BackdoorGeneric Rule to detect the Enfal Malware-2015-02-10 00:00:0060Florian RothEXE,FILE,GEN,MAL44ad0725968b589df4d9b83461acc663
817EnigmaPacker_RareDetects an ENIGMA packed executableInternal Research2017-04-27 00:00:0060Florian RothEXE,FILE2e94cf82a091fc5a1509200400740835
818Enigma_Protected_MalwareDetects samples packed by Enigma Protectorhttps://goo.gl/OEVQ9w2017-02-03 00:00:0075Florian Roth with the help of binar.lyEXE,FILE,MALe02b5b66e3b73fc6764e4db2fa3251b6
819Enigma_Protected_Malware_May17_RhxFilesAuto-generated rule - file RhxFiles.dllInternal Research2017-05-02 00:00:0075Florian Roth with the help of binar.lyEXE,FILE,MAL5b1a3673d318228ad17073ff9624185f
820EquationDrug_CompatLayer_UnilayDLLEquationDrug - Unilay.DLLhttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pEXE,FILE57ba4d66c6ed22844eb72728f09a2597
821EquationDrug_FileSystem_FilterEquationDrug - Filesystem filter driver - volrec.sys, scsi2mgr.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4p2327fdf9194211c00430eefbe163583b
822EquationDrug_HDDSSD_OpEquationDrug - HDD/SSD firmware operation - nls_933w.dllhttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4p2f6e053968f1d642ec8bdcf441291447
823EquationDrug_KernelRootkitEquationDrug - Kernel mode stage 0 and rootkit (Windows 2000 and above) - msndsrv.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4peda83e9d7d20428eb0a51853d49147ae
824EquationDrug_KeyloggerEquationDrug - Key/clipboard logger driver - msrtvd.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pHKTLb0c56a123c4650117bcc4b65ae889a3c
825EquationDrug_MS_IdentifierMicrosoft Identifier used in EquationDrug Platform-2015-03-11 00:00:0075Florian Roth @4nc4p0bc45170c2d4b50719cf029e07be5e8b
826EquationDrug_NetworkSniffer1EquationDrug - Backdoor driven by network sniffer - mstcp32.sys, fat32.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pMAL09dcb2349f45ec5e1aa3cadb2845e0d3
827EquationDrug_NetworkSniffer2EquationDrug - Network Sniffer - tdip.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4p3f47605d50cca76d93730327968796e9
828EquationDrug_NetworkSniffer3EquationDrug - Network Sniffer - tdip.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4p5ff2e2254e4155db6fcdd02677908ac7
829EquationDrug_NetworkSniffer4EquationDrug - Network-sniffer/patcher - atmdkdrv.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pfb864fba90d20a6c97e5205c0146057f
830EquationDrug_NetworkSniffer5EquationDrug - Network-sniffer/patcher - atmdkdrv.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pf3d11e1af4163400843245049cb821df
831EquationDrug_PlatformOrchestratorEquationDrug - Platform orchestrator - mscfg32.dll, svchost32.dllhttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pc9e3fcd3b3b24b26ba202b14f87255de
832EquationDrug_VolRec_DriverEquationDrug - Collector plugin for Volrec - msrstd.syshttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/2015-03-11 00:00:0075Florian Roth @4nc4pa52c43e7944ba250156d1a528de74076
833EquationGroup_AuditcleanerEquation Group hack tool leaked by ShadowBrokers- file Auditcleanerhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL770b54e61e62a638235f93634e396002
834EquationGroup_DULEquation Group hack tool leaked by ShadowBrokers- file DULhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLc5ffc50667fb8570b15595ad65592cd7
835EquationGroup_DXGHLP16EquationGroup Malware - file DXGHLP16.SYShttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL2f8e939ac5fb828509fc037131db5310
836EquationGroup_EquationDrug_Gen_1EquationGroup Malwarehttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,GEN,MALc99fff6bebdf39c960e3850170f62a57
837EquationGroup_EquationDrug_Gen_2EquationGroup Malware - file PortMap_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Auto GeneratedEXE,FILE,GEN,MAL7d82cdec429d163b812c955033e0c6b9
838EquationGroup_EquationDrug_Gen_3EquationGroup Malware - file mssld.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Auto GeneratedEXE,FILE,GEN,MAL60aed6f3ce8b1cc411db52b091c07057
839EquationGroup_EquationDrug_Gen_4EquationGroup Malware - file PC_Level4_flav_dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Auto GeneratedEXE,FILE,GEN,MALc26d566d8386245260cee2c2f1d7ffc2
840EquationGroup_EquationDrug_Gen_5EquationGroup Malware - file PC_Level3_http_dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,GEN,MAL791a85ac7fbdd11ef97f59c6945f2c9f
841EquationGroup_EquationDrug_Gen_6EquationGroup Malware - file PC_Level3_dll_x64https://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,GEN,MAL0946a5f7c97639c69f9a0973e6c506a3
842EquationGroup_EquationDrug_msgkdEquationGroup Malware - file msgkd.ex_https://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL046e15346ad7a723a7e4d679a2d8772a
843EquationGroup_EquationDrug_mstcp32EquationGroup Malware - file mstcp32.syshttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL711ad989f61f61e6f8751c657833d285
844EquationGroup_EquationDrug_ntevtEquationGroup Malware - file ntevt.syshttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALc483c99bb2995e71c8dd0f5c6e86678e
845EquationGroup_EquationDrug_tdi6EquationGroup Malware - file tdi6.syshttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL68be2c7ef9b027d0a96d405f14054ee1
846EquationGroup_EventLogEdit_ImplantEquationGroup Malware - file EventLogEdit_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL2c2be8d2c37df69084c38b7a4234e9c2
847EquationGroup_GetAdmin_LpEquationGroup Malware - file GetAdmin_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL1e97b4e713cbfb29ec26d361b16108d3
848EquationGroup_LSADUMP_LpEquationGroup Malware - file LSADUMP_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,HKTL,MAL731309734d583d0b837598bf2d05851b
849EquationGroup_ModifyGroup_LpEquationGroup Malware - file ModifyGroup_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL1337de2e9b413582841b5340efa67e93
850EquationGroup_PC_Level3_http_flav_dllEquationGroup Malware - file PC_Level3_http_flav_dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL9187c03351bb7c6040273a8d4d7bf05f
851EquationGroup_PC_Level3_http_flav_dll_x64EquationGroup Malware - file PC_Level3_http_flav_dll_x64https://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALc04c069fa6c5a082690130775d2d8069
852EquationGroup_PC_Level4_flav_dll_x64EquationGroup Malware - file PC_Level4_flav_dll_x64https://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL1114404f89cce39b3a23177e8d9643c2
853EquationGroup_PC_Level4_flav_exeEquationGroup Malware - file PC_Level4_flav_exehttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALddc8abb3594dfb720f95e7170000e9f3
854EquationGroup_PassFreely_LpEquationGroup Malware - file PassFreely_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL9cbf27185f325ae41f5d60bb37bdbbfc
855EquationGroup_PortMap_LpEquationGroup Malware - file PortMap_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALc8c90b7ac023165d4d7b6ab441ad250b
856EquationGroup_ProcessHide_LpEquationGroup Malware - file ProcessHide_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALe4eeea73bc431a2aa77fb8a339b29ab8
857EquationGroup_ProcessOptions_LpEquationGroup Malware - file ProcessOptions_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL95c49a9808264ae52b5ebaeb7bde14b3
858EquationGroup_RunAsChild_LpEquationGroup Malware - file RunAsChild_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL90ca59ed086ff6312b046ee9c657e20f
859EquationGroup_Toolset_Apr17_ActiveDirectory_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb7356077f4eeddc1c3844d7683bdf469
860EquationGroup_Toolset_Apr17_AdUser_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7aae3acc15a6c23491c3e63158b37eef
861EquationGroup_Toolset_Apr17_Architouch_1_0_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE0d66c58cd7297d9f012fc3081355243e
862EquationGroup_Toolset_Apr17_Architouch_Eternalsynergy_SmbtouchDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE8d5c2c5362470228952334a3f48f65ad
863EquationGroup_Toolset_Apr17_Banner_Implant9xDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE1de788df6dafb8e4e8cf12ee45c50ae2
864EquationGroup_Toolset_Apr17_DS_ParseLogsDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE6fd565c99c208b5c8c8c9d277784a6ac
865EquationGroup_Toolset_Apr17_Darkpulsar_1_1_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE4e70b464154eb8aa0582f601120773ff
866EquationGroup_Toolset_Apr17_DiBa_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE388811d116e3bc51358ec962ccc06fbd
867EquationGroup_Toolset_Apr17_DiBa_Target_2000Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa13982f21bc5caaaca6a4f2780399a25
868EquationGroup_Toolset_Apr17_DiBa_Target_BHDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE764638e8cb406f38d281b699c08637f5
869EquationGroup_Toolset_Apr17_DiBa_Target_BH_2000Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE0f945d32c236e1a9e5683c07f7c0c1b5
870EquationGroup_Toolset_Apr17_DllLoad_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEfed04826969ed552ce691bc9965f3ef6
871EquationGroup_Toolset_Apr17_DmGz_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEd5af3c268b01a9ef1d477ebf717e9314
872EquationGroup_Toolset_Apr17_DmGz_Target_2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7c47a5e261a640d8aa9a4eb574342716
873EquationGroup_Toolset_Apr17_DoubleFeatureDll_dll_2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEf472de25fbfbbf9a85d0801ff6568355
874EquationGroup_Toolset_Apr17_DoubleFeatureDll_dll_3Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE60aed6f3ce8b1cc411db52b091c07057
875EquationGroup_Toolset_Apr17_Doublepulsar_1_3_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEbaa3e5ec39839d0a86f6ac420f586c02
876EquationGroup_Toolset_Apr17_Dsz_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE33fe8c54b266ef283a636c231048ae65
877EquationGroup_Toolset_Apr17_EXPADetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE0956888b708845615394ca4ae2ebe386
878EquationGroup_Toolset_Apr17_Easybee_1_0_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE05bd44b7d8917b450651b5e3e557712e
879EquationGroup_Toolset_Apr17_Easypi_ExplodingcanDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE9c3b95dfb6c87110a7f2bf2d4cdb6b74
880EquationGroup_Toolset_Apr17_Eclipsedwing_Rpcproxy_PcdlllauncherDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE989424ce05f45b34d068c771a0f96343
881EquationGroup_Toolset_Apr17_Eclipsedwingtouch_1_0_4Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEe68d37e990243af13593cf57e700c914
882EquationGroup_Toolset_Apr17_Educatedscholar_1_0_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE37642ca2f3a08356a290c25963e7ca16
883EquationGroup_Toolset_Apr17_Educatedscholartouch_1_0_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa2b1afc92775f381dd8876cb1e6bc98c
884EquationGroup_Toolset_Apr17_Englishmansdentist_1_2_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE706d7309640198c1a123fd2cbaa9013b
885EquationGroup_Toolset_Apr17_EpWrapperDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEbb7e38b9f22b8de85ddb98b2ab043755
886EquationGroup_Toolset_Apr17_Erraticgopher_1_0_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEdc21bc344241e61b993940a99572f060
887EquationGroup_Toolset_Apr17_Erraticgophertouch_1_0_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE28a533e088ad9660e9ad27c405f3377a
888EquationGroup_Toolset_Apr17_Esteemaudit_2_1_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE6c3379a686592c46d9ef8d135d9382ce
889EquationGroup_Toolset_Apr17_Esteemaudittouch_2_1_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE27abad7eb8ac03eb4e7cde100fbba10b
890EquationGroup_Toolset_Apr17_EternalromanceDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE857cc98a711449837051ff218e9d25e4
891EquationGroup_Toolset_Apr17_Eternalromance_2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE0ec496b73b856ffdf3a4bfb720e5f306
892EquationGroup_Toolset_Apr17_Explodingcantouch_1_2_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb1a3c4c0992cdd90212a6cfcdf3c00d9
893EquationGroup_Toolset_Apr17_GangsterThief_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE9b4b7de2904a4d6b60b79324aa2ca5c7
894EquationGroup_Toolset_Apr17_Gen1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE9aa747526894fd276fa6f2247eaa34e5
895EquationGroup_Toolset_Apr17_Gen2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEdf4f2e422261cb8e4a3a9b6e9bb4da13
896EquationGroup_Toolset_Apr17_Gen3Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE2b7322579100e04f0e0c39d74c43b42a
897EquationGroup_Toolset_Apr17_Gen4Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb33c0b85651708e85d11c38c56f69966
898EquationGroup_Toolset_Apr17_GenKeyDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE6ec81a655a6e62bd302756f166ffbdad
899EquationGroup_Toolset_Apr17_GetAdmin_LSADUMP_ModifyPrivilege_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE9bd47bd45ed7033c0a9aebf804b409a0
900EquationGroup_Toolset_Apr17_GrDo_FileScanner_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb77ca3111c19898e498e8381f7e6b983
901EquationGroup_Toolset_Apr17_Ifconfig_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7e945b244da98a32790028bdad19134a
902EquationGroup_Toolset_Apr17_Iistouch_1_2_2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE6e3ae16ccf3d5e64d0e2c6afb2e99e17
903EquationGroup_Toolset_Apr17_KisuComms_Target_2000Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb015209967f7d7ae3077ca810d5dc016
904EquationGroup_Toolset_Apr17_Mcl_NtMemory_StdDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE9b64f40a57355e2545a7520a1c15e7ef
905EquationGroup_Toolset_Apr17_Mofconfig_1_0_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE28f3226fa0204beeeb5b335f4ab8998c
906EquationGroup_Toolset_Apr17_Namedpipetouch_2_0_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE010975a4b2d365a5c894764457bc4249
907EquationGroup_Toolset_Apr17_Oracle_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE80b9953a2587b208a68e230ccece1381
908EquationGroup_Toolset_Apr17_PC_ExploitDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE3a702857e3d6479039d8792f2bdb27f4
909EquationGroup_Toolset_Apr17_PC_LPDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEeed646975c6cf416cdcf8aae889514d3
910EquationGroup_Toolset_Apr17_PC_Legacy_dllDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE5d8e944d2992831ebc44ae2a4dc7b67e
911EquationGroup_Toolset_Apr17_PC_Level3_GenDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE,GEN2612e5cdac71ef211e2e06eb3945ca50
912EquationGroup_Toolset_Apr17_PC_Level3_http_exeDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE84847a051c02ae52697ea0625157af2a
913EquationGroup_Toolset_Apr17_PC_Level_GenericDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE,GEN89d8ff71af2b2d375f68dbcbaa378fef
914EquationGroup_Toolset_Apr17_PacketScan_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE3258463f0e6f998f42b0dabe1ea64d41
915EquationGroup_Toolset_Apr17_ParseCaptureDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEd16137f74862ae0220ad505ebc51e1be
916EquationGroup_Toolset_Apr17_Processes_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEcba8dba96720baeda15c13f9f376f822
917EquationGroup_Toolset_Apr17_Regread_1_1_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE01ed91dcb5fabca7f3dff5ab656426b3
918EquationGroup_Toolset_Apr17_RemoteCommand_LpDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE971974f470269497d978fa01d8411c14
919EquationGroup_Toolset_Apr17_RemoteExecute_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE27425e42b9ac9cd66b1ee6a3853a64f9
920EquationGroup_Toolset_Apr17_RemoteExecute_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEccfa14b55a7791e19a2df499e0a6e78f
921EquationGroup_Toolset_Apr17_Rpctouch_2_1_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE22603ee6c4b4beb068f00ee0c6dc178c
922EquationGroup_Toolset_Apr17_SendPKTriggerDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE68fdaccc15bcec1f88d619d44a2a623b
923EquationGroup_Toolset_Apr17_SetCallbackDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE5cc99f9bdfbd95d664aba8793575aa3a
924EquationGroup_Toolset_Apr17_SetCallbackPortsDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE575c52463c41796f536bc56801024429
925EquationGroup_Toolset_Apr17_SetOurAddrDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE1ec865afd0e5a21004a41a29484ca53a
926EquationGroup_Toolset_Apr17_SetPortsDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7c38753c72ef92406543ca60a84dfa25
927EquationGroup_Toolset_Apr17_SetResourceNameDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE379639e6ade003f097d2fcc9e93fde8a
928EquationGroup_Toolset_Apr17_Shares_TargetDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb04386af8b299ff04cf7e10c7b6f626d
929EquationGroup_Toolset_Apr17_SlDecoderDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE8c92eda0dc3a7a4f6cc274cd2af70d08
930EquationGroup_Toolset_Apr17_Smbtouch_1_1_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE13c7e9415593c1d35cf980afae13a314
931EquationGroup_Toolset_Apr17_Windows_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE1178f632d2c6d8f82dbadcd590dd6ce7
932EquationGroup_Toolset_Apr17__AddResourceDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEabfbf765bb3dac99f5bb81d0baf57491
933EquationGroup_Toolset_Apr17__DoubleFeatureReader_DoubleFeatureReader_0Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEba22f86f5178e2050519325aaa551931
934EquationGroup_Toolset_Apr17__EAFU_ecwi_ESKE_EVFR_RPC2_4Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE0bbd0cbe1e7c57baf3a2d57da1aea25d
935EquationGroup_Toolset_Apr17__ELV_ESKE_13Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE4d397415f6327dd1b84896994fc65127
936EquationGroup_Toolset_Apr17__ELV_ESKE_ETBL_ETRE_EVFR_11Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEc63aae2e1dc378552613280c5b2f6e16
937EquationGroup_Toolset_Apr17__ELV_ESKE_EVFR_16Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEd12b8b4afa30981ed48601ffe5806d39
938EquationGroup_Toolset_Apr17__ELV_ESKE_EVFR_RPC2_15Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE586a226b96bf1cfdd61aee4d27bfaf4a
939EquationGroup_Toolset_Apr17__ELV_ESKE_EVFR_RideArea2_12Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb896d925bd79e724281bac78b4f8620e
940EquationGroup_Toolset_Apr17__ESKE_RPC2_8Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7f48440dd35d534f09eef2676d7aadc2
941EquationGroup_Toolset_Apr17__ETBL_ETRE_10Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEed72136f0914236cee8619a902bd24ae
942EquationGroup_Toolset_Apr17__ETBL_ETRE_SMBTOUCH_17Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE792d2698751621181755648da1501c48
943EquationGroup_Toolset_Apr17__EmphasismineDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE515fb76bb78d2f7fdd538d206f811cf0
944EquationGroup_Toolset_Apr17__LSADUMP_Lp_ModifyPrivilege_Lp_PacketScan_Lp_put_Lp_RemoteExecute_Lp_Windows_Lp_wmi_Lp_9Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE199bfc46ffcde4d131c89c4eaf7aad43
945EquationGroup_Toolset_Apr17__NameProbe_SMBTOUCH_14Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE444337a634db7cbdb2c185b71f789daa
946EquationGroup_Toolset_Apr17__SendCFTrigger_SendPKTrigger_6Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE05c62adbbcf90da8e53317889129d85f
947EquationGroup_Toolset_Apr17__ecwi_ESKE_EVFR_RPC2_2Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE15087343cbc48daf3a85154a22f05f05
948EquationGroup_Toolset_Apr17__vtuner_vtuner_1Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb0dae39138eca8d21cfa93cf9ca86143
949EquationGroup_Toolset_Apr17_clocksvcDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEfc0a309581335db0d4793bef652a4ad3
950EquationGroup_Toolset_Apr17_drivers_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEefa68f1e327141c8d9bb6c51fec034d9
951EquationGroup_Toolset_Apr17_greatdoc_dll_configDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE464158b540f16b8b1b7689e619323d2f
952EquationGroup_Toolset_Apr17_lp_mstcpDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa6455048c9a5419b15e3d76596456bfb
953EquationGroup_Toolset_Apr17_msgkd_msslu64_msgki_mssldDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE4dd2318780233dcbbc581c7c22f61cce
954EquationGroup_Toolset_Apr17_msgks_mskguDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE7bc5b0809dcce5a3f137ee77fae3a444
955EquationGroup_Toolset_Apr17_mstcp32_DXGHLP16_tdipDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEfbdb5b7e19e22b2d37125dbe73126301
956EquationGroup_Toolset_Apr17_ntevtDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa6a0d65030e5649d839fd735fb2f1073
957EquationGroup_Toolset_Apr17_ntfltmgrDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE660989497995efb8c531e686713e0b7c
958EquationGroup_Toolset_Apr17_promiscdetect_safeDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE47d6fa8a3b0cb849f41d37931edc1249
959EquationGroup_Toolset_Apr17_put_Implant9xDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEca9cae6d1e1f329bbcedd38eb64fd763
960EquationGroup_Toolset_Apr17_pwd_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE221b93c5d228c3a7592c398120b805c1
961EquationGroup_Toolset_Apr17_rc5Detects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE41d121343b7d73773dea874878e3c34c
962EquationGroup_Toolset_Apr17_regprobeDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE2c8aa954e58c7099e90430698d21d430
963EquationGroup_Toolset_Apr17_renamerDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE106a6ee3d141eed69ebad41faac22b2c
964EquationGroup_Toolset_Apr17_scannerDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEb4729cd00720fd4f6d0ce01484012b04
965EquationGroup_Toolset_Apr17_st_lpDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE4fb31bbcd5d00936c88852c0272ca08f
966EquationGroup_Toolset_Apr17_svctouchDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE567618e015415d759aae51d26b450875
967EquationGroup_Toolset_Apr17_tacothiefDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa830db478b5e1904ef1906d3b9ace7fb
968EquationGroup_Toolset_Apr17_wmi_ImplantDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEa400e12ff31c97f6be02a289e79a3735
969EquationGroup_Toolset_Apr17_xxxRIDEAREADetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE6472cc3a38af094eeaf66811e6757cb3
970EquationGroup_Toolset_Apr17_yakDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILEe3cd27eacf597e496ba46ff0123db4ba
971EquationGroup_Toolset_Apr17_yak_min_installDetects EquationGroup Tool - April Leakhttps://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation2017-04-15 00:00:0075Florian RothEXE,FILE2f6453ea63d03b4b0a63708b17fad7ed
972EquationGroup__ftshellEquation Group hack tool leaked by ShadowBrokers- from files ftshell, ftshell.v3.10.3.7https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLf88e054eb2f98b07227534fda5d33a3b
973EquationGroup__ftshell_ftshell_v3_10_3_0Equation Group hack tool leaked by ShadowBrokers- from files ftshell, ftshell.v3.10.3.7https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLe27684c1b964de88273525328e05eede
974EquationGroup__funnelout_v4_1_0_1Equation Group hack tool leaked by ShadowBrokers- from files funnelout.v4.1.0.1.plhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLd8f05177e79ccbb0b24b76da425429bf
975EquationGroup__ghost_sparc_ghost_x86_3Equation Group hack tool leaked by ShadowBrokers- from files ghost_sparc, ghost_x86https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL185ff0e54027b5a22293763ccc427a9c
976EquationGroup__jparsescan_parsescan_5Equation Group hack tool leaked by ShadowBrokers- from files jparsescan, parsescanhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL50a686d09c2e759360c6cd02321d7e9f
977EquationGroup__magicjack_v1_1_0_0_clientEquation Group hack tool leaked by ShadowBrokers- from files magicjack_v1.1.0.0_client-1.1.0.0.pyhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL73341b040a293c76e7ad301d3b34371c
978EquationGroup__pclean_v2_1_1_pclean_v2_1_1_4Equation Group hack tool leaked by ShadowBrokers- from files pclean.v2.1.1.0-linux-i386, pclean.v2.1.1.0-linux-x86_64https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLaed6ef9aa0b36f9c67ca60fb0013c438
979EquationGroup__scanner_scanner_v2_1_2Equation Group hack tool leaked by ShadowBrokers- from files scanner, scanner.v2.1.2https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL7b6e303c108264a88cfd1a660fa01de9
980EquationGroup_calserverEquation Group hack tool leaked by ShadowBrokers- file calserverhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL662083f8caf6dc4e63a260d8b5c0aa7e
981EquationGroup_charm_saver_win2k_v_2_0_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE337cf049bfed0384e624dffbcdc81eaf
982EquationGroup_cmsdEquation Group hack tool leaked by ShadowBrokers- file cmsdhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL82aff8b3fb6fa34eaaaac7f147cc9e73
983EquationGroup_cmsexEquation Group hack tool leaked by ShadowBrokers- file cmsexhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL84c5b6d19ae2b7a7816cd839b7cc182b
984EquationGroup_cryptToolEquation Group hack tool leaked by ShadowBrokers- file cryptToolhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL21d4db180fdedfbb898763f10a9385d3
985EquationGroup_curseflower_mswin32_v_1_0_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILEf6115a74ada4c081b30d897cba74fee0
986EquationGroup_cursehappy_win2k_v_6_1_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE2340eca6c15849bc662a84918b2019fa
987EquationGroup_cursehelper_win2k_i686_v_2_2_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILEff4c0083ead631aedde343b1bfc37034
988EquationGroup_curseroot_win2k_v_2_1_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE02abf0e8135cb95419905d16e5679979
989EquationGroup_cursesleepy_mswin32_v_1_0_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE8c5ba6f57696417ee0d74db26ef7ff39
990EquationGroup_cursetingle_2_0_1_2_mswin32_v_2_0_1Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILEaaf262f720218a8cb5363f36344728cb
991EquationGroup_cursewham_curserazor_cursezinger_curseroot_win2kEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE115ad255134fcdaf2710431c348d9560
992EquationGroup_curseyo_win2k_v_1_0_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothEXE,FILE40a532a12356e2b7f6bfe0b64d516b57
993EquationGroup_cursezinger_linuxrh7_3_v_2_0_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEc56b59b03c5c664e6dbbd3d1c214afe0
994EquationGroup_dumppoppyEquation Group hack tool leaked by ShadowBrokers- file dumppoppyhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL52adab9be80a11a52403f199adc81616
995EquationGroup_ebbislandEquation Group hack tool leaked by ShadowBrokers- file ebbislandhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL5751dfff8e03cb21ac4ffc4743c244ed
996EquationGroup_ebbshaveEquation Group hack tool leaked by ShadowBrokers- file ebbshave.v5https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL8c9e67e3bdb36bfaa21ed0441bbfdd49
997EquationGroup_eggbasketEquation Group hack tool leaked by ShadowBrokers- file eggbaskethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLa1543c0579cb2aff126c59301669dfe8
998EquationGroup_eh_1_1_0Equation Group hack tool leaked by ShadowBrokers- file eh.1.1.0.0https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL72a1cdb31bf653d236c3174253ae81f4
999EquationGroup_elatedmonkey_1_0_1_1Equation Group hack tool leaked by ShadowBrokers- file elatedmonkey.1.0.1.1.shhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL2d0226c0d1bbeca40f7541acc78de960
1000EquationGroup_electricslideEquation Group hack tool leaked by ShadowBrokers- file electricslidehttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLbb7f7662d4e40c35f49cfd26bfaf8bcb
1001EquationGroup_elgingambleEquation Group hack tool leaked by ShadowBrokers- file elgingamblehttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTLef5b6d9324e86e442e489e9d85e3a308
1002EquationGroup_emptycrissEquation Group hack tool leaked by ShadowBrokers- file emptycrisshttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL432be1a50b4db57f3f58c49df26b1d54
1003EquationGroup_envisioncollisionEquation Group hack tool leaked by ShadowBrokers- file envisioncollisionhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL8ef60df99720313bcee319e943059d66
1004EquationGroup_envoytomatoEquation Group hack tool leaked by ShadowBrokers- file envoytomatohttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL9ce659d819e264cf98bec9d5d13358a7
1005EquationGroup_epoxyresin_v1_0_0Equation Group hack tool leaked by ShadowBrokers- file epoxyresin.v1.0.0.1https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL8900a6adb1521fe33f1589f5eb10b15a
1006EquationGroup_estesfoxEquation Group hack tool leaked by ShadowBrokers- file estesfoxhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL49d1c5133034ee666c67d0a86ffeef84
1007EquationGroup_estopmoonlitEquation Group hack tool leaked by ShadowBrokers- file estopmoonlithttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTLe19ea12e699972247b8540855783a271
1008EquationGroup_evolvingstrategy_1_0_1Equation Group hack tool leaked by ShadowBrokers- file evolvingstrategy.1.0.1.1https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL6898e2c79fbdd39846d9c31437c59c89
1009EquationGroup_ewokEquation Group hack tool leaked by ShadowBrokers- file ewokhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL699aaae8212224474d565d94c85668e8
1010EquationGroup_exzeEquation Group hack tool leaked by ShadowBrokers- file exzehttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL250d04616bdf51ef957517803aacedc5
1011EquationGroup_grEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Roth26ccd5b38b31f1edd893fa066255bf17
1012EquationGroup_gr_dev_bin_nowEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Roth74cec48099854ebea1f8cf4c938ebb0b
1013EquationGroup_gr_dev_bin_postEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Rothf92fa0540f27bfd1295bc740883e8240
1014EquationGroup_jackpopEquation Group hack tool leaked by ShadowBrokers- file jackpophttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL16f9fc72ef538421918346856fe51017
1015EquationGroup_jparsescanEquation Group hack tool leaked by ShadowBrokers- file jparsescanhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL12e46c85667ffe8ca31955f84fa09ea6
1016EquationGroup_jscanEquation Group hack tool leaked by ShadowBrokers- file jscanhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL723d7a648ad32f79c61e36cbaeb4e370
1017EquationGroup_libXmexploit2Equation Group hack tool leaked by ShadowBrokers- file libXmexploit2.8https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLcd6cf0f1d7fdbd6147ccc984d645df3b
1018EquationGroup_linux_exactchangeEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEdd1a684c26edaa331ac29731ff5aaaf9
1019EquationGroup_magicjack_v1_1_0_0_client_1_1_0_0Equation Group hack tool leaked by ShadowBrokers- file magicjack_v1.1.0.0_client-1.1.0.0.pyhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLc649212bf95d99daee81c68618f50fb9
1020EquationGroup_modifyAudit_ImplantEquationGroup Malware - file modifyAudit_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL4711346bf0a7a3901db5e88c6afe8a7e
1021EquationGroup_modifyAudit_LpEquationGroup Malware - file modifyAudit_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL7ce3a67ebf3c885e3f168ad6c257db86
1022EquationGroup_modifyAuthentication_ImplantEquationGroup Malware - file modifyAuthentication_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALe7ca66adb01f6427291200a74e10160a
1023EquationGroup_morerats_client_StoreEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEcf0715bfc58c5e91b662fe37ba1ff895
1024EquationGroup_morerats_client_addkeyEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Roth84c7fd5a7b6c532f41241b344cbc3360
1025EquationGroup_morerats_client_genkeyEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Rothf42866361bc2d986afe6f246eee3042b
1026EquationGroup_morerats_client_noprepEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Roth95d1c61589cd0923e0daadf9541423bc
1027EquationGroup_nethide_ImplantEquationGroup Malware - file nethide_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALfd10578a09eaf704b1c8c0fa85176a18
1028EquationGroup_nethide_LpEquationGroup Malware - file nethide_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALfc2123bcb001f25954b833a873e53ca6
1029EquationGroup_noclient_3_3_2Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Rothc3d6229208c857cc91c8b8491cd62f87
1030EquationGroup_ntfltmgrEquationGroup Malware - file ntfltmgr.syshttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL4d9fcc64eb8bce01014fac4a3d41a40e
1031EquationGroup_orleans_stride_sunos5_9_v_2_4_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILE8d63f5732f2c17d353cd95bacfc48abc
1032EquationGroup_packratEquation Group hack tool leaked by ShadowBrokers- file packrathttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL1e0e42f02c15446dfda600b4a8d900dc
1033EquationGroup_parsescanEquation Group hack tool leaked by ShadowBrokers- file parsescanhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL2e8468475fd9c6d83bfeb364fa213d8c
1034EquationGroup_pclean_v2_1_1_2Equation Group hack tool leaked by ShadowBrokers- file pclean.v2.1.1.0-linux-i386https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLcb6063e7d8b7e089dc7473ae79fe2b06
1035EquationGroup_porkclientEquation Group hack tool leaked by ShadowBrokers- file porkclienthttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLd9a662b2f250d07c1acf6b2c8fae83ae
1036EquationGroup_processinfo_ImplantEquationGroup Malware - file processinfo_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL8623d4c50ddab329bd52f60061c657f2
1037EquationGroup_promptkillEquation Group hack tool leaked by ShadowBrokers- file promptkillhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTLfb149c88adee0602f9226998ff4cd038
1038EquationGroup_pwdump_ImplantEquationGroup Malware - file pwdump_Implant.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MALf6cee9fed16d5765f68c5a14593d54a0
1039EquationGroup_pwdump_LpEquationGroup Malware - file pwdump_Lp.dllhttps://goo.gl/tcSoiJ2017-01-13 00:00:0075Florian RothEXE,FILE,MAL4d69ca11f0e60bf0b1f454979f965219
1040EquationGroup_ratloadEquation Group hack tool leaked by ShadowBrokers- file ratloadhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL0b25d89f893c48b8144b4ed7b9d55018
1041EquationGroup_reverse_shellEquation Group hack tool leaked by ShadowBrokers- file reverse.shell.scripthttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL3a571c17b75c12ce6f1d0094f049ddbb
1042EquationGroup_sambalEquation Group hack tool leaked by ShadowBrokers- file sambalhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL072f7c5cad731648712fe64218dbf452
1043EquationGroup_scannerEquation Group hack tool leaked by ShadowBrokers- file scannerhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTLb477266f13c036c85702cd3cfb17db5f
1044EquationGroup_scanner_outputDetects output generated by EQGRP scanner.exeInternal Research2017-04-17 00:00:0075Florian Roth8a160c2a16137109e3b43b75db5a20de
1045EquationGroup_scripmeEquation Group hack tool leaked by ShadowBrokers- file scripmehttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL72b6c03c1a4d989e877824ba01d857d1
1046EquationGroup_seconddate_ImplantStandalone_3_0_3Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILE04da62c78e20c155b8d1d88121d6e47c
1047EquationGroup_slugger2Equation Group hack tool leaked by ShadowBrokers- file slugger2https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL37474786e9ecf74ad2c69179f313789a
1048EquationGroup_smashEquation Group hack tool leaked by ShadowBrokers- file smashhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL0f92f7586addcead7afdf9a3311aba59
1049EquationGroup_sshoboEquation Group hack tool leaked by ShadowBrokers- file sshobohttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTLc218f5f5a44066ee45d91e9e793c6a64
1050EquationGroup_store_linux_i386_v_3_3_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEc153ec3d1a475d0f6b6976a3ee73784e
1051EquationGroup_telexEquation Group hack tool leaked by ShadowBrokers- file telexhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL7fed1862c0540c8f9e862a9953b1bc81
1052EquationGroup_tmpwatchEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian Roth3d6a97619461d7b9be09c02e73a8b28f
1053EquationGroup_tnmungerEquation Group hack tool leaked by ShadowBrokers- file tnmungerhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL1a68a3abc1ad77b27d0db60d1072d332
1054EquationGroup_toast_v3_2_0Equation Group hack tool leaked by ShadowBrokers- file toast_v3.2.0.1-linuxhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL0a29d836c2ebeab07b324845b93c522b
1055EquationGroup_watcher_linux_i386_v_3_3_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEe2e9500f11244768d4579bd5848e5b36
1056EquationGroup_watcher_linux_x86_64_v_3_3_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILE1d4246458549f7684a0f93cdd1441b12
1057EquationGroup_watcher_solaris_i386_v_3_3_0Equation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILEcb8b0bd788e50f787da569d7cc47c7bf
1058EquationGroup_wrap_telnetEquation Group hack tool leaked by ShadowBrokers- file wrap-telnet.shhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL4403d1422fed835a0398fb9a0bb459fd
1059EquationGroup_x86_linux_exactchangeEquation Group hack tool sethttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-09 00:00:0075Florian RothFILE78f8e7edc2e1fd1b50ffc548921116b3
1060EquationGroup_xspyEquation Group hack tool leaked by ShadowBrokers- file xspyhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL02cf1914e6e12c5d035d5bd424acf80f
1061EquationGroup_ysEquation Group hack tool leaked by ShadowBrokers- file ys.autohttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothHKTL00539eff444ec58e3afbdcb6c50af743
1062EquationGroup_ys_ratloadEquation Group hack tool leaked by ShadowBrokers- file ys.ratload.shhttps://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b12017-04-08 00:00:0075Florian RothFILE,HKTL1870dc7e8f54d10fbbdb4fce459736b7
1063Equation_Kaspersky_DoubleFantasy_1Equation Group Malware - DoubleFantasyhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL54cdc279f8015fc2aed7df399d81085d
1064Equation_Kaspersky_EOP_PackageEquation Group Malware - EoP package and malware launcherhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL60d4abef921cb655fccf09c6f201cbcd
1065Equation_Kaspersky_EquationDrugInstallerEquation Group Malware - EquationDrug installer LUTEUSOBSTOShttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL479518d8a98bdd1d2152a94edaf25446
1066Equation_Kaspersky_EquationLaserInstallerEquation Group Malware - EquationLaser Installerhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL75afa4d795bc406a6ed0a137815b59fd
1067Equation_Kaspersky_FannyWormEquation Group Malware - Fanny Wormhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL3286dae74bc8eb305cce388dbeac18f7
1068Equation_Kaspersky_GROK_KeyloggerEquation Group Malware - GROK keyloggerhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,HKTL,MAL49f616b083443a2cf07b3134ea564e91
1069Equation_Kaspersky_GreyFishInstallerEquation Group Malware - Grey Fishhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothMAL86c4b085e4572dfba4d82c3ef5ee894b
1070Equation_Kaspersky_HDD_reprogramming_moduleEquation Group Malware - HDD reprogramming modulehttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL5cffb0d7dc56fc9880bf40cc4ce15074
1071Equation_Kaspersky_SuspiciousStringEquation Group Malware - suspicious string found in samplehttp://goo.gl/ivt8EW2015-02-17 00:00:0060Florian RothEXE,FILE,MALb1537463111916954a88570ba5a36974
1072Equation_Kaspersky_TripleFantasy_1Equation Group Malware - TripleFantasy http://goo.gl/ivt8EWhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL12419495139f2c95fecb32d3d85ce666
1073Equation_Kaspersky_TripleFantasy_LoaderEquation Group Malware - TripleFantasy Loaderhttp://goo.gl/ivt8EW2015-02-16 00:00:0075Florian RothEXE,FILE,MAL098ee0372b5ceed483ec31f48d97ae55
1074EternalRocks_svchostDetects EternalRocks Malware - file taskhost.exehttps://twitter.com/stamparm/status/8648651447482982422017-05-18 00:00:0075Florian RothEXE,FILE,MALeb541e855c60ff59d778dc864d472225
1075EternalRocks_taskhostDetects EternalRocks Malware - file taskhost.exehttps://twitter.com/stamparm/status/8648651447482982422017-05-18 00:00:0075Florian RothEXE,FILE,MAL3021c23324fe2302bdb41aa15b837b4f
1076Exe_Cloaked_as_ThumbsDbDetects an executable cloaked as thumbs.db - Malware-2014-07-18 00:00:0050Florian RothEXE,EXTVAR,FILE,MALdabe73be07c4808e40120a4b9f8da19f
1077Exp_EPS_CVE20152545Detects EPS Word Exploit CVE-2015-2545Internal Research - ME2017-07-19 00:00:0070Florian RothEXPLOIT,FILE,OFFICEd8bc44ff431898d0ec449f67cc7898d1
1078Exploit_MS15_077_078MS15-078 / MS15-077 exploit - generic signaturehttps://code.google.com/p/google-security-research/issues/detail?id=473&can=1&start=2002015-07-21 00:00:0075Florian RothEXE,FILE3bf5393f5551de8d98c60ae0dea9ea9b
1079Exploit_MS15_077_078_HackingTeamMS15-078 / MS15-077 exploit - Hacking Team code-2015-07-21 00:00:0075Florian RothEXE,FILE6a330fce9d69063a7257053ea1163d1d
1080Explosion_Generic_1Generic Rule for Explosion/Explosive Malware - Volatile Cedar APTnot set2015-04-03 00:00:0070Florian RothAPT,FILE,GEN,MAL,MIDDLE_EAST7176189d78db9acf3f2e25d4f8a78839
1081Explosion_Sample_1Explosion/Explosive Malware - Volatile Cedar APThttp://goo.gl/5vYaNb2015-04-03 00:00:0070Florian RothAPT,FILE,MAL,MIDDLE_EAST2ec656e895da7bc6fdf8dd4f138d1418
1082Explosion_Sample_2Explosion/Explosive Malware - Volatile Cedar APThttp://goo.gl/5vYaNb2015-04-03 00:00:0070Florian RothAPT,FILE,MAL,MIDDLE_EAST025241ffc1ca87df0d5a25aa730802a1
1083Explosive_EXEExplosion/Explosive Malware - Volatile Cedar APT-1970-01-01 01:00:0075Check Point Software Technologies Inc.APT,FILE,MAL,MIDDLE_EAST9295dec3b56c390863c09283cd3f92fb
1084Explosive_UAExplosive Malware Embedded User Agent - Volatile Cedar APT http://goo.gl/HQRCdwhttp://goo.gl/HQRCdw2015-04-03 00:00:0060Florian RothAPT,FILE,MAL,MIDDLE_EAST9ea48a1a18d0cc897b51a5735db2dc10
1085FE_LEGALSTRIKE_MACROThis rule is designed to identify macros with the specific encoding used in the sample 30f149479c02b741e897cdb9ecd22da7.-2017-06-02 00:00:0075Ian.Ahl@fireeye.com @TekDefense - modified by Florian Roth20f49f718a4278bd6d36a7ef6a22a3c4
1086FE_LEGALSTRIKE_RTFRtf Phishing Campaign leveraging the CVE 2017-0199 exploit, to point to the domain 2bunnyDOTcom-2017-06-02 00:00:0075joshua.kim@FireEye. - modified by Florian RothEXPLOIT,FILE1db43b0047aac1cdf88a6cc5b26b9e30
1087FIN7_Backdoor_Aug17Detects Word Dropper from Proofpoint FIN7 Reporthttps://www.proofpoint.com/us/threat-insight/post/fin7carbanak-threat-actor-unleashes-bateleur-jscript-backdoor2017-08-04 00:00:0075Florian RothEXE,FILE,MAL,OFFICE,RUSSIA4b2fa16e5bc451e352ad5fefa8110582
1088FIN7_Dropper_Aug17Detects Word Dropper from Proofpoint FIN7 Reporthttps://www.proofpoint.com/us/threat-insight/post/fin7carbanak-threat-actor-unleashes-bateleur-jscript-backdoor2017-08-04 00:00:0075Florian RothFILE,MAL,OFFICE,RUSSIA83a4f7075ee7380a1fee40157a6e8e20
1089FPipe2_0Disclosed hacktool set (old stuff) - file FPipe2.0.exe-2014-11-23 00:00:0060Florian RothHKTL2608ab40ef3be0886ed2c3832d8d1ff4
1090FSO_s_EFSO_2Webshells Auto-generated - file EFSO_2.asp-1970-01-01 01:00:0075Florian RothWEBSHELL981a677aecf00d635859c64cd4c3f43f
1091FSO_s_EFSO_2_2Webshells Auto-generated - file EFSO_2.asp-1970-01-01 01:00:0075Florian RothWEBSHELL981a677aecf00d635859c64cd4c3f43f
1092FSO_s_RemExpWebshells Auto-generated - file RemExp.asp-1970-01-01 01:00:0075Florian RothWEBSHELL3ec8eb48e6c2d769597406326c2e8ac9
1093FSO_s_RemExp_2Webshells Auto-generated - file RemExp.asp-1970-01-01 01:00:0075Florian RothWEBSHELL76dee5e4423345c7d71d0d61285077e7
1094FSO_s_ajanWebshells Auto-generated - file ajan.asp-1970-01-01 01:00:0075Florian RothWEBSHELLe7426d96d66ebf4a407fc0b1c2ab77a9
1095FSO_s_ajan_2Webshells Auto-generated - file ajan.asp-1970-01-01 01:00:0075Florian RothWEBSHELL4fa422008a2c56c6ebd3c690d98a404b
1096FSO_s_c99Webshells Auto-generated - file c99.php-1970-01-01 01:00:0075Florian RothWEBSHELL1f9c9a196afadc4df5a17b07f19e677d
1097FSO_s_casus15Webshells Auto-generated - file casus15.php-1970-01-01 01:00:0075Florian RothWEBSHELL8f55ba7abaf6b503f8fbc3a349c18231
1098FSO_s_casus15_2Webshells Auto-generated - file casus15.php-1970-01-01 01:00:0075Florian RothWEBSHELLdf31cdccbfd0546898801cb78b722f0e
1099FSO_s_cmdWebshells Auto-generated - file cmd.asp-1970-01-01 01:00:0075Florian RothWEBSHELLeda45608fabb5617dce501130936941c
1100FSO_s_indexerWebshells Auto-generated - file indexer.asp-1970-01-01 01:00:0075Florian RothWEBSHELL9c9e1135c48ccbaf12e6dfacf020f1d3
1101FSO_s_indexer_2Webshells Auto-generated - file indexer.asp-1970-01-01 01:00:0075Florian RothWEBSHELLc4febcd3a72c61ff09c0bb155ab5bc13
1102FSO_s_ntdaddyWebshells Auto-generated - file ntdaddy.asp-1970-01-01 01:00:0075Florian RothWEBSHELL05e6f7d444cec90a24eccec2b7b7efcc
1103FSO_s_phpinjWebshells Auto-generated - file phpinj.php-1970-01-01 01:00:0075Florian RothWEBSHELL1ed6c1f1129e7488a930f20d2cf7ab3d
1104FSO_s_phpinj_2Webshells Auto-generated - file phpinj.php-1970-01-01 01:00:0075Florian RothWEBSHELL22a68d5205873da411447139bcfa414b
1105FSO_s_phvayvWebshells Auto-generated - file phvayv.php-1970-01-01 01:00:0075Florian RothWEBSHELLe2014f9a2228338eaba91ff966b79368
1106FSO_s_phvayv_2Webshells Auto-generated - file phvayv.php-1970-01-01 01:00:0075Florian RothWEBSHELL3084815b75c5854db8ad3cee9dceba46
1107FSO_s_readerWebshells Auto-generated - file reader.asp-1970-01-01 01:00:0075Florian RothWEBSHELL4fbc0337997085cbfba8cc612b98cbfb
1108FSO_s_remviewWebshells Auto-generated - file remview.php-1970-01-01 01:00:0075Florian RothWEBSHELL967fd709aca6b68d3d18098b92eb0be6
1109FSO_s_remview_2Webshells Auto-generated - file remview.php-1970-01-01 01:00:0075Florian RothWEBSHELL64c9096d84412a83b3acc32275eae257
1110FSO_s_sincapWebshells Auto-generated - file sincap.php-1970-01-01 01:00:0075Florian RothWEBSHELL08779eabb953b4e451ac88323ec43c5e
1111FSO_s_testWebshells Auto-generated - file test.php-1970-01-01 01:00:0075Florian RothWEBSHELLde5b4a2d0574a41c3764887085ed1c27
1112FSO_s_toolWebshells Auto-generated - file tool.asp-1970-01-01 01:00:0075Florian RothWEBSHELL80ca29a5ff9e9ff0a61870a70c4dfd54
1113FSO_s_zehir4Webshells Auto-generated - file zehir4.asp-1970-01-01 01:00:0075Florian RothWEBSHELL6036c962adcbbd0dee59eef1f437150f
1114FSO_s_zehir4_2Webshells Auto-generated - file zehir4.asp-1970-01-01 01:00:0075Florian RothWEBSHELL6a7beb2c0020f4eac967494afcb84283
1115FVEY_ShadowBroker_Auct_Dez16_StringsString from the ShodowBroker Files Screenshots - Dec 2016https://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0060Florian RothEXE,FILE,HKTL873bbc7ffaa10f1f0b507a88b242868b
1116FVEY_ShadowBroker_Gen_Readme1Auto-generated rulehttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothGEN,HKTL52b9fb36e34465bc6e490a7902d85d13
1117FVEY_ShadowBroker_Gen_Readme2Auto-generated rule - from files user.tool.orleansstride.COMMON, user.tool.curserazor.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothGEN,HKTL1c8865ffe7d9ff01359eff438fd5d7ad
1118FVEY_ShadowBroker_Gen_Readme3Auto-generated rulehttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothGEN,HKTL51deea13e94d2b6357a82c9afc021cef
1119FVEY_ShadowBroker_Gen_Readme4Auto-generated rule - from files violetspirit.README, violetspirit.READMEhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothGEN,HKTLea6a1d81dfa2f802395d5d0ec41a9578
1120FVEY_ShadowBroker_README_cupAuto-generated rule - file README.cup.NOPENhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL9836be810f68d6f00c0b12b59239160e
1121FVEY_ShadowBroker_eleganteagle_opscript_1_0_0Auto-generated rule - file eleganteagle_opscript.1.0.0.6https://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL9d3f4373e412a042ad916e688b4aa627
1122FVEY_ShadowBroker_gr_grAuto-generated rule - file gr.noteshttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLefce067a4d2ecacc7032c9f15c522b18
1123FVEY_ShadowBroker_nopen_oneshotAuto-generated rule - file oneshot.examplehttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLd8c0c197bad756eb953bc02be0db1702
1124FVEY_ShadowBroker_opscriptAuto-generated rule - file opscript.sehttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL6017185446fa55d1dbab6cae7d447dfa
1125FVEY_ShadowBroker_strifeworldAuto-generated rule - file strifeworld.1https://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLa5b41af36e9531c16c32df465d928752
1126FVEY_ShadowBroker_user_toolAuto-generated rule - file user.tool.elatedmonkeyhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLa331e21bff6a4b741fc1e45e4bbf9d34
1127FVEY_ShadowBroker_user_tool_dubmoatAuto-generated rule - file user.tool.dubmoat.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLc975859064672e5fcad2239bd2744aed
1128FVEY_ShadowBroker_user_tool_earlyshovelAuto-generated rule - file user.tool.earlyshovel.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLc6fe8bed211cf4d5c608cb56caf91690
1129FVEY_ShadowBroker_user_tool_ebbislandAuto-generated rule - file user.tool.ebbisland.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL2d6d7b363eed6912c6dcc5fbbab0f306
1130FVEY_ShadowBroker_user_tool_elgingambleAuto-generated rule - file user.tool.elgingamble.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL9773e8c7311277f8b35046ca03837f08
1131FVEY_ShadowBroker_user_tool_envisioncollisionAuto-generated rule - file user.tool.envisioncollision.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLdcc6747b6a1cccdd6a5cf0eb4c42ff30
1132FVEY_ShadowBroker_user_tool_epicheroAuto-generated rule - file user.tool.epichero.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL37bca351a45aadfb47ea96ff119ccc44
1133FVEY_ShadowBroker_user_tool_porkAuto-generated rule - file user.tool.pork.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL14d74a2a7835eb3b79537e0c908b3a0b
1134FVEY_ShadowBroker_user_tool_shentysdelightAuto-generated rule - file user.tool.shentysdelight.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL5fcb087d7fe0ff5df237b81393279ab8
1135FVEY_ShadowBroker_user_tool_stoicsurgeonAuto-generated rule - file user.tool.stoicsurgeon.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL3760060db20e3c8f1b448beac75fa7be
1136FVEY_ShadowBroker_user_tool_yellowspiritAuto-generated rule - file user.tool.yellowspirit.COMMONhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTLe7168614d19166eae9e4d2aeb0742fd5
1137FVEY_ShadowBroker_violetspiritAuto-generated rule - file violetspirit.READMEhttps://bit.no.com:43110/theshadowbrokers.bit/post/message6/2016-12-17 00:00:0075Florian RothHKTL8071bb882cefcd3800c7fac1449fbea6
1138FVEY_ShadowBrokers_Jan17_Screen_StringsDetects strings derived from the ShadowBroker's leak of Windows tools/exploitshttps://bit.no.com:43110/theshadowbrokers.bit/post/message7/2017-01-08 00:00:0075Florian RothEXE,FILE,HKTLeb06a505f5765d49cff6dc089d791416
1139FakeM_GenericDetects FakeM malware sampleshttp://researchcenter.paloaltonetworks.com/2016/01/scarlet-mimic-years-long-espionage-targets-minority-activists/2016-01-25 00:00:0085Florian RothEXE,FILE,GEN62dd27826be63cb238ecbcc9761c0b68
1140Fake_AdobeReader_EXEDetects an fake AdobeReader executable based on filesize OR missing strings in file-2014-09-11 00:00:0050Florian RothEXE,EXTVAR,FILE6ed223a9a34e0217ffb36a9d7d63b2f1
1141Fake_FlashPlayerUpdaterService_EXEDetects an fake AdobeReader executable based on filesize OR missing strings in file-2014-09-11 00:00:0050Florian RothEXE,EXTVAR,FILE0a573e3600f055dfa5d50e550058e9c1
1142Fareit_Trojan_Oct15Detects Fareit Trojan from Sep/Oct 2015 Wavehttp://goo.gl/5VYtlU2015-10-18 00:00:0080Florian RothEXE,FILE,MAL861bf95fc9b7db9ce2b2783f4e106bac
1143FeliksPack3___PHP_Shells_2005Webshells Auto-generated - file 2005.asp-1970-01-01 01:00:0075Florian RothWEBSHELLb4cadcb3fc713e4ec393a4a72d6eb69c
1144FeliksPack3___PHP_Shells_phpftWebshells Auto-generated - file phpft.php-1970-01-01 01:00:0075Florian RothWEBSHELL0d8e40ba444aa04df42f6f08be3afba0
1145FeliksPack3___PHP_Shells_r57Webshells Auto-generated - file r57.php-1970-01-01 01:00:0075Florian RothWEBSHELLabe763cfd379633d8189158b5a3ff655
1146FeliksPack3___PHP_Shells_sshWebshells Auto-generated - file ssh.php-1970-01-01 01:00:0075Florian RothWEBSHELL979639d65983314f87bd93c6ec299d0d
1147FeliksPack3___PHP_Shells_usrWebshells Auto-generated - file usr.php-1970-01-01 01:00:0075Florian RothWEBSHELLf82506e929bf3f26e278ccb8d9c5bf57
1148FeliksPack3___PHP_Shells_xIShellWebshells Auto-generated - file xIShell.php-1970-01-01 01:00:0075Florian RothWEBSHELLbba7b0bbffa2faa94bae172a2ae8748d
1149FeliksPack3___Scanners_ipscanAuto-generated rule on file ipscan.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL3824246c1082abffdff1b7d35554448e
1150Fidelis_Advisory_Purchase_Order_ppsDetects a string found in a malicious document named Purchase_Order.ppshttp://goo.gl/ZjJyti2015-06-09 00:00:0075Florian Roth2e1c8fee28e77bdb5f6065f0e2d5337c
1151Fidelis_Advisory_cedt370Detects a string found in memory of malware cedt370r(3).exehttp://goo.gl/ZjJyti2015-06-09 00:00:0075Florian Roth561913875b4d8d530d2f4e2ea5595f7e
1152Fierce2This signature detects the Fierce2 domain scanner-2014-07-06 00:00:0060Florian RothHKTL8b025f1c2147c7c14e93a0c3c280879f
1153Fireball_archerDetects Fireball malware - file archer.dllhttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILEcd994c2a3ab39a0f0d1fbcb077060253
1154Fireball_de_svrDetects Fireball malware - file de_svr.exehttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILE4918450cab0b95753a56a0cb7195a85d
1155Fireball_gubedDetects Fireball malware - file gubed.exehttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILE0bed0b435e60cb9373242d586178830e
1156Fireball_lancerDetects Fireball malware - file lancer.dllhttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILE7105126cbe2804bc84e4ebd80aca5292
1157Fireball_regkeyDetects Fireball malware - file regkey.exehttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILE4ce88b3bed7db607d8b633b087dc5761
1158Fireball_winsapDetects Fireball malware - file winsap.dllhttps://goo.gl/4pTkGQ2017-06-02 00:00:0075Florian RothEXE,FILE01f4e60dca3447848ab83446e64cba83
1159FiveEyes_QUERTY_Malwareqwerty_20120FiveEyes QUERTY Malware - file 20120.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMALce68ef98fd0d7e9290d25252da563d6e
1160FiveEyes_QUERTY_Malwareqwerty_20121FiveEyes QUERTY Malware - file 20121.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL20675c5a33fcbb81d289a3dd4dd06527
1161FiveEyes_QUERTY_Malwareqwerty_20123FiveEyes QUERTY Malware - file 20123.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL8ac6aa4b3cdebe7b16fd6c1f4991cb96
1162FiveEyes_QUERTY_Malwaresig_20120_cmdDefFiveEyes QUERTY Malware - file 20120_cmdDef.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL98190776e0f106edc063d5efb43e4432
1163FiveEyes_QUERTY_Malwaresig_20120_dllFiveEyes QUERTY Malware - file 20120.dll.binhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL95ac49aa25e59a6c6860894cd75dcdd5
1164FiveEyes_QUERTY_Malwaresig_20121_cmdDefFiveEyes QUERTY Malware - file 20121_cmdDef.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL2a2baaea3b522b7754109296c266a2e0
1165FiveEyes_QUERTY_Malwaresig_20121_dllFiveEyes QUERTY Malware - file 20121.dll.binhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL14786683533096ddd7ffd1ca359e64d8
1166FiveEyes_QUERTY_Malwaresig_20123_cmdDefFiveEyes QUERTY Malware - file 20123_cmdDef.xmlhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL28f695302224954d50a138f4e679fdf6
1167FiveEyes_QUERTY_Malwaresig_20123_sysFiveEyes QUERTY Malware - file 20123.sys.binhttp://www.spiegel.de/media/media-35668.pdf2015-01-18 00:00:0075Florian RothMAL3bf8d87197575d4c66061baaeaf56fd5
1168Flash_CVE_2015_5119_APT3_legExploit Sample CVE-2015-5119-2015-08-01 00:00:0070Florian RothEXPLOIT,FILEc8914ad59caaa241260130270ce70de6
1169Foudre_Backdoor_1Detects Foudre Backdoorhttps://goo.gl/Nbqbt62017-08-01 00:00:0075Florian RothEXE,FILE,MAL8caef6efbd53375b27a7f2e7005f668a
1170Foudre_Backdoor_Component_1Detects Foudre Backdoorhttps://goo.gl/Nbqbt62017-08-01 00:00:0075Florian RothEXE,FILE,MALd66ce32cff518db81eebe31490fc4235
1171Foudre_Backdoor_Dropper_1Detects Foudre Backdoorhttps://goo.gl/Nbqbt62017-08-01 00:00:0075Florian RothEXE,FILE,MAL9e9f387a9613c2b1e3c409aca6d2ffb2
1172Foudre_Backdoor_SFXDetects Foudre Backdoor SFXhttps://goo.gl/Nbqbt62017-08-01 00:00:0075Florian RothEXE,FILE,MAL10c88ffe2c44252876d2df08cbf20223
1173FourElementSword_32DLLDetects FourElementSword Malware - file 7a200c4df99887991c638fe625d07a4a3fc2bdc887112437752b3df5c8da79b6https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MALb8df1b7df580e20ef9c9a9c1c73f7d26
1174FourElementSword_Config_FileDetects FourElementSword Malware - file f05cd0353817bf6c2cab396181464c31c352d6dea07e2d688def261dd6542b27https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothMAL01880ac8349e00e32ce0cc757e60d83d
1175FourElementSword_ElevateDLLDetects FourElementSword Malwarehttps://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MAL571b69ee80e456d988a23971685542a1
1176FourElementSword_ElevateDLL_2Detects FourElementSword Malware - file 9c23febc49c7b17387767844356d38d5578727ee1150956164883cf555fe7f95https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MAL9410dbd0e19faac56a6a45854c40a254
1177FourElementSword_Keyainst_EXEDetects FourElementSword Malware - file cf717a646a015ee72f965488f8df2dd3c36c4714ccc755c295645fe8d150d082https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MALea26ffca0c249ed5b6358c8eba58a984
1178FourElementSword_PowerShell_StartDetects FourElementSword Malware - file 9b6053e784c5762fdb9931f9064ba6e52c26c2d4b09efd6ff13ca87bbb33c692https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothMAL,SCRIPT560bae78b69ffdbe200586cd163c2242
1179FourElementSword_ResN32DLLDetects FourElementSword Malware - file bf1b00b7430899d33795ef3405142e880ef8dcbda8aab0b19d80875a14ed852fhttps://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothMAL26dc548575d146f6e0d209449598b821
1180FourElementSword_T9000Detects FourElementSword Malware - file 5f3d0a319ecc875cc64a40a34d2283cb329abcf79ad02f487fbfd6bef153943chttps://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MALb2f5321f0fd91705716d9c7200a7a3b7
1181FourElementSword_fslapi_dll_guiDetects FourElementSword Malware - file 2a6ef9dde178c4afe32fe676ff864162f104d85fac2439986de32366625dc083https://www.arbornetworks.com/blog/asert/four-element-sword-engagement/2016-04-18 00:00:0075Florian RothEXE,FILE,MALbc10bd859bcd1178f4bb8943df37f05c
1182FreeMilk_APT_Mal_1Detects malware from FreeMilk campaignhttps://researchcenter.paloaltonetworks.com/2017/10/unit42-freemilk-highly-targeted-spear-phishing-campaign/2017-10-05 00:00:0075Florian RothAPT,EXE,FILE889dcb4b543b828246e5933b999e018a
1183FreeMilk_APT_Mal_2Detects malware from FreeMilk campaignhttps://researchcenter.paloaltonetworks.com/2017/10/unit42-freemilk-highly-targeted-spear-phishing-campaign/2017-10-05 00:00:0075Florian RothAPT,EXE,FILE45c28a8cf16054aaf514da341c88696c
1184FreeMilk_APT_Mal_3Detects malware from FreeMilk campaignhttps://researchcenter.paloaltonetworks.com/2017/10/unit42-freemilk-highly-targeted-spear-phishing-campaign/2017-10-05 00:00:0075Florian RothAPT,EXE,FILE53f7a7601986ac603194075dd344f586
1185FreeMilk_APT_Mal_4Detects malware from FreeMilk campaignhttps://researchcenter.paloaltonetworks.com/2017/10/unit42-freemilk-highly-targeted-spear-phishing-campaign/2017-10-05 00:00:0075Florian RothAPT,EXE,FILE54a7157ba9c861178abd74bc8a8916e6
1186FreeVersion_debugChinese Hacktool Set - file debug.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLcb480065ffcf4fa6695aa67f53b226b2
1187FreeVersion_releaseChinese Hacktool Set - file release.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd9621f81c53b9f9882cdd24cbe987ab5
1188Freeenki_Infostealer_Nov17Detects Freenki infostealer malwarehttp://blog.talosintelligence.com/2017/11/ROKRAT-Reloaded.html2017-11-28 00:00:0075Florian RothEXE,FILE28764c814be94b3da5eaf30f035369ba
1189Freeenki_Infostealer_Nov17_Export_Sig_TestingDetects Freenki infostealer malwarehttp://blog.talosintelligence.com/2017/11/ROKRAT-Reloaded.html2017-11-28 00:00:0075Florian RothEXE,FILE2a1076aa339cba5051d57714c4923699
1190Fscan_PortscannerFscan port scanner scan output / stringshttps://twitter.com/JamesHabben/status/8171124479704801282017-01-06 00:00:0075Florian RothHKTL5f456b582bef0885f91b11abc10530da
1191Furtim_Parent_1Detects Furtim Parent Malwarehttps://sentinelone.com/blogs/sfg-furtims-parent/2016-07-16 00:00:0075Florian RothEXE,FILE,MAL4fc9b24cd7f04b0de3a870d01b9239d9
1192Furtim_nativeDLLDetects Furtim malware - file native.dllMISP 39712016-06-13 00:00:0075Florian RothEXE,FILEfcc7e0ae33c824452c888d52e7c24d13
1193GIFCloaked_Webshell_ALooks like a webshell cloaked as GIF-1970-01-01 01:00:0060Florian RothFILE,WEBSHELL9e930cf0531ffd77d0d8468e48443200
1194GRIZZLY_STEPPE_Malware_1Auto-generated rule - file HRDG022184_certclint.dllhttps://goo.gl/WVflzO2016-12-29 00:00:0075Florian RothEXE,FILE,MALf4f0db65da77fd9d1a819766cc6a843c
1195GRIZZLY_STEPPE_Malware_2Auto-generated rule - file 9acba7e5f972cdd722541a23ff314ea81ac35d5c0c758eb708fb6e2cc4f598a0https://goo.gl/WVflzO2016-12-29 00:00:0075Florian RothEXE,FILE,MALc74d22aeb75463df1ab8c4ca4df543ce
1196Gazer_certificateDetects Tura's Gazer malwarehttps://www.welivesecurity.com/2017/08/30/eset-research-cyberespionage-gazer/2017-08-30 00:00:0075ESETEXE,FILE3c6b7c28296ac682d8d9622a4efd2c87
1197Gazer_certificate_subjectDetects Tura's Gazer malwarehttps://www.welivesecurity.com/2017/08/30/eset-research-cyberespionage-gazer/2017-08-30 00:00:0075ESETEXTVARfd563f73c76cf0dd6f070bdbb0d48a74
1198Gazer_logfile_nameDetects Tura's Gazer malwarehttps://www.welivesecurity.com/2017/08/30/eset-research-cyberespionage-gazer/2017-08-30 00:00:0075ESETEXE,FILE5919a7d9d507a550feb9011c1062f15f
1199Gen_Base64_EXEDetects Base64 encoded Executable in ExecutableInternal Research2017-04-21 00:00:0075Florian RothEXE,FILE,GEN4c430038702234a1c17c4c632c4942f7
1200Gen_Net_LocalGroup_Administrators_Add_CommandDetects an executable that contains a command to add a user account to the local administrators groupInternal Research2017-07-08 00:00:0075Florian RothEXE,FILE,GEN06a366ba8169c06fe9434f20e760146a
1201Gen_Trojan_MikeyTrojan Mikey - file sample_mikey.exe-2015-05-07 00:00:0070Florian RothEXE,FILE,GEN,MAL492dc399dfa7c1034629d0ce970f7a44
1202GenerateChinese Hacktool Set - file Generate.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,GEN,HKTL6fe1bcc8c105045ddf4c78516d5bdbbb
1203Generic_DropperDetects Dropper PDB string in filehttps://goo.gl/JAHZVL2018-03-03 00:00:0075Florian RothEXE,FILE,GEN,MALe95708895c8515e5625fa1b2d02a27a3
1204GetUserSPNs_PS1Auto-generated rule - file GetUserSPNs.ps1https://github.com/skelsec/PyKerberoast2016-05-21 00:00:0075Florian Roth321bc9b5da10324bdb1457a221db47ff
1205GetUserSPNs_VBSAuto-generated rule - file GetUserSPNs.vbshttps://github.com/skelsec/PyKerberoast2016-05-21 00:00:0075Florian RothSCRIPTb5eb4f3fd7483db06432ed04d3865105
1206GhostDragon_Gh0stRATDetects Gh0st RAT mentioned in Cylance' Ghost Dragon Reporthttps://blog.cylance.com/the-ghost-dragon2016-04-23 00:00:0075Florian RothCHINA,EXE,FILE,MAL314f371321516f1a4f0eba20922edb81
1207GhostDragon_Gh0stRAT_Sample2Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Reporthttps://blog.cylance.com/the-ghost-dragon2016-04-23 00:00:0075Florian RothCHINA,EXE,FILE,MAL9cf2dd913485d70f62c64220dc18cdac
1208GhostDragon_Gh0stRAT_Sample3Detects Gh0st RAT mentioned in Cylance' Ghost Dragon Reporthttps://blog.cylance.com/the-ghost-dragon2016-04-23 00:00:0075Florian RothCHINA,MAL15649b30c246f9f3a0d035c9b02d3800
1209GlassRAT_GenericDetects GlassRAT Malwarehttps://blogs.rsa.com/peering-into-glassrat/2015-11-23 00:00:0080Florian RothEXE,FILE,GEN,MALa67da6cd4c8b9d82705f15f246820511
1210GoldDragon_Aux_FileDetects export from Gold Dragon - February 2018https://securingtomorrow.mcafee.com/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/2018-02-03 00:00:0090Florian RothCHINA27f7bccaf84780a16ab91ccc4037fbfd
1211GoldDragon_Ghost419_RATDetects Ghost419 RAT from Gold Dragon reporthttps://goo.gl/rW1yvZ2018-02-03 00:00:0075Florian RothCHINA,EXE,FILE,MALb8dc2e479c7716472fd03d13ca14d7f6
1212GoldDragon_RunnignRATDetects Running RAT malware from Gold Dragon reporthttps://goo.gl/rW1yvZ2018-02-03 00:00:0075Florian RothCHINA,EXE,FILE,MALa40682a7cd679c5b38e6293375905607
1213GoldDragon_RunningRATDetects Running RAT from Gold Dragon reporthttps://goo.gl/rW1yvZ2018-02-03 00:00:0075Florian RothCHINA,EXE,FILE,MAL8ed341d9704cab0e0a449968c46e5609
1214GoldDragon_malware_Feb18_1Detects malware from Gold Dragon reporthttps://securingtomorrow.mcafee.com/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/2018-02-03 00:00:0090Florian RothCHINA,EXE,FILE6b9e865c3d6f03743045bb450ad5ad97
1215GoldenEyeRansomware_Dropper_MalformedZoomitAuto-generated rule - file b5ef16922e2c76b09edd71471dd837e89811c5e658406a8495c1364d0d9dc690https://goo.gl/jp2SkT2016-12-06 00:00:0075Florian RothEXE,FILE,MAL7c942ab313a74d59c472cc86e6db54c7
1216GoldenEye_Ransomware_XLSGoldenEye XLS with Macro - file Schneider-Bewerbung.xlshttps://goo.gl/jp2SkT2016-12-06 00:00:0075Florian RothCRIME,FILEe12efdbae3c6da55c99c468d25712a08
1217GoodToolset_ms11011Chinese Hacktool Set - file ms11011.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd605f15f762fce89259fda4f68c00127
1218GoodToolset_ms11046Chinese Hacktool Set - file ms11046.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL2b99f21021d9c92e9245fde198eb1cfc
1219GoodToolset_ms11080Chinese Hacktool Set - file ms11080.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLe81bf8edb7ebe43a15d022f0b81258d8
1220GoodToolset_prChinese Hacktool Set - file pr.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL66fcbd7f4ee77287950347374252918d
1221GoogleBot_UserAgentDetects the GoogleBot UserAgent String in an ExecutableInternal Research2017-01-27 00:00:0065Florian RothEXE,FILE162919fdd9d00538d2c1eb00422ddc9a
1222Greenbug_Malware_1Detects Malware from Greenbug Incidenthttps://goo.gl/urp4CD2017-01-25 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EAST556615c892a2ef3f3de3618e53834268
1223Greenbug_Malware_2Detects Backdoor from Greenbug Incidenthttps://goo.gl/urp4CD2017-01-25 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EAST0a529b1fdfe16b2e6f0b043239d71499
1224Greenbug_Malware_3Detects Backdoor from Greenbug Incidenthttps://goo.gl/urp4CD2017-01-25 00:00:0075Florian RothMAL,MIDDLE_EAST830d04460d0d17f59c98841f39ee2e80
1225Greenbug_Malware_4Detects ISMDoor Backdoorhttps://goo.gl/urp4CD2017-01-25 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EASTf756b16a93dac0b7daa37c713582d2de
1226Greenbug_Malware_5Auto-generated rulehttps://goo.gl/urp4CD2017-01-25 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EAST894631f4a2d9649d008f12449ccbbf7b
1227Greenbug_Malware_Nov17_1Detects Greenbug Malwarehttp://www.clearskysec.com/greenbug/2017-11-26 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EAST14db750969640a3ab8494229acbef741
1228Groups_cpasswordGroups XML contains cpassword value, which is decrypted password - key is in MSDN http://goo.gl/mHrC8Phttp://www.grouppolicy.biz/2013/11/why-passwords-in-group-policy-preference-are-very-bad/2015-09-08 00:00:0050Florian RothFILE194d4a8f6d5d460aca5ab08db6274cc9
1229Gsecdump_password_dump_fileDetects a gsecdump output filehttps://t.co/OLIj1yVJ4m2018-03-06 00:00:0065Florian RothFILEfe3173f05892024b04af1dd50a629a5d
1230Guilin_veterans_cookie_spoofing_toolChinese Hacktool Set - file Guilin veterans cookie spoofing tool.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL9dade89e7bd064e5ceb1ddc96c279159
1231HDConfigWebshells Auto-generated - file HDConfig.exe-1970-01-01 01:00:0075Florian RothWEBSHELL72d6e0b6a8ddb1948bc12412590df151
1232HDRoot_Sample_Jul17_1Detects HDRoot samplesWinnti HDRoot VT2017-07-07 00:00:0075Florian RothEXE,FILE2e89ba094176dfd224547ad52eef782e
1233HDRoot_Sample_Jul17_2Detects HDRoot samplesWinnti HDRoot VT2017-07-07 00:00:0075Florian RothEXE,FILEe90415ce1c4c1ac4680211d436b48054
1234HKTL_DsniffDetects Dsniff hack toolhttps://goo.gl/eFoP4A2019-02-19 00:00:0055Florian RothHKTL02926ca7741beeaf77dd4dbc505c26b0
1235HKTL_EmbeddedPDFDetects Embedded PDFs which can start malicious contenthttps://twitter.com/infosecn1nja/status/1021399595899731968?s=122018-07-25 00:00:0075Tobias MichalskiFILE,HKTL9595397ef6713b499df35a9cc1530720
1236HKTL_Lazagne_Gen_18Detects Lazagne password extractor hacktoolhttps://github.com/AlessandroZ/LaZagne2018-12-11 00:00:0080Florian RothGEN,HKTL0ba7ad0382ef504e7d469b00ace3f8d2
1237HKTL_Lazagne_PasswordDumper_Dec18_1Detects password dumper Lazagne often used by middle eastern threat groupshttps://www.symantec.com/blogs/threat-intelligence/seedworm-espionage-group2018-12-11 00:00:0085Florian RothEXE,FILE,HKTL19b29fa95bc6375a6ae34c98bec99215
1238HKTL_LazyCat_LogEraserDetetcs a tool used in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothHKTL4d2ea6ce77f3c01620a0c4cfb8a5f388
1239HKTL_NoPowerShellDetects NoPowerShell hack toolhttps://github.com/bitsadmin/nopowershell2018-12-28 00:00:0075Florian RothHKTL,SCRIPT68bbae7e3cfd114d9e4803c74cc4615c
1240HKTL_PowerKatz_Feb19_1Detetcs a tool used in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothHKTL9dad892eb3185948cd94185fab356fa0
1241HKTL_PowerSploitDetects default strings used by PowerSploit to establish persistencehttps://www.hybrid-analysis.com/sample/16937e76db6d88ed0420ee87317424af2d4e19117fe12d1364fee35aa2fadb75?environmentId=1002018-06-23 00:00:0075Markus NeisHKTL8e67b87f506dbd2236a14dfd6105859b
1242HKTL_SqlMapDetects sqlmap hacktoolhttps://github.com/sqlmapproject/sqlmap2018-10-09 00:00:0075Florian RothHKTL0f6a00eefaa6b2703b4a41155b28bcd3
1243HKTL_SqlMap_backdoorDetects SqlMap backdoorshttps://github.com/sqlmapproject/sqlmap2018-10-09 00:00:0075Florian RothFILE,HKTL,MALfd9f97c93c7703763be08d02ac9126fc
1244HKTL_Unknown_Feb19_1Detetcs a tool used in the Australian Parliament House network compromisehttps://twitter.com/cyb3rops/status/10974236654723768322019-02-18 00:00:0075Florian RothHKTL72f3da6804f056fb52a5eaf0ccae6f0c
1245HKTL_beRootexeDetects beRoot.exe which checks common Windows missconfigurationshttps://github.com/AlessandroZ/BeRoot/tree/master/Windows2018-07-25 00:00:0075yarGen Rule GeneratorEXE,FILE,HKTLfaf3b3b4c281fa1a35f00eba5b1215d1
1246HKTL_beRootexe_outputDetects the output of beRoot.exehttps://github.com/AlessandroZ/BeRoot/tree/master/Windows2018-07-25 00:00:0075Tobias MichalskiHKTLf91e861d691e7bbb698cfd3f5c9acbc7
1247HKTL_htran_goDetects go based htran variant-2019-01-09 00:00:0075Jeff BeleyEXE,FILE,HKTL6cb106df30b2d99863218849c73c4e2a
1248HKTL_shellpop_Netcat_UDPDetects suspicious netcat popshellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTLdfccbec4acd47cde75cdff95c89a2fbf
1249HKTL_shellpop_PHP_TCPDetects malicious PHP shellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL2ea721bdd34b8ba87dfbe6c3a252652d
1250HKTL_shellpop_PerlDetects Shellpop Perl scripthttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL4a67d90418dcdab0517a990ebe007e6c
1251HKTL_shellpop_Powershell_TCPDetects malicious powershellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL6d553713422049bf023e72f31389fec6
1252HKTL_shellpop_PythonDetects malicious python shellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL,SCRIPTe6dff79aa25dfae3ae3ed3f18cd01a8a
1253HKTL_shellpop_TCLshDetects suspicious TCLsh popshellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTLa17d4faead0ca2c3f967c0ad6fcd74c4
1254HKTL_shellpop_Telnet_TCPDetects malicious telnet shellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTLa900e181c91fde4e7a61f3bc48897ac7
1255HKTL_shellpop_awkDetects suspicious AWK Shellpophttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTLf13a77ca8c482d7d79c3758dfec85a76
1256HKTL_shellpop_netcatDetects suspcious netcat shellpophttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL4ae3f2588e5d6a0ba293521ea1f928e4
1257HKTL_shellpop_rubyDetects suspicious ruby shellpophttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL09f35a5a9c86c0ba7211144ac044393e
1258HKTL_shellpop_socatDetects suspicious socat popshellhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTLe20bc3677fda7e480368a35b32f0f365
1259HScan_v1_20_PipeCmdChinese Hacktool Set - file PipeCmd.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL78dffe7bc36704a324aaa2ab113cab11
1260HScan_v1_20_hscanChinese Hacktool Set - file hscan.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL57bcb3432ab195c4334f510fb48720c7
1261HTA_EmbeddedDetects an embedded HTA filehttps://twitter.com/msftmmpc/status/8773969327585607682017-06-21 00:00:0050Florian Rothf30542960e1d8208ff631623e25e0839
1262HTA_with_WScript_ShellDetects WScript Shell in HTAhttps://twitter.com/msftmmpc/status/8773969327585607682017-06-21 00:00:0080Florian Roth14bdadb231881f3fe7e0fdd15f1f3b9a
1263HTKL_BlackBone_DriverInjectorDetects BlackBone Driver injectorhttps://github.com/DarthTon/Blackbone2018-09-11 00:00:0060Florian RothEXE,FILE,HKTL8c8f2fc700ac026c8cf3e94354e2ed82
1264HTTPSCANNERChinese Hacktool Set - file HTTPSCANNER.EXEhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL3026b737f4e09a512a07653b69c3eace
1265HYTop2006_rar_Folder_2006Webshells Auto-generated - file 2006.asp-1970-01-01 01:00:0075Florian RothWEBSHELLda24bab15e1377bca46e329bfb75bc09
1266HYTop2006_rar_Folder_2006X2Webshells Auto-generated - file 2006X2.exe-1970-01-01 01:00:0075Florian RothWEBSHELL0c1ddfe1cad9165623c985954d29bb57
1267HYTop2006_rar_Folder_2006XWebshells Auto-generated - file 2006X.exe-1970-01-01 01:00:0075Florian RothWEBSHELL36040b91854ec313820099ba69c2215a
1268HYTop2006_rar_Folder_2006ZWebshells Auto-generated - file 2006Z.exe-1970-01-01 01:00:0075Florian RothWEBSHELLa1962038ea977bb14b735d8b5974cdd0
1269HYTop_AppPack_2005Webshells Auto-generated - file 2005.asp-1970-01-01 01:00:0075Florian RothWEBSHELLf5cb6e080bfe294a10c50d62f6dfd270
1270HYTop_CaseSwitch_2005Webshells Auto-generated - file 2005.exe-1970-01-01 01:00:0075Florian RothWEBSHELL8d181359912086a28c87b47fac50757c
1271HYTop_DevPack_2005Webshells Auto-generated - file 2005.asp-1970-01-01 01:00:0075Florian RothWEBSHELL748922ce8621e44385d2fef31f67e551
1272HYTop_DevPack_2005RedWebshells Auto-generated - file 2005Red.asp-1970-01-01 01:00:0075Florian RothWEBSHELLd6e22e53c10cd5283fdcb8493769c0dc
1273HYTop_DevPack_configWebshells Auto-generated - file config.asp-1970-01-01 01:00:0075Florian RothWEBSHELL5000cb7793cb1336167fb210c3fc98e4
1274HYTop_DevPack_fsoWebshells Auto-generated - file fso.asp-1970-01-01 01:00:0075Florian RothWEBSHELLc6d14d695629fc4346190b4a7f4cea5a
1275HYTop_DevPack_serverWebshells Auto-generated - file server.asp-1970-01-01 01:00:0075Florian RothWEBSHELL25db6785ca701d752af51049eda12e19
1276HYTop_DevPack_uploadWebshells Auto-generated - file upload.asp-1970-01-01 01:00:0075Florian RothWEBSHELL16da3d9a93bb30a6fac46f236a188dd4
1277HackTool_ProducersHacktool Producers String-1970-01-01 01:00:0050Florian Roth (auto-filled)EXE,EXTVAR,FILE,HKTLa636a8943abc6048126d4112cfa5dd62
1278HackTool_SamplesHacktool-1970-01-01 01:00:0050Florian Roth (auto-filled)HKTL4d5088e4cf37ed47dec8d6600d5e82c7
1279HackingTeam_Elevator_EXEHacking Team Disclosure Sample - file elevator.exeHacking Team Disclosure elevator.c2015-07-07 00:00:0070Florian RothEXE,FILE56c349f7bfa6d5269c87fff3892ce72b
1280Hackingteam_Elevator_DLLHacking Team Disclosure Sample - file elevator.dllhttp://t.co/EG0qtVcKLh2015-07-07 00:00:0070Florian RothEXE,FILEbd9c1be1e921b6957139fc26ec5733c9
1281Hacktool_Strings_p0wnedShellp0wnedShell Runspace Post Exploitation Toolkit - file p0wnedShell.cshttps://github.com/Cn33liz/p0wnedShell2017-01-14 00:00:0075Florian RothHKTLbb4a6e97b2e41ca757f1cfef53778bad
1282Hacktool_This_CruftDetects string 'This cruft' often used in hack tools like netcat or cryptcat and also mentioned in Project Sauron reporthttps://goo.gl/eFoP4A2016-08-08 00:00:0060Florian RothEXE,FILE,HKTL6c84bc98b3fdf8f6b28acb59b6f2d734
1283Hacktools_CN_445_cmdDisclosed hacktool set - file cmd.bat-2014-11-17 00:00:0060Florian RothFILE,HKTL76ecaec2e7d5176644cca8e7f646958f
1284Hacktools_CN_Burst_BlastDisclosed hacktool set - file Blast.bat-2014-11-17 00:00:0060Florian RothHKTLa0f3f5373501db261a16e37614900070
1285Hacktools_CN_Burst_ClearDisclosed hacktool set - file Clear.bat-2014-11-17 00:00:0060Florian RothHKTL884a3f6e94f08dd236009b7923878df6
1286Hacktools_CN_Burst_StartDisclosed hacktool set - file Start.bat - DoS tool-2014-11-17 00:00:0060Florian RothHKTL99da0cf9327036ccf2b660aaa3613657
1287Hacktools_CN_Burst_ThecardDisclosed hacktool set - file Thecard.bat-2014-11-17 00:00:0060Florian RothHKTL9766cdea682cce09fad700844716291f
1288Hacktools_CN_Burst_passDisclosed hacktool set - file pass.txt-2014-11-17 00:00:0060Florian RothHKTL3f8d389905d458d1561199db8a3c47f8
1289Hacktools_CN_Burst_sqlDisclosed hacktool set - file sql.exe-2014-11-17 00:00:0060Florian RothHKTL8ed9596e0ea59e7312c7545349bccf20
1290Hacktools_CN_GOGOGO_BatDisclosed hacktool set - file GOGOGO.bat-2014-11-17 00:00:0060Florian RothHKTL8fd012883c919042404c3a76a688d2c0
1291Hacktools_CN_HttpDisclosed hacktool set - file Http.exe-2014-11-17 00:00:0060Florian RothHKTLbcb41e6687608e9529ec19ce9a9d1901
1292Hacktools_CN_JoHor_Posts_KillerDisclosed hacktool set - file JoHor_Posts_Killer.exe-2014-11-17 00:00:0060Florian RothHKTL8153098a93d05ded4a2fe1f0c579a742
1293Hacktools_CN_Panda_445Disclosed hacktool set - file 445.rar-2014-11-17 00:00:0060Florian RothCHINA,HKTLb32cf7bc389ff0184f5474078059bfcc
1294Hacktools_CN_Panda_445TOOLDisclosed hacktool set - file 445TOOL.rar-2014-11-17 00:00:0060Florian RothCHINA,HKTL1e70e1870931db4e79da096edd296a47
1295Hacktools_CN_Panda_BurstDisclosed hacktool set - file Burst.rar-2014-11-17 00:00:0060Florian RothCHINA,HKTLd8b36a6f75992cfdd272877952a9dae8
1296Hacktools_CN_Panda_tasksvrDisclosed hacktool set - file tasksvr.exe-2014-11-17 00:00:0060Florian RothCHINA,HKTL6aeb6b7378e79b09ff0c3714096bffc2
1297Hacktools_CN_Panda_tesksdDisclosed hacktool set - file tesksd.jpg-2014-11-17 00:00:0060Florian RothCHINA,HKTL9ed360c83601611c077c544e7d694761
1298Hacktools_CN_Scan_BATDisclosed hacktool set - file scan.bat-2014-11-17 00:00:0060Florian RothHKTL229cf2ee3796b8550ce6d515bcc05379
1299Hacktools_CN_WinEggDropDisclosed hacktool set - file s.exe-2014-11-17 00:00:0060Florian RothHKTL19b36981cee7c13dd393bb4cb6426557
1300HawkEye_Keylogger_Feb18_1Detects HawkEye keylogger variante observed in February 2018https://app.any.run/tasks/ae2521dd-61aa-4bc7-b0d8-8c85ddcbfcc92018-02-12 00:00:0075Florian RothEXE,FILE,HKTL71cd95d98cd9b233bd6a88a9362ff61f
1301HawkEye_PHP_PanelDetects HawkEye Keyloggers PHP Panel-2014-12-14 00:00:0060Florian RothHKTL,WEBSHELL6afd5d0d01337139d808fa669b16701b
1302Hermes2_1Detects Hermes Ransomware as used in BAE report on FEIBhttps://baesystemsai.blogspot.de/2017/10/taiwan-heist-lazarus-tools.html2017-10-11 00:00:0075BAECRIME,EXE,FILE,MAL,RANSOM937be2f1171c37c98c6255f5762bc9ff
1303HiddenCobra_BANKSHOT_GenDetects Hidden Cobra BANKSHOT trojanhttps://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity2017-12-26 00:00:0075Florian RothEXE,FILE,GEN,NKc805c0b9735b2e541e02273a9b4bde2e
1304HiddenCobra_FallChill_1Auto-generated rule - file a606716355035d4a1ea0b15f3bee30aad41a2c32df28c2d468eafd18361d60d6https://www.us-cert.gov/ncas/alerts/TA17-318A2017-11-15 00:00:0075Florian RothEXE,FILE,NK7ab0d825c7e039bbba73d37ee0194a20
1305HiddenCobra_FallChill_2Auto-generated rule - file 0a118eb23399000d148186b9079fa59caf4c3faa7e7a8f91533e467ac9b6ff41https://www.us-cert.gov/ncas/alerts/TA17-318A2017-11-15 00:00:0075Florian RothEXE,FILE,NKc3f6bc1bd7e8678b9bc54e518cd3be8b
1306HiddenCobra_Rule_1Detects Hidden Cobra Malwarehttps://www.us-cert.gov/ncas/alerts/TA17-164A2017-06-13 00:00:0075US CERTMAL,NK192d2d7d294c49a58fe9502d75c15811
1307HiddenCobra_Rule_3Detects Hidden Cobra Malwarehttps://www.us-cert.gov/ncas/alerts/TA17-164A2017-06-13 00:00:0075US CERTMAL,NK73f6dc36836f7f4313771243a0c4e7f1
1308HiddenCobra_r4_wiper_1Detects HiddenCobra Wiperhttps://www.us-cert.gov/sites/default/files/publications/MAR-10135536.11.WHITE.pdf2017-12-12 00:00:0075NCCIC PartnerEXE,FILE,NK153f4da40245946b0daff8957e56fabb
1309HiddenCobra_r4_wiper_2Detects HiddenCobra Wiperhttps://www.us-cert.gov/sites/default/files/publications/MAR-10135536.11.WHITE.pdf2017-12-12 00:00:0075NCCIC PartnerEXE,FILE,NK09d2f319f06557337e8f2ca2bc68ed22
1310HoneyBee_Dropper_MalDocDetects samples from Operation Honeybeehttps://goo.gl/JAHZVL2018-03-03 00:00:0075Florian RothFILE,MAL29d1b5c8ab49aaeb6b5f27dcbaf6f555
1311HttpBrowser_RAT_GenThreat Group 3390 APT Sample - HttpBrowser RAT Generichttp://snip.ly/giNB2015-08-06 00:00:0090Florian RothAPT,EXE,FILE,GEN,MAL0a8f2a2a0f107737986499287f983f53
1312HttpBrowser_RAT_Sample1Threat Group 3390 APT Sample - HttpBrowser RAT Sample update.hancominc.comhttp://snip.ly/giNB2015-08-06 00:00:0080Florian RothAPT,EXE,FILE,MAL8cedf5b8a1bf22758d20e2114be87708
1313HttpBrowser_RAT_Sample2Threat Group 3390 APT Sample - HttpBrowser RAT Samplehttp://snip.ly/giNB2015-08-06 00:00:0080Florian RothAPT,EXE,FILE,MALae192c0b376d8e405f53b48a8f492d4d
1314HttpBrowser_RAT_dropper_Gen1Threat Group 3390 APT Sample - HttpBrowser RAT Dropperhttp://snip.ly/giNB2015-08-06 00:00:0070Florian RothAPT,EXE,FILE,MAL8b342ec50cc8e1ce7f6beeee253fc2e4
1315HttpBrowser_RAT_dropper_Gen2Threat Group 3390 APT Sample - HttpBrowser RAT Dropperhttp://snip.ly/giNB2015-08-06 00:00:0070Florian RothAPT,EXE,FILE,MALb2d8dbeb89cd64c2e9c6cab362655918
1316IDTools_For_WinXP_IdtToolChinese Hacktool Set - file IdtTool.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL950abb138df278ba8ce65424df409daf
1317IDTools_For_WinXP_IdtTool_2Chinese Hacktool Set - file IdtTool.syshttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL9aeadab485566a8f4253e441d7febc82
1318IISPutScannerChinese Hacktool Set - file IISPutScanner.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLf42ccf0be8b1e856a7daa5ec6b4dd6fc
1319IISPutScannesrChinese Hacktool Set - file IISPutScannesr.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLe4a5940830f463bee658bdba9f39d559
1320IMPLANT_10_v2CozyDuke / CozyCar / CozyBear Implant by APT29https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA6cba89c6e422c5d3d225fa1db24aa084
1321IMPLANT_1_v1Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA13e44d3f9f9c34807f5fd863e20479f3
1322IMPLANT_1_v2Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAf14875543cbb0e586ddea978e6199870
1323IMPLANT_1_v3Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA25b466eb2204fb2ae7a0e1d87f26ea13
1324IMPLANT_1_v4Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAefe22cd7a541213887f0b67016c015e7
1325IMPLANT_1_v5Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAa98d4678afae075e31bb0ca4bb8bcb78
1326IMPLANT_1_v7Downrage Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA6d646f58a097a243eb873988d3024587
1327IMPLANT_2_v10CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAe4c0a2365583d7ae2bd491320c00fae1
1328IMPLANT_2_v11CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA6e07661f66f4f0cb14974f06980a6f64
1329IMPLANT_2_v12CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA965d8a562a80ff53eba1ddfa8f3add76
1330IMPLANT_2_v13CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAe4c0a2365583d7ae2bd491320c00fae1
1331IMPLANT_2_v14CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA28bb907a3cbfa5bdbebc97a4c358cc7e
1332IMPLANT_2_v15CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAac5b18fc969ae1e07ea3b778a83d1dda
1333IMPLANT_2_v16CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAd9a4e8aa7d9cb2afb222db6a4ad28c16
1334IMPLANT_2_v17CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAa40f1e5f14add1d04a59bdd2369e34d8
1335IMPLANT_2_v18CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAa3b85933b6c4721908e4879103db9849
1336IMPLANT_2_v19CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA615ddbfcf6a2507c309774c46969860c
1337IMPLANT_2_v1CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA8347799f4984f532dd6fbffd0d81dd59
1338IMPLANT_2_v20CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA51ef682ace710c59853ce43c2b3772a3
1339IMPLANT_2_v2CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAe4c0a2365583d7ae2bd491320c00fae1
1340IMPLANT_2_v3CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAa8e197f48034c0898c38376cebadd378
1341IMPLANT_2_v4CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA6e07661f66f4f0cb14974f06980a6f64
1342IMPLANT_2_v5CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA965d8a562a80ff53eba1ddfa8f3add76
1343IMPLANT_2_v6CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAdadff5ff640e4a5327bbaa5d10749f92
1344IMPLANT_2_v7CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA2f6428f0769689187689eb8d0bd5eef7
1345IMPLANT_2_v8CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA28bb907a3cbfa5bdbebc97a4c358cc7e
1346IMPLANT_2_v9CORESHELL/SOURFACE Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAacfb8be0cbbb4727e12e7510e901b672
1347IMPLANT_3_v1X-Agent/CHOPSTICK Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIA6fa77568add47319ec2952ec54e68b5f
1348IMPLANT_3_v2X-Agent/CHOPSTICK Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAf2a148ba07e7a8eaf23e79de3657207c
1349IMPLANT_3_v3X-Agent/CHOPSTICK Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA79df08800fd05e0cfd619df1b57c4e21
1350IMPLANT_4_v10BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA76e30591472d73da92a25bb19bd86c3d
1351IMPLANT_4_v11BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAc5a63ea8a25f1dee23faaaa077711d30
1352IMPLANT_4_v13BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAe84cc133f0ce0f1f5d866afe1775a450
1353IMPLANT_4_v1BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAfb840080d38aea8a4c90974c63d729c0
1354IMPLANT_4_v2BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA750956a380b75925e9d8a0f2f79767b5
1355IMPLANT_4_v3_AlternativeRuleBlackEnergy / Voodoo Bear Implant by APT28US CERT Grizzly Steppe Report2017-02-12 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA0bb9d02ef10b941dc572e513bacd91d8
1356IMPLANT_4_v4BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA6544c4cf536807978a5949ddfcfae9d8
1357IMPLANT_4_v5BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA0e6c1fee2847ec224c36eaf1a53495e3
1358IMPLANT_4_v7BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAb5b64ef96be5b89c6814beaeac56b1f8
1359IMPLANT_4_v8BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIA0b3ce34ba581c01c9940847bc516ae8f
1360IMPLANT_4_v9BlackEnergy / Voodoo Bear Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIA0ebf1d5bead715d9b832e475bf58e0f0
1361IMPLANT_5_v1XTunnel Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIAca13bf4063f2c823ab5b25ac1f05aaa4
1362IMPLANT_5_v2XTunnel Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIA39eb6b3c5972083b00b6402d9dd6e67d
1363IMPLANT_5_v3XTunnel Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIA626e936bfee7340a2150ffbc1344f34a
1364IMPLANT_5_v4XTunnel Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,RUSSIAd4678bab3784b7664a62636b38fec8df
1365IMPLANT_6_v1Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA4392fa953a93a065748803b75e4048af
1366IMPLANT_6_v2Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA339cbebc51fb082776d5971fd1bd76b4
1367IMPLANT_6_v3Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAc0b0b74701f290319007ddf8554aeefa
1368IMPLANT_6_v4Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA50a431669aa2212f8b5b0aba5d809697
1369IMPLANT_6_v5Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIA7c34bc08460d4ff9c0063146f609b8ba
1370IMPLANT_6_v6Sednit / EVILTOSS Implant by APT28https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAb80e253e49cc11187824310baae04cd7
1371IMPLANT_7_v1Implant 7 by APT29https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAc7819d6781fc33bda36fab02c5458f7a
1372IMPLANT_8_v1HAMMERTOSS / HammerDuke Implant by APT29https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0065US CERTAPT,FILE,RUSSIAb5dfb5adc530f1271fa783bff7275b2f
1373IMPLANT_9_v1Onion Duke Implant by APT29https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,FILE,RUSSIAc7e3a4122634e9a7f6bdf0b5c2b14cbe
1374IP_Stealing_UtilitiesAuto-generated rule on file IP Stealing Utilities.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL367b0b4c66b040c6f45215ea17045e90
1375IceFog_Malware_Feb18_1Detects IceFog malwarehttps://twitter.com/ClearskySec/status/9681044658186690572018-02-26 00:00:0075Florian RothEXE,FILE,MALde5380f0d6d32d59c4f94a3020ca072c
1376Impacket_KeywordDetects Impacket Keyword in ExecutableInternal Research2017-08-04 00:00:0060Florian RothEXE,FILE,HKTL4cba52d46a6c9b618a814217084659cc
1377Impacket_Lateral_MovementDetects Impacket Network Aktivity for Lateral Movementhttps://github.com/CoreSecurity/impacket2018-03-22 00:00:0060Markus NeisEXE,FILE3c01b9435d3d523d1a0c3810225c9d5d
1378Impacket_Tools_Generic_1Compiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE,GEN752c3234f23dafbc777de088ea5c362a
1379Impacket_Tools_atexecCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE3b367a5f7a76e0f5e91a206f5eaac957
1380Impacket_Tools_esentutlCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILEe741c8017df9a7f359ab553a487a4969
1381Impacket_Tools_goldenPacCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE9cd96d037e21f0e56a591e90a3d32777
1382Impacket_Tools_ifmapCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE3d5ab83b07fe194d79cb91f48d219932
1383Impacket_Tools_lookupsidCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE099abe272f1f4f38f63f5940d46ace4b
1384Impacket_Tools_mimikatzCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE7f62c6e0fe87b53de0476abab475e3c5
1385Impacket_Tools_mmcexecCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE857f31811354d2f9596adb3a9340cb1e
1386Impacket_Tools_netviewCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE65e85c10b30e3ac7993b9e16ccbb2626
1387Impacket_Tools_opdumpCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE119f3e401c8a9daef44f2681d527f86b
1388Impacket_Tools_psexecCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE002228094a299d2fd9a38a5ebee4e8a9
1389Impacket_Tools_rpcdumpCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE7e7a35ee6029c30299b6975278e407c8
1390Impacket_Tools_secretsdumpCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE8949ccb9e0a4e7f0a3a71f9b374bdb52
1391Impacket_Tools_smbexecCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE4b15ba763aee4a637c946c50161e95cf
1392Impacket_Tools_smbrelayxCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE9e99d921d1b8c832d88041da447c3089
1393Impacket_Tools_smbtortureCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE9999e1f8392c0e05f54d846b3a6a458f
1394Impacket_Tools_sniffCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE6aafe17062bcf2aaa3f5dd5e9cdbd1a1
1395Impacket_Tools_snifferCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILEd057a3d9f361df652943973e264c2526
1396Impacket_Tools_tracerCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILEa9160c997fbd60d2a45987a30d56b968
1397Impacket_Tools_wmiexecCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILEf9cbdb578991f08080256653d6606f83
1398Impacket_Tools_wmipersistCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILEa74782085f2f6709e64ac5e99b402551
1399Impacket_Tools_wmiqueryCompiled Impacket Toolshttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE965594c199c2279f786f8b76539e07cb
1400Imphash_Malware_2_TA17_293ADetects malware based on Imphash of malware used in TA17-293Ahttps://www.us-cert.gov/ncas/alerts/TA17-293A2017-10-21 00:00:0075Florian RothEXE,FILE,MAL16fbc1efbb567029ac6c5d41a6e1b7b0
1401Imphash_UPX_Packed_Malware_1_TA17_293ADetects malware based on Imphash of malware used in TA17-293Ahttps://www.us-cert.gov/ncas/alerts/TA17-293A2017-10-21 00:00:0075Florian RothEXE,FILE,MALf46a879344bf8363971337532a15b20c
1402Indetectables_RATDetects Indetectables RAT based on strings found in research by Paul Rascagneres & Ronan Mouchouxhttp://www.sekoia.fr/blog/when-a-brazilian-string-smells-bad/2015-10-01 00:00:0075Florian RothEXE,FILE,MAL38e427f07be5fb2a53844f0b6de008e9
1403Industroyer_Malware_1Detects Industroyer related malwarehttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian RothEXE,FILE,MAL3966d7bde9684b2e7f9545d6f419f55b
1404Industroyer_Malware_2Detects Industroyer related malwarehttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian RothEXE,FILE,MAL6149b4f102b3e49c8c09b1548cbc97fd
1405Industroyer_Malware_4Detects Industroyer related malwarehttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian RothEXE,FILE,MALde708439171fb45cddb5e3eeef7d373a
1406Industroyer_Malware_5Detects Industroyer related malwarehttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian RothEXE,FILE,MAL29d80ef09b2ed59741953462e6f50a90
1407Industroyer_Portscan_3Detects Industroyer related custom port scanerhttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian RothEXE,FILEce1b1e4b41117d92ba4e449478a45b82
1408Industroyer_Portscan_3_OutputDetects Industroyer related custom port scaner output filehttps://goo.gl/x81cSy2017-06-13 00:00:0075Florian Roth71a54e0dd41891a6722de498635e35b2
1409InjectionParametersChinese Hacktool Set - file InjectionParameters.vbhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL26a053e1abd98fb72563cdd675624229
1410InstGinaDisclosed hacktool set (old stuff) - file InstGina.exe-2014-11-23 00:00:0060Florian RothHKTL9c3bbc25ead31913bd57abb3f0bd5a55
1411Invoke_MetasploitDetects Invoke-Metasploit Payloadhttps://github.com/jaredhaight/Invoke-MetasploitPayload/blob/master/Invoke-MetasploitPayload.ps12017-09-23 00:00:0075Florian RothHKTL,METASPLOIT72b357bde2605ade189a08a08e4a350d
1412Invoke_MimikatzDetects Invoke-Mimikatz Stringhttps://github.com/clymb3r/PowerShell/tree/master/Invoke-Mimikatz2016-08-03 00:00:0075Florian Roth0fa508a3ba50e082c0ca194319a5e9de
1413Invoke_OSiRisOsiris Device Guard Bypass - file Invoke-OSiRis.ps1Internal Research2017-03-27 00:00:0075Florian Roth9a8436277af07f6ad501e8784ccedfe8
1414Invoke_PSImageDetects a command to execute PowerShell from Stringhttps://github.com/peewpw/Invoke-PSImage2017-12-16 00:00:0075Florian RothSCRIPTfa87ad2742d0232286d64da0b74c8371
1415Invoke_SMBExecDetects Invoke-WmiExec or Invoke-SmbExechttps://github.com/Kevin-Robertson/Invoke-TheHash2017-06-14 00:00:0075Florian Rotha2e4a70fd04d68b87334e43737e46318
1416Invoke_SMBExec_Invoke_WMIExec_1Auto-generated rule - from files Invoke-SMBExec.ps1, Invoke-WMIExec.ps1https://github.com/Kevin-Robertson/Invoke-TheHash2017-06-14 00:00:0075Florian Roth029645dc82fd3fae36789635e19def06
1417Invoke_WMIExec_GenAuto-generated rule - from files Invoke-SMBClient.ps1, Invoke-SMBExec.ps1, Invoke-WMIExec.ps1, Invoke-WMIExec.ps1https://github.com/Kevin-Robertson/Invoke-TheHash2017-06-14 00:00:0075Florian RothGEN001e9c94c3e51137b38e6211cf602a27
1418Invoke_WMIExec_Gen_1Detects Invoke-WmiExec or Invoke-SmbExechttps://github.com/Kevin-Robertson/Invoke-TheHash2017-06-14 00:00:0075Florian RothGEN976960adf81103acb127599a8a4a26f5
1419Invoke_mimikittenzDetects Mimikittenz - file Invoke-mimikittenz.ps1https://github.com/putterpanda/mimikittenz2016-07-19 00:00:0090Florian RothFILEad7ae071e1bd371cda7dde6b8e825f10
1420IronGate_APT_Step7ProSim_GenDetects IronGate APT Malware - Step7ProSim DLLhttps://goo.gl/Mr6M2J2016-06-04 00:00:0090Florian RothAPT,EXE,FILE,GEN,MAL38328b3f4797da32e1acfc1e2928e927
1421IronGate_PyInstaller_update_EXEDetects a PyInstaller file named update.exe as mentioned in the IronGate APThttps://goo.gl/Mr6M2J2016-06-04 00:00:0060Florian RothAPT,EXE,FILE8667f454f4c05442ab6e5a122f650b1a
1422IronPanda_DNSTunClientIron Panda malware DnsTunClient - file named.exehttps://goo.gl/E4qia92015-09-16 00:00:0080Florian RothCHINA,EXE,FILE08b505078c843ba1db1837e0f25c410a
1423IronPanda_Malware1Iron Panda Malwarehttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,EXE,FILE,MAL11de9f582ba4d3d6694c5ca9555194b7
1424IronPanda_Malware2Iron Panda Malwarehttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,EXE,FILE,MAL478523e2ee451a9a7344f36da5341f4b
1425IronPanda_Malware3Iron Panda Malwarehttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,EXE,FILE,MALbfa3859a2f065f646a5f15a603204572
1426IronPanda_Malware4Iron Panda Malwarehttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,EXE,FILE,MAL8673cb97d8ab4266fec94f56deb2025c
1427IronPanda_Malware_HtranIron Panda Malware Htranhttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,EXE,FILE,MALb38b00ef7f406bb84097167a2512cdd1
1428IronPanda_Webshell_JSPIron Panda Malware JSPhttps://goo.gl/E4qia92015-09-16 00:00:0075Florian RothCHINA,MAL,WEBSHELL5b4b7c61818bc8ad0b7ee6d4cd4a7f7f
1429IronTiger_ASPXSpyASPXSpy detection. It might be used by other fraudstershttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend Micro567f1e4f0656f6a944a1176bc28df52a
1430IronTiger_ChangePort_Toolkit_ChangePortExeIron Tiger Malware - Toolkit ChangePorthttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL10c2f63a9609edbdc0210ea9db527377
1431IronTiger_ChangePort_Toolkit_driversinstallIron Tiger Malware - Changeport Toolkit driverinstallhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL18a6e50c1df7d3b25734ba0755796db8
1432IronTiger_EFH3_encoderIron Tiger EFH3 Encoderhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIAf732e241ea4fe85f8c3771e63a8f56ec
1433IronTiger_GTalk_TrojanIron Tiger Malware - GTalk Trojanhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL33b8b7b9d5d6f6670fec37b4a8ab98ea
1434IronTiger_GetPassword_x64Iron Tiger Malware - GetPassword x64http://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL6ae7de7140982363cf322180222cdc52
1435IronTiger_Gh0stRAT_variantThis is a detection for a s.exe variant seen in Op. Iron Tigerhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,EXTVAR,FILE,INDIA62bb6185fe78522f126be78226b78add
1436IronTiger_HTTP_SOCKS_Proxy_soexeIron Tiger Toolset - HTTP SOCKS Proxy soexehttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,HKTL,INDIA7054a58e81065405f247dfe385511c35
1437IronTiger_NBDDos_Gh0stvariant_dropperIron Tiger Malware - NBDDos Gh0stvariant Dropperhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL1dd38542e223729f1986336fe40e2d4e
1438IronTiger_PlugX_DosEmulatorIron Tiger Malware - PlugX DosEmulatorhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL29f8c003348899cddf4b1c4ca5906433
1439IronTiger_PlugX_FastProxyIron Tiger Malware - PlugX FastProxyhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,HKTL,INDIA,MALecaa9b0f19db4e9cf57069c032a09341
1440IronTiger_PlugX_ServerIron Tiger Malware - PlugX Serverhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MALd4b7b10e258dbec974b25a69165b2cfd
1441IronTiger_ReadPWD86Iron Tiger Malware - ReadPWD86http://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MALed58c1de9179e94e76c337089abbfdc4
1442IronTiger_Ring_Gh0stvariantIron Tiger Malware - Ring Gh0stvarianthttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIA,MAL8ed27ccf524f238e77d4d78a16c83af0
1443IronTiger_dllshellexc2010dllshellexc2010 Exchange backdoor + remote shellhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,MAL95332a7027afc7250f264b4001943d70
1444IronTiger_dnstunnelThis rule detects a dns tunnel tool used in Operation Iron Tigerhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroEXE,FILE,INDIAa9e32c5e0e5806de9dc374dfaeb4698c
1445IronTiger_wmiexecIron Tiger Tool - wmi.vbs detectionhttp://goo.gl/T5fSJC1970-01-01 01:00:0075Cyber Safety Solutions, Trend MicroINDIA1591d900e86fc64549b7cfeadc7d5a19
1446IsDebug_V1_4Chinese Hacktool Set - file IsDebug V1.4.dllhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL09baee3cc82c025d555eeb732f6a5cf4
1447IsmDoor_Jul17_A2Detects IsmDoor Malwarehttps://twitter.com/Voulnet/status/8921047532951101452017-08-01 00:00:0075Florian RothEXE,FILE,MAL9024aa46fadddce3072104f6013837ac
1448JSP_Browser_APT_webshellVonLoesch JSP Browser used as web shell by APT groups - jsp File browser 1.1a-2014-10-10 00:00:0060Florian RothAPT,WEBSHELL97c14840d47a91ac80bcb5dbd6f82dee
1449JSP_jfigueiredo_APT_webshellJSP Browser used as web shell by APT groups - author: jfigueiredohttp://ceso.googlecode.com/svn/web/bko/filemanager/Browser.jsp2014-12-10 00:00:0060Florian RothAPT,WEBSHELL6996bd4798b7bda37d584339f2c5597a
1450JSP_jfigueiredo_APT_webshell_2JSP Browser used as web shell by APT groups - author: jfigueiredohttp://ceso.googlecode.com/svn/web/bko/filemanager/2014-12-10 00:00:0060Florian RothAPT,WEBSHELL2b0f1798ac5409b6a4a997e7a24ac11d
1451JS_Suspicious_MSHTA_BypassDetects MSHTA Bypasshttps://twitter.com/ItsReallyNick/status/8877051052393431042017-07-19 00:00:0070Florian RothSCRIPT781d13a8c9fdb4c1996a825754adff4a
1452JS_Suspicious_Obfuscation_DropboxDetects PowerShell AMSI Bypasshttps://twitter.com/ItsReallyNick/status/8877051052393431042017-07-19 00:00:0070Florian RothOBFUS,SCRIPT69550be03dd4caa9cade2b6e4a570dec
1453JavaScript_Run_SuspiciousDetects a suspicious Javascript Run commandhttps://twitter.com/craiu/status/9003140635609989122017-08-23 00:00:0060Florian RothSCRIPTd05dcd536febf6738cf028f84fa59284
1454Java_Shell_jsSemi-Auto-generated - file Java Shell.js.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL628ac0a54ad99c19e1d1329d1563e04f
1455Jc_ALL_WinEggDropShell_rar_Folder_Install_2Disclosed hacktool set (old stuff) - file Install.exe-2014-11-23 00:00:0060Florian RothHKTL1c949099eccee4e1dbd7fae80dc0d479
1456Jc_WinEggDrop_ShellDisclosed hacktool set (old stuff) - file Jc.WinEggDrop Shell.txt-2014-11-23 00:00:0060Florian RothHKTLa759fcb1522707e516395d8faff1e84c
1457JspWebshell_1_2_jspSemi-Auto-generated - file JspWebshell 1.2.jsp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLffb152623a412aedd48df3343bc1ac79
1458KA_uShellWebshells Auto-generated - file KA_uShell.php-1970-01-01 01:00:0075Florian RothWEBSHELL0458e512995804b4b6d6e31fa7ea7972
1459KHRAT_MalwareDetects an Imphash of KHRAT malwarehttps://researchcenter.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/2017-08-31 00:00:0075Florian RothEXE,FILE,MALd38075a1976cb952026e204015620408
1460KINS_DLL_zeusMatch default bot in KINS leaked dropper, Zeushttp://goo.gl/arPhm31970-01-01 01:00:0075AlienVault Labs aortega@alienvault.com785bbfbec966d1c2070045078e1b4204
1461KINS_dropperMatch protocol, process injects and windows exploit present in KINS dropperhttp://goo.gl/arPhm31970-01-01 01:00:0075AlienVault Labs aortega@alienvault.comad9d4d7c38f4ec21fe75b95fa16f106e
1462KR_Target_Malware_Aug17Detects malware that targeted South Korea in Aug 2017 - file MRDqsbuEqGxrgqtbXU.exehttps://twitter.com/eyalsela/status/9002502030973542402017-08-23 00:00:0075Florian RothEXE,FILE,MAL39fd33487a3106781f0a7858ba15dbad
1463KasperMalware_Oct17_1Detects Kasper BackdoorInternal Research2017-10-24 00:00:0075Florian RothEXE,FILE,MALc0ce02ce76760d2dd96578f688af2822
1464KeeTheft_EXEDetects component of KeeTheft - KeePass dump tool - file KeeTheft.exehttps://github.com/HarmJ0y/KeeThief2017-08-29 00:00:0075Florian RothEXE,FILE,HKTL023264599ccf314f19c3679624433716
1465KeeTheft_Out_ShellcodeDetects component of KeeTheft - KeePass dump tool - file Out-Shellcode.ps1https://github.com/HarmJ0y/KeeThief2017-08-29 00:00:0075Florian RothHKTLd24c08205aa10b61f058be56607f5409
1466KeeThief_PSDetects component of KeeTheft - KeePass dump tool - file KeeThief.ps1https://github.com/HarmJ0y/KeeThief2017-08-29 00:00:0075Florian RothFILE,HKTL1dfd6e704652d62558024be4ae61c0bc
1467Kekeo_HacktoolDetects Kekeo Hacktoolhttps://github.com/gentilkiwi/kekeo/releases2017-07-21 00:00:0075Florian RothEXE,FILE,HKTLe20502f7bd7ff67ecd64a55da07a2448
1468KeyBoy_876_0x4e20000Detects KeyBoy Backdoorhttps://blog.trendmicro.com/trendlabs-security-intelligence/tropic-trooper-new-strategy/2018-03-26 00:00:0075Markus Neis, Florian RothEXE,FILE,MALa6cfcbf0019c12adcff8b635b065c966
1469KeyBoy_InstallClientDetects KeyBoy InstallClienthttps://blog.trendmicro.com/trendlabs-security-intelligence/tropic-trooper-new-strategy/2018-03-26 00:00:0075Markus Neis, Florian RothEXE,FILE88df7bec01a7632c0587ceb2d201877b
1470KeyBoy_rasautoDetects KeyBoy ServiceClienthttps://blog.trendmicro.com/trendlabs-security-intelligence/tropic-trooper-new-strategy/2018-03-26 00:00:0075Markus Neis, Florian RothEXE,FILEbbea488b3e42de4a6d271ba0729b1f8e
1471KeyBoy_wab32resDetects KeyBoy Loader wab32res.dllhttps://blog.trendmicro.com/trendlabs-security-intelligence/tropic-trooper-new-strategy/2018-03-26 00:00:0075Markus Neis, Florian RothEXE,FILE8521077ff91451e4f60b6c25d52b49b1
1472KeyBoys_malware_1Detects Keyboys malwarehttp://www.pwc.co.uk/issues/cyber-security-data-privacy/research/the-keyboys-are-back-in-town.html2017-11-02 00:00:0075Florian RothEXE,FILE71450a89b02038c7ffb91077547782fd
1473Keylogger_CN_APTKeylogger - generic rule for a Chinese variant-2016-03-07 00:00:0075Florian RothAPT,CHINA,EXE,FILE,HKTLc280d93bc11d106aa6f7bb009c8f4c4d
1474KiwiTaskmgr_2Chinese Hacktool Set - file KiwiTaskmgr.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLf5c086692a803e535d33536be101ebd5
1475Korplug_FASTRule to detect Korplug/PlugX FAST variant-2015-08-20 00:00:0075Florian RothEXE,FILEfff9eaa3006bd9326cdc446f0b2c4c40
1476Kraken_Bot_SampleKraken Bot Sample - file inf.binhttps://blog.gdatasoftware.com/blog/article/dissecting-the-kraken.html2015-05-07 00:00:0090Florian RothEXE,FILEc0df53d1c30a9f0ada1afddd2232503b
1477Kriskynote_Mar17_1Detects Kriskynote MalwareInternal Research2017-03-03 00:00:0075Florian RothEXE,FILE,MALec66b7b2721175e1a8d474682f096e11
1478Kriskynote_Mar17_2Detects Kriskynote MalwareInternal Research2017-03-03 00:00:0075Florian RothEXE,FILE,MAL705712e6a5f5456013df0117ebbe5912
1479Kriskynote_Mar17_3Detects Kriskynote MalwareInternal Research2017-03-03 00:00:0075Florian RothEXE,FILE,MAL328ed08b0e7ef903be7d95db642d402c
1480LNK_Malicious_Nov1Detects a suspicious LNK filehttps://www.virustotal.com/en/file/ee069edc46a18698fa99b6d2204895e6a516af1a306ea986a798b178f289ecd6/analysis/2017-11-06 00:00:0060Florian RothFILEe1f4aa99cddc9346e7f704fd5727438c
1481Laudanum_Tools_GenericLaudanum Injector Toolshttp://laudanum.inguardians.com/2015-06-22 00:00:0075Florian RothGEN,HKTL,WEBSHELL53ef2b76836889b4db91fd2bd73873ea
1482Lazagne_PW_DumperDetects Lazagne PW Dumperhttps://github.com/AlessandroZ/LaZagne/releases/2018-03-22 00:00:0070Markus Neis / Florian RothHKTLd474972f183e90b1502f6a95f2eec61b
1483Lazarus_Dec_17_1Detects Lazarus malware from incident in Dec 2017https://goo.gl/8U6fY22017-12-20 00:00:0075Florian RothFILE,NK88b9ff00d315152b02486a1cc2bf6cbb
1484Lazarus_Dec_17_2Detects Lazarus malware from incident in Dec 2017https://goo.gl/8U6fY22017-12-20 00:00:0075Florian RothEXE,FILE,NK565f5b81028a9aafd2cba6ae1131289b
1485Lazarus_Dec_17_4Detects Lazarus malware from incident in Dec 2017ithumb.jshttps://goo.gl/8U6fY22017-12-20 00:00:0075Florian RothNK7b9f0eddc2f513deeef53671876616f9
1486Lazarus_Dec_17_5Detects Lazarus malware from incident in Dec 2017https://goo.gl/8U6fY22017-12-20 00:00:0075Florian RothNK313deaf84e4012c6d9aef4cfcc783830
1487Leviathan_CobaltStrike_Sample_1Detects Cobalt Strike sample from Leviathan reporthttps://goo.gl/MZ7dRg2017-10-18 00:00:0075Florian RothEXE,FILEfcb16c7097fd700ecbf53244e561baa4
1488LightFTP_ConfigDetects a light FTP server - config filehttps://github.com/hfiref0x/LightFTP2015-05-14 00:00:0075Florian RothFILE92708cf17ba51fe1329532890b470896
1489LightFTP_fftp_x86_64Detects a light FTP serverhttps://github.com/hfiref0x/LightFTP2015-05-14 00:00:0050Florian RothEXE,FILEadb6da1a73776148193cc66184a329f3
1490LinuxHacktool_eyes_aLinux hack tools - file anot set2015-01-19 00:00:0075Florian RothHKTL,LINUXce6d21d7c5d0d460e898f74a8ea750d0
1491LinuxHacktool_eyes_massLinux hack tools - file massnot set2015-01-19 00:00:0075Florian RothHKTL,LINUX0a890ad2583d081e9b0b69f2e1f2500b
1492LinuxHacktool_eyes_pscan2Linux hack tools - file pscan2not set2015-01-19 00:00:0075Florian RothHKTL,LINUX038e54d10f23af15056e7a125f7f7e6a
1493LinuxHacktool_eyes_pscan2_2Linux hack tools - file pscan2.cnot set2015-01-19 00:00:0075Florian RothHKTL,LINUX8bdb7093c18e08b9383d1668b5101f14
1494LinuxHacktool_eyes_scansshLinux hack tools - file scansshnot set2015-01-19 00:00:0075Florian RothHKTL,LINUX917a32d3c57b75125b85e6953321861d
1495Linux_Portscan_Shark_1Detects Linux Port Scanner SharkVirustotal Research - see https://github.com/Neo23x0/Loki/issues/352016-04-01 00:00:0075Florian RothFILE,HKTL,LINUX29d6a12c0f9f85963c4e16e93176304b
1496Linux_Portscan_Shark_2Detects Linux Port Scanner SharkVirustotal Research - see https://github.com/Neo23x0/Loki/issues/352016-04-01 00:00:0075Florian RothHKTL,LINUX81d8156f2c9c785c8ab94ed5ec81404e
1497LiuDoor_Malware_1Liudoor Trojan used in Terracotta APThttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/2015-08-04 00:00:0070Florian RothAPT,EXE,FILE,MAL4b853827f50229be8d533e1e2bcbd2b4
1498LiuDoor_Malware_2Liudoor Trojan used in Terracotta APThttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/2015-08-04 00:00:0070Florian RothAPT,EXE,FILE,MAL8abecb543f4eb5fe0af9df843fdcf68e
1499Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_Exploit_phpSemi-Auto-generated - file Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLa56ad941ebd1bcd6996fe8f856e8140e
1500Locky_RansomwareDetects Locky Ransomware (matches also on Win32/Kuluoz)https://goo.gl/qScSrE2016-02-17 00:00:0075Florian Roth (with the help of binar.ly)CRIME,MAL,RANSOMdc3aac29a8446becf5b60b4943fd491a
1501LokiBot_Dropper_Packed_R11_Feb18Auto-generated rule - file scan copy.pdf.r11https://app.any.run/tasks/401df4d9-098b-4fd0-86e0-7a52ce6ddbf52018-02-14 00:00:0075Florian RothFILE,MAL0a940418920de069813e9b22e0d61056
1502LokiBot_Dropper_ScanCopyPDF_Feb18Auto-generated rule - file Scan Copy.pdf.comhttps://app.any.run/tasks/401df4d9-098b-4fd0-86e0-7a52ce6ddbf52018-02-14 00:00:0075Florian RothEXE,FILE,MALfe9c3814d17893126261d25e0749c8c6
1503MAL_APT_Operation_ShadowHammer_MalSetupDetects a malicious file used by BARIUM group in Operation ShadowHammerhttps://securelist.com/operation-shadowhammer/89992/2019-03-25 00:00:0080Florian RothAPT,EXE,FILE16d118342fa17f6c23faab87a32b1d3d
1504MAL_AirdViper_Sample_Apr18_1Detects Arid Viper malware sampleInternal Research2018-05-04 00:00:0075Florian RothEXE,FILE,MIDDLE_EASTa3b09a463ab2bdcfe778e6d55856c74b
1505MAL_BackNet_Nov18_1Detects BackNet sampleshttps://github.com/valsov/BackNet2018-11-02 00:00:0075Florian RothEXE,FILE2d0c731b8abd59f6d91fa31412ec6ea5
1506MAL_BurningUmbrella_Sample_10Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE658870bf26737675844b2a3bccf387d6
1507MAL_BurningUmbrella_Sample_11Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothFILE69afaca58ccf27456c8ef44b173e4d08
1508MAL_BurningUmbrella_Sample_12Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE5fe6c422dfc8fa02b01be7b774f34256
1509MAL_BurningUmbrella_Sample_13Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEbbb081fb951dc8ac72d7b2a1362b199c
1510MAL_BurningUmbrella_Sample_14Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE5d753222adbc97c18c25414108ca6604
1511MAL_BurningUmbrella_Sample_15Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE07d846366bd5aeb95c60366d46263d41
1512MAL_BurningUmbrella_Sample_16Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEa865d4418e209dd111e300d738bc4298
1513MAL_BurningUmbrella_Sample_17Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE050d629779c91d397321d07f41625374
1514MAL_BurningUmbrella_Sample_18Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEbddf113c4b8fe5d618b32e4194cbdcbf
1515MAL_BurningUmbrella_Sample_19Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEe1030c17aefa7bb1944c95dacd03eaac
1516MAL_BurningUmbrella_Sample_1Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEbdbf80b5431a5baa6eb44e9b0a22bab0
1517MAL_BurningUmbrella_Sample_20Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEf5fd49c2de9e3a74d3c4257d1c34dc80
1518MAL_BurningUmbrella_Sample_21Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE417a1c1b3da72756687419512131114e
1519MAL_BurningUmbrella_Sample_22Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE3c8bcbddb3dc7f12dbf45f4ad73307a3
1520MAL_BurningUmbrella_Sample_2Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE3690db10a9e00a260a0e762adfd50404
1521MAL_BurningUmbrella_Sample_3Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEbb77559a3a161cbfff79e8bcd6a0bfce
1522MAL_BurningUmbrella_Sample_4Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE2f499349fbd85f3855aef0f29fe176ee
1523MAL_BurningUmbrella_Sample_6Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE2b26bc328fd1bfb10ed764147b049d71
1524MAL_BurningUmbrella_Sample_7Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILEffa6386e333fffa03aa83a01747f86b7
1525MAL_BurningUmbrella_Sample_8Detects malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE04da79743f549ff8d1bcf6ee9387eb12
1526MAL_CMD_Script_Obfuscated_Feb19_1Detects obfuscated batch script using env variable sub-stringshttps://twitter.com/DbgShell/status/11010764571897937932019-03-01 00:00:0075Florian RothFILE,OBFUS76fca7c0f6a35400aa98006c132d25e8
1527MAL_CN_FlyStudio_May18_1Detects malware / hacktool detected in May 2018Internal Research2018-05-11 00:00:0075Florian RothEXE,FILE152b3c8cfe35e0fbd19a940bf0f865b7
1528MAL_CrypRAT_Jan19_1Detects CrypRATInternal Research2019-01-07 00:00:0090Florian RothEXE,FILE,MALe5edbfef12bb6a7862c06c4ce24e4880
1529MAL_DNSPIONAGE_Malware_Nov18Detects DNSpionage Malwarehttps://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html2018-11-30 00:00:0075Florian RothEXE,FILE,MALf9d4ad6ed17a2803c455f800d3a3911f
1530MAL_ELF_LNX_Mirai_Oct10_1Detects ELF Mirai variantInternal Research2018-10-27 00:00:0075Florian RothFILE,LINUX9fe2b35f9d6fb9d5dc551cf0fb8b3a67
1531MAL_ELF_LNX_Mirai_Oct10_2Detects ELF malware Mirai relatedInternal Research2018-10-27 00:00:0075Florian RothFILE,LINUX9756cdae9051814bc60387f787d49b29
1532MAL_ELF_VPNFilter_1Detects VPNFilter malwareInternal Research2018-05-24 00:00:0075Florian RothFILE,LINUXa1cbbc394bb8b1c191528d1ca90ff6bf
1533MAL_ELF_VPNFilter_2Detects VPNFilter malwareInternal Research2018-05-24 00:00:0075Florian RothFILE,LINUX67a6647e5aa45a28c218543894e850a4
1534MAL_ELF_VPNFilter_3Detects VPNFilter malwareInternal Research2018-05-24 00:00:0075Florian RothFILE,LINUX3f63d2e28e130f444f94ee54da2e0dc8
1535MAL_Envrial_Jan18_1Detects Encrial credential stealer malwarehttps://twitter.com/malwrhunterteam/status/9533135146298531842018-01-21 00:00:0075Florian RothEXE,FILE1473f2906f2cce3c353426b7c6aae93f
1536MAL_ExileRAT_Feb19_1Detects Exile RAThttps://blog.talosintelligence.com/2019/02/exilerat-shares-c2-with-luckycat.html2019-02-04 00:00:0075Florian RothEXE,FILE,MAL3ee4049b2bccf3722f4339f58aeb5362
1537MAL_Floxif_GenericDetects Floxif MalwareInternal Research2018-05-11 00:00:0080Florian RothEXE,FILE,GEN,MAL06599060e22f16a5eb20403b471a4409
1538MAL_GandCrab_Apr18_1Detects GandCrab malwarehttps://twitter.com/MarceloRivero/status/9884555160945500172018-04-23 00:00:0075Florian RothEXE,FILEa1cb3694dd0b06edac068fbf74a401ab
1539MAL_HawkEye_Keylogger_Gen_Dec18Detects HawkEye Keylogger Rebornhttps://twitter.com/James_inthe_box/status/10721162246523248702018-12-10 00:00:0075Florian RothGEN,HKTLe5ec95cb11e0a5f57689fcc76cb13173
1540MAL_Hogfish_Report_Related_SampleDetects APT10 / Hogfish related sampleshttps://www.accenture.com/t20180423T055005Z__w__/se-en/_acnmedia/PDF-76/Accenture-Hogfish-Threat-Analysis.pdf2018-05-01 00:00:0075Florian RothAPT,CHINA,EXE,FILEd6d4b5dff8b5f73cf6fc3e0bcd275e7e
1541MAL_JRAT_Oct18_1Detects JRAT malwareInternal Research2018-10-11 00:00:0075Florian RothFILE,MAL75f6c0c536703a47f30a2bc9445afa45
1542MAL_KHRAT_scriptRule derived from KHRAT script but can match on other malicious scripts as wellhttps://researchcenter.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/2017-08-31 00:00:0075Florian RothMAL841f1d94ddfa2b3051ea257b62ebe105
1543MAL_KHRAT_scritpletRule derived from KHRAT scriptlethttps://researchcenter.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/2017-08-31 00:00:0075Florian RothFILE,MAL7ba86301cf6f3e46c20740f3a8333ed1
1544MAL_Kwampirs_Apr18Kwampirs dropper and main payload componentshttps://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia2018-04-23 00:00:0075Symantec49aa486e152e9680f0743294813e8679
1545MAL_LNX_SSHDOOR_TritonSignature detecting https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf2018-12-05 00:00:0075Marc-Etienne M.Leveille, modified by Florian RothFILE,LINUX956fded15ceb060dc3ecc659afdd9de0
1546MAL_Metasploit_Framework_UADetects User Agent used in Metasploit Frameworkhttps://github.com/rapid7/metasploit-framework/commit/12a6d67be48527f5d3987e40cac2a0cbb4ab6ce72018-08-16 00:00:0065Florian RothEXE,FILE,METASPLOIT71d7054c6f564e1de62cfc38f42f8460
1547MAL_MuddyWater_DroppedTask_Jun18_1Detects a dropped Windows task as used by MudyWater in June 2018https://app.any.run/tasks/719c94eb-0a00-47cc-b583-ad4f9e25ebdb2018-06-12 00:00:0075Florian RothFILEdb7175839835bc2e29e54302454f21fb
1548MAL_Nitol_Malware_Jan19_1Detects Nitol Malwarehttps://twitter.com/shotgunner101/status/10846024136911667212019-01-14 00:00:0075Florian RothEXE,FILE,MAL01b1214e73903837f2c8e5f6fd2e608d
1549MAL_OSX_FancyBear_Agent_Jul18_1Detects FancyBear Agent for OSXhttps://twitter.com/DrunkBinary/status/10184488950540984322018-07-15 00:00:0075Florian RothFILE,MACOS,RUSSIA92f1b3d05e41b9dd965ea61bfe645e20
1550MAL_PE_Type_BabyShark_LoaderDetects PE Type babyShark loader mentioned in February 2019 blog post by PaloAltNetworkshttps://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/2019-02-24 00:00:0075Florian RothEXE,EXTVAR,FILE2e0971cffdf5e336ae6fdb789d120e0f
1551MAL_RTF_Embedded_OLE_PEDetects a suspicious string often used in PE files in a hex encoded object streamhttps://www.nextron-systems.com/2018/01/22/creating-yara-rules-detect-embedded-exe-files-ole-objects/2018-01-22 00:00:0075Florian RothFILE589f28952cd825e33d7ff1d1c1772eb4
1552MAL_RedLeaves_Apr18_1Detects RedLeaves malwarehttps://www.accenture.com/t20180423T055005Z__w__/se-en/_acnmedia/PDF-76/Accenture-Hogfish-Threat-Analysis.pdf2018-05-01 00:00:0075Florian RothEXE,FILEa05436e491e372d19b16cbca108eb57b
1553MAL_Ryuk_RansomwareDetects strings known from Ryuk Ransomwarehttps://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/2018-12-31 00:00:0075Florian RothCRIME,EXE,FILE,MAL,RANSOM98701b4936d6ae65267b023e00bdb632
1554MAL_Sednit_DelphiDownloader_Apr18_2Detects malware from Sednit Delphi Downloader reporthttps://www.welivesecurity.com/2018/04/24/sednit-update-analysis-zebrocy/2018-04-24 00:00:0075Florian Roth2ab1a68fe94fd35dacc9f58542381fd1
1555MAL_Sednit_DelphiDownloader_Apr18_3Detects malware from Sednit Delphi Downloader reporthttps://www.welivesecurity.com/2018/04/24/sednit-update-analysis-zebrocy/2018-04-24 00:00:0075Florian RothEXE,FILE4ad0bced1f4e34cc8e8f9ea2de2753cc
1556MAL_Turla_Agent_BTZDetects Turla Agent.BTZhttps://www.gdatasoftware.com/blog/2014/11/23937-the-uroburos-case-new-sophisticated-rat-identified2018-04-12 00:00:0075Florian RothEXE,FILE,RUSSIAd4738ae9524e241647acf057010693ab
1557MAL_Turla_Sample_May18_1Detects Turla sampleshttps://twitter.com/omri9741/status/9919420077015982082018-05-03 00:00:0075Florian RothEXE,FILE,RUSSIA6d0ba27773679cbf2fc67f5821a7f666
1558MAL_Unknown_PWDumper_Apr18_3Detects sample from unknown sample set - IL originInternal Research2018-04-06 00:00:0075Florian RothEXE,FILE,HKTL6509d5231679ceeb1222a264a95f6093
1559MAL_Visel_Sample_May18_1Detects Visel malware sample from Burning Umbrella reporthttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothEXE,FILE3df895c601e021b54890e18c8707549c
1560MAL_WebMonitor_RATDetects WebMonitor RAThttps://researchcenter.paloaltonetworks.com/2018/04/unit42-say-cheese-webmonitor-rat-comes-c2-service-c2aas/2018-04-13 00:00:0075Florian RothEXE,FILE,MAL25e54e9f05a7c11521dcc9a884f8855b
1561MAL_Winnti_Sample_May18_1Detects malware sample from Burning Umbrella report - Generic Winnti Rulehttps://401trg.pw/burning-umbrella/2018-05-04 00:00:0075Florian RothCHINA,EXE,FILE,GENeb999bc4b55a5487d3737e3362bfb272
1562MAL_Xbash_JS_Sep18Detects XBash malwarehttps://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/2018-09-18 00:00:0075Florian RothFILEfadb40b08eb743e0f151e99bc5b5045b
1563MAL_Xbash_PY_Sep18Detects Xbash malwarehttps://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/2018-09-18 00:00:0075Florian RothFILEcdc1944ecbd9d229ffb66027e029f9b5
1564MAL_Xbash_SH_Sep18Detects Xbash malwarehttps://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/2018-09-18 00:00:0075Florian RothFILEa1d2fa5cf9289ef93a69c9f7a1ed4198
1565MAL_unspecified_Jan18_1Detects unspecified malware sampleInternal Research2018-01-19 00:00:0075Florian RothMAL53a088f662a88b8cbf6faa5c620a75f5
1566ME_Campaign_Malware_1Detects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0075Florian RothEXE,FILE,MALec6583f6d6d6876d34d35e4a61c6ac59
1567ME_Campaign_Malware_2Detects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0075Florian RothEXE,FILE,MALb5cc325864903b8976a636cecf3ca7fd
1568ME_Campaign_Malware_3Detects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0075Florian RothFILE,MAL9dd6ca5777d2d584cf595a3c5567416e
1569ME_Campaign_Malware_4Detects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0075Florian RothEXE,FILE,MALddbc49108a4b4aa4f3ff6064e4503f91
1570ME_Campaign_Malware_5Detects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0075Florian RothEXE,FILE,MAL1a4405d9e838d5ba0fa547a5eed3ffe5
1571MS08_067_Exploit_Hacktools_CNDisclosed hacktool set - file cs.exe-2014-11-17 00:00:0060Florian RothHKTL21d169fddabd9e593fdff9b00219f909
1572MSBuild_Mimikatz_Execution_via_XMLDetects an XML that executes Mimikatz on an endpoint via MSBuildhttps://gist.github.com/subTee/c98f7d005683e616560bda3286b6a0d8#file-katz-xml2016-10-07 00:00:0075Florian RothHKTLd4c5affa1be7d808bc30775b3baa0125
1573MSSqlPassChinese Hacktool Set - file MSSqlPass.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLc7ad5dbde500ec1c2961ba2f217ff6b4
1574Mal_Dropper_httpEXE_from_CABDetects a dropper from a CAB file mentioned in the articlehttps://goo.gl/13Wgy12016-05-25 00:00:0060Florian RothEXE,FILE,MAL3493b2b3d6eb9886c1f28b7f60935d68
1575Mal_PotPlayer_DLLDetects a malicious PotPlayer.dllhttps://goo.gl/13Wgy12016-05-25 00:00:0070Florian RothEXE,FILEed81a39d085b61d1a2ec6ff8dbb03c60
1576Mal_http_EXEDetects trojan from APT report named http.exehttps://goo.gl/13Wgy12016-05-25 00:00:0080Florian RothAPT,EXE,FILEe9d09cae1326861c54399c3893e87ba6
1577Malicious_BAT_StringsDetects a string also used in Netwire RAT auxilliaryhttps://pastebin.com/8qaiyPxs2018-01-05 00:00:0060Florian RothMAL6d73f24f709bda8388f8972fdd3a196f
1578Malicious_SFX1SFX with voicemail contenthttp://www.kernelmode.info/forum/viewtopic.php?f=16&t=39502015-07-20 00:00:0075Florian RothFILEd88d47919b0ee26a0ffbed2a56558725
1579Malicious_SFX2SFX with adobe.exe contenthttp://www.kernelmode.info/forum/viewtopic.php?f=16&t=39502015-07-20 00:00:0075Florian RothEXE,FILE38ad418f21b5b45e0929a2efe232ddb3
1580Malware_Floxif_mpsvc_dllMalware - FloxifInternal Research2017-04-07 00:00:0075Florian RothEXE,FILE,MAL1b12342c5f193d0105cd3b3c6b11111d
1581Malware_JS_powershell_obfuscatedUnspecified malware - file rechnung_3.jsInternal Research2017-03-24 00:00:0075Florian RothMAL,OBFUSd05457605a9bbca34711f5ef85f5858c
1582Malware_MsUpdater_String_in_EXEMSUpdater String in ExecutableVT Analysis2015-06-03 00:00:0050Florian RothEXE,FILE,MAL66f32a4600929b84ebcfffc8a06d1f2d
1583Malware_QA_1177VT Research QA uploaded malware - file 1177.vbsVT Research QA2016-08-29 00:00:0080Florian RothFILE,MAL26deb049d1fff4920697923d81970553
1584Malware_QA_get_The_FucKinG_IPVT Research QA uploaded malware - file get The FucKinG IP.exeVT Research QA2016-08-29 00:00:0080Florian RothEXE,FILE,MAL64d9ad3382c32ecfa570297dd6609fd2
1585Malware_QA_not_copyVT Research QA uploaded malware - file not copy.exeVT Research QA2016-08-29 00:00:0080Florian RothEXE,FILE,MAL6d288671603d06b96c868787895533f1
1586Malware_QA_tlsVT Research QA uploaded malware - file tls.exeVT Research QA2016-08-29 00:00:0080Florian RothEXE,FILE,MALd1a91cac10548e7a6cc189137ae584ad
1587Malware_QA_updateVT Research QA uploaded malware - file update.exeVT Research QA2016-08-29 00:00:0080Florian RothEXE,FILE,MAL44e4e17251d3eabbb5c7c8265ecaf65d
1588Malware_QA_update_testVT Research QA uploaded malware - file update_.exeVT Research QA2016-08-29 00:00:0080Florian RothEXE,EXTVAR,FILE,MALd1abdc9a8641e7ef123090d3312c7834
1589Malware_QA_vqgkVT Research QA uploaded malware - file vqgk.dllVT Research QA2016-08-29 00:00:0080Florian RothEXE,FILE,MAL9f2b5b9bb991f4d5bdbb4ab8229627ce
1590MarathonToolChinese Hacktool Set - file MarathonTool.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL3e74d8fbab426bbbc6aa0f101865f7bd
1591MarathonTool_2Chinese Hacktool Set - file MarathonTool.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL37cd7001e0a4b6f496edbbfaa67ce64b
1592Metasploit_Loader_RSMudgeDetects a Metasploit Loader by RSMudge - file loader.exehttps://github.com/rsmudge/metasploit-loader2016-04-20 00:00:0075Florian RothEXE,FILE,METASPLOIT7fd97b5f0691841e958b7c484768cad5
1593Methodology_Artificial_UserAgent_IE_Win7Looking for hard-coded User-Agent string that has been present in *several* APT37 and suspected APT37 malware families. Lots of DPRK activity. Someone is re-using code, or perhaps some mal dev has a favorite. This will also catch a boatload of other stuff.-1970-01-01 01:00:0075Steve Miller aka @stvemillertimeAPT,FILE48b45a2303731a0e1b8fbb39882ecc55
1594Miari_2_May17Detects Mirai MalwareInternal Research2017-05-12 00:00:0075Florian RothFILE,MAL2cb0aafa06ccb1aa700af48af986162e
1595Microcin_Sample_1Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MALddb59d0e95372a286d4f0a90a2977b0e
1596Microcin_Sample_2Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MAL769582e6a23cbd98bbb5dcd2cee02886
1597Microcin_Sample_3Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MAL8b1ed923e2af62b48d9a1f125b3ba6d6
1598Microcin_Sample_4Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MAL209d1ef4592bbd03d1a00b3027bde864
1599Microcin_Sample_5Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MALc484413923079b10b50bd7468b051582
1600Microcin_Sample_6Malware sample mentioned in Microcin technical report by Kasperskyhttps://securelist.com/files/2017/09/Microcin_Technical-PDF_eng_final.pdf2017-09-26 00:00:0075Florian RothEXE,FILE,MAL4cf718c5de310c200208af11294f0486
1601Mimikatz_Gen_StringsDetects Mimikatz by using some special stringsInternal Research2017-06-19 00:00:0075Florian RothEXE,FILE,GEN,HKTL6d80063795e5abedb4128385bd79657b
1602Mimikatz_LogfileDetects a log file generated by malicious hack tool mimikatz-2015-03-31 00:00:0080Florian RothHKTL2a1be474c623d0d66444c261b0b0921e
1603Mimikatz_Memory_Rule_1Detects password dumper mimikatz in memory-2014-12-22 00:00:0070Florian RothHKTLfd99b65577446908d8ffa120bdd59756
1604Mimikatz_Memory_Rule_2Mimikatz Rule generated from a memory dump-1970-01-01 01:00:0080Florian Roth - Florian RothHKTL964d12c0ec6e0144aae80b8854fbe2aa
1605Mimikatz_StringsDetects Mimikatz stringsnot set2016-06-08 00:00:0065Florian RothEXE,FILE,HKTL0165b2978a56e010701eca3c26d75e16
1606Mimipenguin_SHDetects Mimipenguin Password Extractor - Linuxhttps://github.com/huntergregal/mimipenguin2017-04-01 00:00:0075Florian RothLINUX785b65fe34483abb839b943a6beac08f
1607MiniDionis_VBS_DroppedDropped File - 1.vbshttps://malwr.com/analysis/ZDc4ZmIyZDI4MTVjNGY5NWI0YzE3YjIzNGFjZTcyYTY/2015-07-21 00:00:0075Florian RothSCRIPT5e62ce472990e8ce732a51c25ee364b1
1608MiniDionis_readerViewMiniDionis Malware - file readerView.exe / adobe.exehttp://www.kernelmode.info/forum/viewtopic.php?f=16&t=39502015-07-20 00:00:0075Florian RothEXE,FILE,MALaa49afd0998b8fa048f32605c352581c
1609MiniDumpTest_msdscAuto-generated rule - file msdsc.exehttps://github.com/giMini/RWMC/2015-08-31 00:00:0075Florian RothEXE,FILE40e0fd2960618c6f508e49d8f0d93fd8
1610MiniRAT_Gen_1Detects Mini RAT malwarehttps://www.eff.org/deeplinks/2018/01/dark-caracal-good-news-and-bad-news2018-01-22 00:00:0075Florian RothEXE,FILE,GEN,MAL10c17d5bd8b17f889a95d1f820379e60
1611Mirai_1_May17Detects Mirai MalwareInternal Research2017-05-12 00:00:0075Florian RothFILE,MAL53074ec45242535a8b3d844800d7209a
1612Mirai_Botnet_MalwareDetects Mirai Botnet MalwareInternal Research2016-10-04 00:00:0075Florian RothFILE,MALcdf11e88016230b4fd2b45690857b63f
1613Mithozhan_TrojanMitozhan Trojan used in APT Terracottahttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/2015-08-04 00:00:0070Florian RothAPT,EXE,FILE,MALa95ab8a8d33cb65a1e2d95eb0d085c61
1614Mithril_MithrilWebshells Auto-generated - file Mithril.exe-1970-01-01 01:00:0075Florian RothWEBSHELL3618525f638a57dfe94a22ba3a321b51
1615Mithril_dllTestWebshells Auto-generated - file dllTest.dll-1970-01-01 01:00:0075Florian RothWEBSHELLff145d80a1f1668c37357f4951a00ae5
1616Mithril_v1_45_MithrilWebshells Auto-generated - file Mithril.exe-1970-01-01 01:00:0075Florian RothWEBSHELL54122329edaa79eb20a0d48ed025527b
1617Mithril_v1_45_dllTestWebshells Auto-generated - file dllTest.dll-1970-01-01 01:00:0075Florian RothWEBSHELL8c223b3b37630d22ce3d1f9526bb7b60
1618MockDll_GenDetects MockDll - regsvr DLL loaderhttps://goo.gl/MZ7dRg2017-10-18 00:00:0075Florian RothEXE,FILE,GEN0c4a1759c9d121f5ed77bf35c280a424
1619Molerats_Jul17_Sample_1Detects Molerats sample - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian RothEXE,FILE3117cbf745781fbe3c26bbfdf53cbf98
1620Molerats_Jul17_Sample_2Detects Molerats sample - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian RothEXE,FILE16a2418c27160a53343f97099d256e4a
1621Molerats_Jul17_Sample_3Detects Molerats sample - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian RothEXE,FILEb5747f67d12cbcb2a2a045682b624f9d
1622Molerats_Jul17_Sample_4Detects Molerats sample - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian Rothb4dbd8f8f1b0eb0219e0e9ae65b3c358
1623Molerats_Jul17_Sample_5Detects Molerats sample - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian Roth385465559106ad34b2972f6a51e161fc
1624Molerats_Jul17_Sample_DropperDetects Molerats sample dropper SFX - July 2017https://mymalwareparty.blogspot.de/2017/07/operation-desert-eagle.html2017-07-07 00:00:0075Florian RothEXE,FILE,MALad1a843dde919afb56a7c4661b62651f
1625Monsoon_APT_Malware_1Detects malware from Monsoon APThttp://blog.fortinet.com/2017/04/05/in-depth-look-at-new-variant-of-monsoon-apt-backdoor-part-22017-09-08 00:00:0075Florian RothAPT,EXE,FILE,MALb5f04265fadfca8e6c1fe8bbfa43a8fd
1626Monsoon_APT_Malware_2Detects malware from Monsoon APThttp://blog.fortinet.com/2017/04/05/in-depth-look-at-new-variant-of-monsoon-apt-backdoor-part-22017-09-08 00:00:0075Florian RothAPT,EXE,FILE,MALa1e08ce4a31a1b6cf48df08f261611b8
1627MooreR_Port_ScannerAuto-generated rule on file MooreR Port Scanner.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLe8a0331b3bcf64192e0fdc7db45b1cbb
1628Moroccan_Spamers_Ma_EditioN_By_GhOsT_phpSemi-Auto-generated - file Moroccan Spamers Ma-EditioN By GhOsT.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL12dc695f065eb9f1299976585e7ef5ce
1629Ms_Viru_racleChinese Hacktool Set - file racle.dllhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL7dbcaf614f7d01a4122dba7248ce5d4d
1630Ms_Viru_vChinese Hacktool Set - file v.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLbb8eba7b37c2c8d4e3e81d4fa5cdc640
1631Msfpayloads_msfMetasploit Payloads - file msf.shInternal Research2017-02-09 00:00:0075Florian RothFILE,METASPLOIT57e9bfbac53f7fae5dad3db0a7a5d118
1632Msfpayloads_msf_10Metasploit Payloads - file msf.exeInternal Research2017-02-09 00:00:0075Florian RothEXE,FILE,METASPLOITa78d9893c06526720770fbd1beebd552
1633Msfpayloads_msf_11Metasploit Payloads - file msf.htaInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT18131350f6e32055b0a01b7c58bfb8ee
1634Msfpayloads_msf_2Metasploit Payloads - file msf.aspInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT0a1985221b1cde5f82316b437f462add
1635Msfpayloads_msf_3Metasploit Payloads - file msf.pshInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT3a43f75fbb94c831f1c54baa3466648c
1636Msfpayloads_msf_4Metasploit Payloads - file msf.aspxInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT9bc51f4c650cc6c870049ee0cfd32b39
1637Msfpayloads_msf_5Metasploit Payloads - file msf.msiInternal Research2017-02-09 00:00:0075Florian RothMETASPLOITb0163f00481568d8bffe86061521e6df
1638Msfpayloads_msf_6Metasploit Payloads - file msf.vbsInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT175e63063471242fa838634ceed72911
1639Msfpayloads_msf_7Metasploit Payloads - file msf.vbaInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT7c79766669369184f5c83d2cc661fd07
1640Msfpayloads_msf_8Metasploit Payloads - file msf.ps1Internal Research2017-02-09 00:00:0075Florian RothMETASPLOIT2e765466ba0bb3c1c4199f02ad6d2a11
1641Msfpayloads_msf_9Metasploit Payloads - file msf.war - contentsInternal Research2017-02-09 00:00:0075Florian RothFILE,METASPLOIT00a136ef60d7bf67940d0546a6f3102d
1642Msfpayloads_msf_cmdMetasploit Payloads - file msf-cmd.ps1Internal Research2017-02-09 00:00:0075Florian RothMETASPLOITb691fa04a573b4b59d1f92827649e6a5
1643Msfpayloads_msf_exeMetasploit Payloads - file msf-exe.vbaInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT66c4082681535a7bfc5d528eedc737fa
1644Msfpayloads_msf_exe_2Metasploit Payloads - file msf-exe.aspxInternal Research2017-02-09 00:00:0075Florian RothMETASPLOITcbddf03027b5588e6652a30585761c8d
1645Msfpayloads_msf_pshMetasploit Payloads - file msf-psh.vbaInternal Research2017-02-09 00:00:0075Florian RothMETASPLOIT849cac7bcbe4f186fad7c19c982faf8f
1646Msfpayloads_msf_refMetasploit Payloads - file msf-ref.ps1Internal Research2017-02-09 00:00:0075Florian RothMETASPLOIT8226d4e88ddffb51f8fd9722dfdf1bef
1647Msfpayloads_msf_svcMetasploit Payloads - file msf-svc.exeInternal Research2017-02-09 00:00:0075Florian RothEXE,FILE,METASPLOIT2f22d6c0722499ad261e9a77b4b3a1a5
1648MuddyWater_Mal_Doc_Feb18_1Detects malicious document used by MuddyWaterInternal Research - TI2T2018-02-26 00:00:0075Florian RothFILE,MIDDLE_EAST65b44ffc1dd6af4c8e33554c92f3e976
1649MuddyWater_Mal_Doc_Feb18_2Detects malicious document used by MuddyWaterInternal Research - TI2T2018-02-26 00:00:0075Florian RothFILE,MIDDLE_EASTa7ca4dcae7f011a0b66df15815fc0db1
1650MySQL_Web_Interface_Version_0_8_phpSemi-Auto-generated - file MySQL Web Interface Version 0.8.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL977b02aa1312a21c3cadbb2ee55f6b50
1651MyWScript_CompiledScriptDetects a scripte with default name Mywscript compiled with Script2Exe (can also be a McAfee tool https://community.mcafee.com/docs/DOC-4124)Internal Research2017-07-27 00:00:0065Florian RothEXE,FILEadab66b1a9b5bd9f71e48373e73d0725
1652NK_Miner_Malware_Jan18_1Detects Noth Korean Monero Miner mentioned in AlienVault reporthttps://goo.gl/PChE1z2018-01-09 00:00:0075Florian Roth (original rule by Chris Doman)EXE,FILE,MAL94faaf399c450181bfb25b5d9b3a1876
1653NTLM_Dump_OutputNTML Hash Dump output file - John/LC format-2015-10-01 00:00:0075Florian RothHKTL8b88b6407f128061ea31fe5e9c23befb
1654NT_Addy_aspSemi-Auto-generated - file NT Addy.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL4f5a456f4dc71d4cdc97d23dc5700e2d
1655Nanocore_RAT_Feb18_1Detects Nanocore RATInternal Research - T2T2018-02-19 00:00:0075Florian RothEXE,FILE,MAL8a0692ead01eb2443c63e8f9465fb41d
1656Nanocore_RAT_Feb18_2Detects Nanocore RATInternal Research - T2T2018-02-19 00:00:0075Florian RothEXE,FILE,MALec22f3fcb9f9df23bee3964998dba62d
1657Nanocore_RAT_Gen_1Detetcs the Nanocore RAT and similar malwarehttps://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/2016-04-22 00:00:0070Florian RothEXE,FILE,GEN,MAL1d44bd69611502109445fdb9cccc8efb
1658Nanocore_RAT_Gen_2Detetcs the Nanocore RAThttps://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/2016-04-22 00:00:00100Florian RothEXE,FILE,GEN,MAL8b5b2a28922b321f712b16b015e7ddcc
1659Nanocore_RAT_Sample_1Detetcs a certain Nanocore RAT samplehttps://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/2016-04-22 00:00:0075Florian RothEXE,FILE,MAL270c2c31cd35fd6398cd09e2dabbc237
1660Nanocore_RAT_Sample_2Detetcs a certain Nanocore RAT samplehttps://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/2016-04-22 00:00:0075Florian RothEXE,FILE,MAL62a7f1be90637b5b379c15b38bb89b52
1661Nautilus_common_stringsRule for detection of Nautilus based on common plaintext stringshttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0075NCSC UKFILEa508ff2539b80ebad58525c1945250fa
1662Nautilus_forensic_artificatsRule for detection of Nautilus related stringshttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0060NCSC UK / Florian Rothce79b8fda4014dbfd77365db92bd3593
1663Nautilus_modified_rc4_loopRule for detection of Nautilus based on assembly code for a modified RC4 loophttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0075NCSC UKFILE4a75739d13de9bb72831e3de77aa4eec
1664Nautilus_rc4_keyRule for detection of Nautilus based on a hardcoded RC4 keyhttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0075NCSC UKFILEe52d35afefd614943bb9a52766b04edf
1665Ncat_Hacktools_CNDisclosed hacktool set - file nc.exe-2014-11-17 00:00:0060Florian RothHKTL6a9b2c9817938897114cba763717e615
1666NcrackThis signature detects the Ncrack brute force tool-2014-07-06 00:00:0060Florian RothHKTL04c1aa622882a460c8dbc8b58180f540
1667NetBIOS_Name_ScannerAuto-generated rule on file NetBIOS Name Scanner.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL47b535d5740e272c7324152bb91a361b
1668Netview_HacktoolNetwork domain enumeration tool - often used by attackers - file Nv.exehttps://github.com/mubix/netview2016-03-07 00:00:0060Florian RothEXE,FILE,HKTLeb916b9ac4ed7885cf74f06a032b5a7f
1669Netview_Hacktool_OutputNetwork domain enumeration tool output - often used by attackers - file filename.txthttps://github.com/mubix/netview2016-03-07 00:00:0060Florian RothHKTL405ac58333a54ffe4cc8096f59324875
1670Neuron_common_stringsRule for detection of Neuron based on commonly used stringshttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0075NCSC UKFILE588116fce379be192335fab5ce1437af
1671Neuron_standalone_signatureRule for detection of Neuron based on a standalone signature from .NET metadatahttps://www.ncsc.gov.uk/alerts/turla-group-malware2017-11-23 00:00:0075NCSC UKFILE0c145e722abc8359ef460d0dd6456959
1672Nirsoft_NetResViewDetects NirSoft NetResView - utility that displays the list of all network resourceshttps://goo.gl/Mr6M2J2016-06-04 00:00:0040Florian RothEXE,FILEaaef31c5a2b2ac01bee6baff3b4a32c5
1673Nishang_WebshellDetects a ASPX web shellhttps://github.com/samratashok/nishang2016-09-11 00:00:0075Florian RothFILE,WEBSHELLfef1549a4535398f6d462156d8145681
1674No_PowerShellDetects an C# executable used to circumvent PowerShell detection - file nps.exehttps://github.com/Ben0xA/nps2016-05-21 00:00:0080Florian RothEXE,FILE,SCRIPT7c5f8a8641ec50d3b18f5d1c8a26cf7c
1675NotPetya_Ransomware_Jun17Detects new NotPetya Ransomware variant from June 2017https://goo.gl/h6iaGj2017-06-27 00:00:0075Florian RothCRIME,EXE,FILE,MAL,RANSOM56e424166ceac048d264f950d1ecf6ac
1676Nshell__1__php_phpSemi-Auto-generated - file Nshell (1).php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL0e7abfec3b95f99de72767fb87180fc8
1677NtGodModeChinese Hacktool Set - file NtGodMode.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL245d5fe8bfa6e3f206861182b9557aa2
1678ONHAT_Proxy_HacktoolDetects ONHAT Proxy - Htran like SOCKS hack tool used by Chinese APT groupshttps://goo.gl/p32Ozf2016-05-12 00:00:00100Florian RothAPT,CHINA,EXE,FILE,HKTLc72f98f56c4f3ccff76f40884458872c
1679OPCLEAVER_BackDoorLoggerKeylogger used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.HKTL5961272363f70a3a905feeca3d33b27c
1680OPCLEAVER_CCProxy_ConfigCCProxy config known from Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Florian RothHKTL70e7f408a1fe6d4601704818a46b7acc
1681OPCLEAVER_JasusARP cache poisoner used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.65037b109409c58451e8319b8188870f
1682OPCLEAVER_LoggerModuleKeylogger used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.HKTL5555aeb091bb68ed60d0565c83161a26
1683OPCLEAVER_NetCNet Crawler used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.f282e4874ce9f2036926ca195300dc58
1684OPCLEAVER_Parviz_DeveloperParviz developer known from Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Florian Rothd698b18bd3ecd3a53b2248580d6d22a7
1685OPCLEAVER_ShellCreator2Shell Creator used by attackers in Operation Cleaver to create ASPX web shellshttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.444ab20d3c11df6405dd3e20f3b1d64f
1686OPCLEAVER_SmartCopy2Malware or hack tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.MAL2c6609c9413ee5d0bcc3146b54688153
1687OPCLEAVER_SynFlooderMalware or hack tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.MAL330ca286e142bd7cb13207d4f1b18c16
1688OPCLEAVER_TinyZBotTiny Bot used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.986083a8f488dbbf494ce94cea1bd75f
1689OPCLEAVER_ZhoupinExploitCrewKeywords used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.8f6c4dd0eb69874f9e43f439904f46e7
1690OPCLEAVER_antivirusdetectorHack tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.d9e971817d28aea965f47ee79a921ac3
1691OPCLEAVER_csextBackdoor used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.MAL35e7d940d93c8945bc8d1b17b92ee830
1692OPCLEAVER_kagentBackdoor used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.MALa5599868ea28b2ad37173040dcb0ded6
1693OPCLEAVER_mimikatzWrapperMimikatz Wrapper used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.61253dc40a7c86a26c13f2e8ac9236ce
1694OPCLEAVER_pvz_inParviz tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.891595a159c750da8c769cc307430147
1695OPCLEAVER_pvz_outParviz tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.6f777926a5ddc320034e2ae8f8bbeab8
1696OPCLEAVER_wndTestBackdoor used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.MAL74c34f0c3a6adfaee5ffe51988306e19
1697OPCLEAVER_zhCatNetwork tool used by Iranian hackers and used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.370656ef831cd7dd769d802b52de585c
1698OPCLEAVER_zhLookUpHack tool used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.73bd56ad6be5a8f3a307b642e27adf15
1699OPCLEAVER_zhmimikatzMimikatz wrapper used by attackers in Operation Cleaverhttp://cylance.com/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf2014-12-02 00:00:0070Cylance Inc.7a7be9c298ac0d131c15ba0d4e969bee
1700OSEditorChinese Hacktool Set - file OSEditor.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL899d8d35b0f3bc57aab85736c6f2d2b7
1701OSX_backdoor_BellaBella MacOS/OSX backdoorhttps://twitter.com/JohnLaTwC/status/9119987771829248012018-02-23 00:00:0075John Lambert @JohnLaTwCEXTVAR,FILE,MACOS,MAL5e593a214895460e5c77272e2dd8b40c
1702OSX_backdoor_EvilOSXEvilOSX MacOS/OSX backdoorhttps://github.com/Marten4n6/EvilOSX, https://twitter.com/JohnLaTwC/status/9661393364364984322018-02-23 00:00:0075John Lambert @JohnLaTwCFILE,MACOS,MAL5776524475279ccf95d39895231813e6
1703Obfuscated_JS_April17Detects cloaked Mimikatz in JS obfuscationInternal Research2017-04-21 00:00:0075Florian RothOBFUSe892bbc03e16003dbd2a4f03072d14ea
1704Obfuscated_VBS_April17Detects cloaked Mimikatz in VBS obfuscationInternal Research2017-04-21 00:00:0075Florian RothOBFUS,SCRIPT9a4ac4427e4c37041a7cd8c4d50ac346
1705Office_AutoOpen_MacroDetects an Microsoft Office file that contains the AutoOpen Macro function-2015-05-28 00:00:0040Florian RothFILE,OFFICE13819a16fa65389b83765def5d6c1cc4
1706Office_OLE_DDEDetects DDE in MS Office documentshttps://blog.nviso.be/2017/10/11/detecting-dde-in-ms-office-documents/2017-10-12 00:00:0050NVISO LabsFILE,OFFICE77ec120990cef678c372d1da97c271ea
1707Office_OLE_DDEAUTODetects DDE in MS Office documentshttps://blog.nviso.be/2017/10/11/detecting-dde-in-ms-office-documents/2017-10-12 00:00:0050NVISO LabsFILE,OFFICE11a3d08f3f65fc6319e534d56ad97724
1708Office_as_MHTMLDetects an Microsoft Office saved as a MHTML file (false positives are possible but raremany matches on CVE-2012-0158)https://www.trustwave.com/Resources/SpiderLabs-Blog/Malicious-Macros-Evades-Detection-by-Using-Unusual-File-Format/2015-05-28 00:00:0040Florian RothEXPLOIT,FILE,OFFICEa47ac19f2730b502def9be6d62e39efe
1709OilRig_Campaign_ReconnaissanceDetects Windows discovery commands - known from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothMIDDLE_EASTf56454047e0f36c902c3042b1d4172fa
1710OilRig_ISMAgent_Campaign_Samples1Detects OilRig malware from Unit 42 report in October 2017https://goo.gl/JQVfFP2017-10-18 00:00:0075Florian RothFILE,MIDDLE_EAST7b036ceda3addf668d6ec6ffbf3b54b2
1711OilRig_ISMAgent_Campaign_Samples2Detects OilRig malware from Unit 42 report in October 2017https://goo.gl/JQVfFP2017-10-18 00:00:0075Florian RothEXE,FILE,MIDDLE_EAST266f86b0829436fd5044ab1baf2f43fe
1712OilRig_ISMAgent_Campaign_Samples3Detects OilRig malware from Unit 42 report in October 2017https://goo.gl/JQVfFP2017-10-18 00:00:0075Florian RothEXE,FILE,MIDDLE_EAST50424b217ff47bf5c8aeedbf608dae7d
1713OilRig_Malware_Campaign_Gen1Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothFILE,MAL,MIDDLE_EAST788971385547af133d4d96ca27960542
1714OilRig_Malware_Campaign_Gen2Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothFILE,MAL,MIDDLE_EASTc7f9296f17a6a0430cb8241710d087be
1715OilRig_Malware_Campaign_Gen3Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothFILE,MAL,MIDDLE_EAST4bc22b3706ea97d9c7595593992d42ca
1716OilRig_Malware_Campaign_Mal1Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothFILE,MAL,MIDDLE_EAST372845575cc930b00047895bb84b63b1
1717OilRig_Malware_Campaign_Mal2Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothFILE,MAL,MIDDLE_EASTcc98308704253795b0e7a32beba8ddf0
1718OilRig_Malware_Campaign_Mal3Detects malware from OilRig Campaignhttps://goo.gl/QMRZ8K2016-10-12 00:00:0075Florian RothMAL,MIDDLE_EAST154c682bec6a9b548bf9620f0d4753ad
1719OilRig_Malware_Nov17_13-https://twitter.com/ClearskySec/status/9332801887330181132017-11-22 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EAST029d2c887abf23646b20946ecda132b9
1720OilRig_RGDoor_Gen1Detects RGDoor backdoor used by OilRig grouphttps://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/2018-01-27 00:00:0080Florian RothEXE,FILE,MAL,MIDDLE_EASTf72630c8f1a8e723a45bae8f51d740e1
1721OilRig_Strings_Oct17Detects strings from OilRig malware and malicious scriptshttps://researchcenter.paloaltonetworks.com/2017/10/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/2017-10-18 00:00:0075Florian RothMIDDLE_EAST079ee4f1e4bcee26ccf04e7975722404
1722Oilrig_IntelSecurityManagerDetects OilRig malwareInternal Research2018-01-19 00:00:0075Eyal SelaMIDDLE_EASTa03f43832286f79c3512ef3c1d79233b
1723Oilrig_IntelSecurityManager_macroDetects OilRig malwareInternal Research2018-01-19 00:00:0075Eyal Sela (slightly modified by Florian Roth)MIDDLE_EAST5b2ed3874ded9d393cf74de48377b2e0
1724Oilrig_MyrtilleDetects Oilrig Myrtille RDP Browserhttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Markus NeisEXE,FILE035870b67960f2d791242558e3a53232
1725Oilrig_PS_CnCPowershell CnC using DNS querieshttps://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018b.pdf2018-03-22 00:00:0075Markus Neis48df4a66976b9a04bc0476b50f39cebe
1726OlympicDestroyer_Gen2Detects Olympic Destroyer malwarehttp://blog.talosintelligence.com/2018/02/olympic-destroyer.html2018-02-12 00:00:0075Florian RothEXE,FILE019f7cd4eb025b029cc70805cad64fdd
1727OpCloudHopper_Cloaked_PSCPTool used in Operation Cloud Hopper - pscp.exe cloaked as rundll32.exehttps://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf2017-04-07 00:00:0090Florian RothEXTVARc885e3eabce842a35890f26466486e1f
1728OpCloudHopper_Dropper_1Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothFILE,MAL66cbf1ca6034281bd4a2d41cfad77e6e
1729OpCloudHopper_Malware_10Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MALf3e97e4cfea6022bf6bc04baf92e2c37
1730OpCloudHopper_Malware_11Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL3aacef22ab991eeabe19f7e942693555
1731OpCloudHopper_Malware_1Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL08f288ce233e219281ac8b265490a245
1732OpCloudHopper_Malware_2Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL79f6ff8f9b71f6233940482c6ee63e44
1733OpCloudHopper_Malware_3Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL64351c6dd480246e11350e2830d19786
1734OpCloudHopper_Malware_4Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL97d09c2ed24f2fb653d89024e236025e
1735OpCloudHopper_Malware_5Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL815087a5f3a5afe8fbbfddeb6cf74518
1736OpCloudHopper_Malware_6Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MALe789ada4588167076c0e469cc060848a
1737OpCloudHopper_Malware_7Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL678f3f18f923ed6b3f5b95dbd7de3dbe
1738OpCloudHopper_Malware_8Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MALa16665107e7c555f4d75a918f5d1ab9d
1739OpCloudHopper_Malware_9Detects malware from Operation Cloud Hopperhttps://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL6ed723e16c1600f41c8d676d212b0f95
1740OpCloudHopper_WindowXarBotMalware related to Operation Cloud Hopperhttps://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf2017-04-07 00:00:0075Florian RothEXE,FILE,MAL9d87d471cea4b438d4b9a25c0dddd4f4
1741OpCloudHopper_WmiDLL_inMemoryMalware related to Operation Cloud Hopper - Page 25https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf2017-04-07 00:00:0075Florian RothMAL23943bd8750e354dd929bb361314f22b
1742OpCloudHopper_lockdownTools related to Operation Cloud Hopperhttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothEXE,FILE1df60a216615f2c98713ffea3bc753c4
1743OpHoneybee_Malware_1Detects malware from Operation Honeybeehttps://goo.gl/JAHZVL2018-03-03 00:00:0075Florian RothEXE,FILE,MAL7881e4978955201f7067ebb33092360a
1744OpHoneybee_MaoCheng_DropperDetects MaoCheng dropper from Operation Honeybeehttps://goo.gl/JAHZVL2018-03-03 00:00:0075Florian RothEXE,FILE,MALfd9c0d962db7d2f3b5b12cbf4ce75855
1745OracleScanChinese Hacktool Set - file OracleScan.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL01fc7202c8185d8b75dcb658c4d6007d
1746OtherTools_servuChinese Hacktool Set - file svu.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,FILE,HKTLe387f9e7347d0de0822e8fd3d156951b
1747OtherTools_xiaoaChinese Hacktool Set - file xiaoa.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL41971ab200b4fa8b5267ffebd2d0fcde
1748PAS_TOOL_PHP_WEB_KIT_modDetects PAS Tool PHP Web Kithttps://www.us-cert.gov/security-publications/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity2016-12-29 00:00:0075US CERT - modified by Florian Roth due to performance reasonsFILEd72b2590fda4c2097da981c53d5b79a6
1749PAS_Webshell_EncodedDetects a PAS webshellhttp://blog.talosintelligence.com/2017/07/the-medoc-connection.html2017-07-11 00:00:0080Florian RothFILE,WEBSHELL2f5087998fe89b4d66b7b135e331d0a3
1750PHANTASMA_phpSemi-Auto-generated - file PHANTASMA.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL8781c37ea5ee5b11297183f4e1e49c92
1751PHISH_02Dez2015_attach_P_ORD_C_10156_124658Phishing Wave - file P-ORD-C-10156-124658.xlshttp://myonlinesecurity.co.uk/purchase-order-124658-gina-harrowell-clinimed-limited-word-doc-or-excel-xls-spreadsheet-malware/2015-12-02 00:00:0075Florian RothFILE30f1eeeb7c829fd96e997e3ae2eefb22
1752PHISH_02Dez2015_dropped_p0o6543f_1Phishing Wave - file p0o6543f.exehttp://myonlinesecurity.co.uk/purchase-order-124658-gina-harrowell-clinimed-limited-word-doc-or-excel-xls-spreadsheet-malware/2015-12-02 00:00:0075Florian RothEXE,FILE0b2a712598e2c8d0c6c21a90374cd526
1753PHISH_02Dez2015_dropped_p0o6543f_2Phishing Wave used MineExplorer Game by WangLei - file p0o6543f.exe.4http://myonlinesecurity.co.uk/purchase-order-124658-gina-harrowell-clinimed-limited-word-doc-or-excel-xls-spreadsheet-malware/2015-12-03 00:00:0075Florian RothEXE,FILE8e2911a66ed33108156beebd0b06c7c1
1754PHP_Backdoor_Connect_pl_phpSemi-Auto-generated - file PHP Backdoor Connect.pl.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsMAL,WEBSHELLfbca35ed7b99876d07d33b1cd0fff20f
1755PHP_Backdoor_v1Webshells Auto-generated - file PHP Backdoor v1.php-1970-01-01 01:00:0075Florian RothMAL,WEBSHELLbacfcf30031b1374cd49f6941b27b911
1756PHP_Cloaked_Webshell_SuperFetchExecLooks like a webshell cloaked as GIF - http://goo.gl/xFvioChttp://goo.gl/xFvioC1970-01-01 01:00:0050Florian RothWEBSHELLd9f9f957b8bce16eaaf687bd0492f572
1757PHP_Shell_php_phpSemi-Auto-generated - file PHP Shell.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLfcab692cf40bfa5b9b34bfc5acc607ad
1758PHP_Shell_v1_7Webshells Auto-generated - file PHP_Shell_v1.7.php-1970-01-01 01:00:0075Florian RothWEBSHELL4399cb043cee4ec15d754eee6766f8d1
1759PHP_Webshell_1_Feb17Detects a simple cloaked PHP web shellhttps://isc.sans.edu/diary/Analysis+of+a+Simple+PHP+Backdoor/221272017-02-28 00:00:0075Florian RothFILE,WEBSHELL98f18922ec97f38f644303d7ee88d6b9
1760PHP_shWebshells Auto-generated - file sh.php-1970-01-01 01:00:0075Florian RothWEBSHELL284e497c974e16baf96aa66c5e1fbbd9
1761PHP_shellWebshells Auto-generated - file shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL536b736dfadf97fca2f3a273de76ed36
1762PLEAD_Downloader_Jun18_1Detects PLEAD Downloaderhttps://blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blacktech.html2018-06-16 00:00:0075Florian RothEXE,FILEc66f744e3361c17f8d1e12089bd50d22
1763PLUGIN_AJunkChinese Hacktool Set - file AJunk.dllhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLcbb7d3c13f165f5deb097645aee32601
1764PLUGIN_TracKidChinese Hacktool Set - file TracKid.dllhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL07c843cd7cb3d204ec77bf685ccca9c5
1765PLUGX_RedLeavesDetects specific RedLeaves and PlugX binarieshttps://www.us-cert.gov/ncas/alerts/TA17-117A2017-03-04 00:00:0075US-CERT Code Analysis Teamf9312c938f41e7cd499a5dbb92bd3fdf
1766POSHSPY_MalwareDetectshttps://www.fireeye.com/blog/threat-research/2017/03/dissecting_one_ofap.html2017-07-15 00:00:0075Florian RothMAL292ea6f1302c1c620e5ffaf985a42971
1767PP_CN_APT_ZeroT_1Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILE3c16bb1ee78537806593f1d726ecf845
1768PP_CN_APT_ZeroT_2Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILE22bb723f64a52be1d67c1d405818f962
1769PP_CN_APT_ZeroT_3Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,FILE2560a8096724033686e67ee343cde409
1770PP_CN_APT_ZeroT_4Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILEcea0317a9ec70b8102b81f51963e0e83
1771PP_CN_APT_ZeroT_5Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,FILEcfe5f435e3a6404aa94cb7ea0f2d763e
1772PP_CN_APT_ZeroT_6Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILEfc006d7b7414f4b287db17c57a1d20d9
1773PP_CN_APT_ZeroT_7Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILE96b2ef6ddaf95435369b722c2a7392d9
1774PP_CN_APT_ZeroT_8Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,FILE9f0df450381784fdca015009e2aac39d
1775PP_CN_APT_ZeroT_9Detects malware from the Proofpoint CN APT ZeroT incidenthttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx2017-02-03 00:00:0075Florian RothAPT,EXE,FILE1adca49046647f85775cc08792fcdf08
1776PROMETHIUM_NEODYMIUM_Malware_1Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MAL2e863fc4a42b49cfa680ca6bd26908f8
1777PROMETHIUM_NEODYMIUM_Malware_2Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MAL357f9ca78dc0fea91b8f128999b43500
1778PROMETHIUM_NEODYMIUM_Malware_3Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MAL7e65cea6ec796e7793e698032345ff29
1779PROMETHIUM_NEODYMIUM_Malware_4Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MAL5080296c45ddb7a3810063298368a3a8
1780PROMETHIUM_NEODYMIUM_Malware_5Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MALefcb13257666203517fa5aa0fafd7174
1781PROMETHIUM_NEODYMIUM_Malware_6Detects PROMETHIUM and NEODYMIUM malwarehttps://goo.gl/8abDE62016-12-14 00:00:0075Florian RothEXE,FILE,MALaccf1556411a9ff00b64aa7da987f1e7
1782PSAttack_EXEPSAttack - Powershell attack tool - file PSAttack.exehttps://github.com/gdssecurity/PSAttack/releases/2016-03-09 00:00:00100Florian RothEXE,FILE,HKTL0f8ebb6ddb2d43b8d08e574400d1100c
1783PSAttack_ZIPPSAttack - Powershell attack tool - file PSAttack.ziphttps://github.com/gdssecurity/PSAttack/releases/2016-03-09 00:00:00100Florian RothFILE,HKTLd6c45386d85d3bb52893dd98f0e6c288
1784PS_AMSI_BypassDetects PowerShell AMSI Bypasshttps://gist.github.com/mattifestation/46d6a2ebb4a1f4f0e7229503dc012ef12017-07-19 00:00:0065Florian RothSCRIPTd95479ddc511fbf2247532be075ec50c
1785PScan_Portscan_1PScan - Port Scanner-1970-01-01 01:00:0050F. RothHKTL7f7a8c433de61dbe899f37401d7a821b
1786PUA_CryptoMiner_Jan19_1Detects Crypto Miner stringsInternal Research2019-01-31 00:00:0075Florian Roth7c46cdd3e29ce0eec3dd617ba817f6cf
1787PUA_LNX_XMRIG_CryptoMinerDetects XMRIG CryptoMiner softwareInternal Research2018-06-28 00:00:0075Florian RothFILE,LINUXdfebb470dadd3e1bfd0b1e1968107000
1788PUP_FancyBear_ComputraceAgentAbsolute Computrace Agent Executablehttps://asert.arbornetworks.com/lojack-becomes-a-double-agent/2018-05-01 00:00:0075ASERT - Arbor Networks (slightly modified by Florian Roth)EXE,FILEc78a790969382a5ef98dad277976cfe4
1789PUP_InstallRex_AntiFWbMalware InstallRex / AntiFW-2015-05-13 00:00:0055Florian RothEXE,FILE,MALa1cd7791e4c3ece7aecf257fccb6b34a
1790Pack_InjectTWebshells Auto-generated - file InjectT.exe-1970-01-01 01:00:0075Florian RothHKTL,WEBSHELL6b47320e79b393f2560584c41c82feba
1791Partial_Implant_IDDetects implant from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSCEXE,FILEa7976cc49a7eba67efc1a72059839d02
1792PassCV_Sabre_Malware_1PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MALdaad0a2ca7c65bc2f8393045ac33b953
1793PassCV_Sabre_Malware_2PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MAL7e21a6349a5874e448ffc2d43c5f19db
1794PassCV_Sabre_Malware_3PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MALebb54c36a25bc08a558985ae076bbcff
1795PassCV_Sabre_Malware_4PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MAL143ff0a4c3219e375a7bb765cfddfec5
1796PassCV_Sabre_Malware_5PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MAL07ac6a98fad12349f0c104d6cafdde63
1797PassCV_Sabre_Malware_Excalibur_1PassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MAL112ec4a29c607785bb7b5c1405b58a36
1798PassCV_Sabre_Malware_Signing_CertPassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0050Florian RothEXE,FILE,MAL9b3e1da1d13ae77c2377533069d006f2
1799PassCV_Sabre_Tool_NTScanPassCV Malware mentioned in Cylance Reporthttps://blog.cylance.com/digitally-signed-malware-targeting-gaming-companies2016-10-20 00:00:0075Florian RothEXE,FILE,MAL496b560f312841437b30fb3896d731c7
1800PassSnifferDisclosed hacktool set (old stuff) - file PassSniffer.exe-2014-11-23 00:00:0060Florian RothHKTL6a4e912de55904c193f877096a7a7ed7
1801PassSniffer_zip_Folder_readmeDisclosed hacktool set (old stuff) - file readme.txt-2014-11-23 00:00:0060Florian RothHKTL43439c6ec6d0fa7211258bd0173288b0
1802PasswordPro_NTLM_DLLAuto-generated rule - file NTLM.dllPasswordPro2017-08-27 00:00:0075Florian RothEXE,FILE,HKTL342a937d9df3dadd0fe5887f4d02d241
1803PasswordReminderWebshells Auto-generated - file PasswordReminder.exe-1970-01-01 01:00:0075Florian RothWEBSHELL6bed9e9c6403073300b020a64a29fca7
1804PasswordsProAuto-generated rule - file PasswordsPro.exePasswordPro2017-08-27 00:00:0075Florian RothEXE,FILE,HKTLc1b3ea81d16beeaee970533cb07a26b9
1805Pastebin_WebshellDetects a web shell that downloads content from pastebin.com http://goo.gl/7dbyZshttp://goo.gl/7dbyZs2015-01-13 00:00:0070Florian RothWEBSHELL25f212d9622c34bc411fd0d94f0978e5
1806Payload_Exe2HexDetects payload generated by exe2hexhttps://github.com/g0tmi1k/exe2hex2016-01-15 00:00:0070Florian Roth707a426b0f3998308db999d34d06e37e
1807Pc_pc2015Chinese Hacktool Set - file pc2015.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL5651cbb54fda28dab576e2de3b614255
1808Pc_rejoiceChinese Hacktool Set - file rejoice.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1690950a8c97ed0ae6fb752094c72562
1809Pc_xaiChinese Hacktool Set - file xai.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd29460bb493b501c962925af4ed4e50b
1810Persistence_Agent_MacOSDetects a Python agent that establishes persistence on macOShttps://ghostbin.com/paste/mz5nf1970-01-01 01:00:0075John Lambert @JohnLaTwCFILE,MACOS,SCRIPTca7e38e44cadc90be6a8ed2153501577
1811PhpShellWebshells Auto-generated - file PhpShell.php-1970-01-01 01:00:0075Florian RothWEBSHELLf30ab4dfe629f32a644b8dc1272147ad
1812Phyton_Shell_pySemi-Auto-generated - file Phyton Shell.py.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL4388daa4cbc7f63d463150b9ce124df3
1813Ping_Command_in_EXEDetects an suspicious ping command execution in an executableInternal Research2016-11-03 00:00:0060Florian RothEXE,FILEa95f24ce64632b83205a8a8f97ff2fcf
1814Pirpi_1609_ADetects Pirpi Backdoor - and other malware (generic rule)http://goo.gl/igxLyF2016-09-08 00:00:0075Florian RothEXE,FILE,MALb4b7e337b1e641c942fcb2c3e910f9ab
1815Pirpi_1609_BDetects Pirpi Backdoorhttp://goo.gl/igxLyF2016-09-08 00:00:0075Florian RothEXE,FILE,MAL37e771945b4ec74ca63c48993a31dc2d
1816PlugX_J16_Gen2Detects PlugX Malware Samples from June 2016VT Research2016-06-08 00:00:0075Florian RothEXE,FILE,MAL83646ed9e41706f8c041b82fed34b529
1817PlugX_J16_GenDetects PlugX Malware samples from June 2016VT Research2016-06-08 00:00:0075Florian RothEXE,FILE,GEN,MAL094d34874121d556cb002e6a43907346
1818PlugX_NvSmartMax_GenThreat Group 3390 APT Sample - PlugX NvSmartMax Generichttp://snip.ly/giNB2015-08-06 00:00:0070Florian RothAPT,EXE,FILE,GENdf2d1bff9a74e9816e1036bbe0e3cca6
1819PoS_Malware_MalumPOSUsed to detect MalumPOS memory dumper-2015-05-25 00:00:0075Trend Micro, Inc.MALbace8b0acb940602c80323e6611563df
1820PoS_Malware_MalumPOS_ConfigMalumPOS Config Filehttp://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-malumpos-targets-hotels-and-other-us-industries/2015-06-25 00:00:0075Florian RothEXTVAR,MALc850ecd21ce9e216491d1e4841f856e8
1821PoisonIvy_Generic_3PoisonIvy RAT Generic Rule-2015-05-14 00:00:0075Florian RothEXE,FILE,GEN,MALd328e9cfec40ad7165205c45f75f6a98
1822PoisonIvy_RAT_ssMUIDLLDetects PoisonIvy RAT DLL mentioned in Palo Alto Blog in April 2016http://goo.gl/WiwtYT2016-04-22 00:00:0075Florian Roth (with the help of yarGen and Binarly)EXE,FILE,MALa5639d3f4a75db637e71ed863d3b265d
1823PoisonIvy_Sample_5Detects PoisonIvy RAT sample setVT Analysis2015-06-03 00:00:0070Florian RothEXE,FILE,MAL27964b182c4d499dd07553c9b2c9f969
1824PoisonIvy_Sample_6Detects PoisonIvy RAT sample setVT Analysis2015-06-03 00:00:0070Florian RothEXE,FILE,MAL8d96097435d40c03eb06faf0fc66c1fc
1825PoisonIvy_Sample_7Detects PoisonIvy RAT sample setVT Analysis2015-06-03 00:00:0070Florian RothEXE,FILE,MAL1fa64afa8039473aa7d78c09185d4dcf
1826PoisonIvy_Sample_APTDetects a PoisonIvy APT malware groupVT Analysis2015-06-03 00:00:0070Florian RothAPT,EXE,FILE90058a251417bae9d1acb97dabc47fef
1827PoisonIvy_Sample_APT_2Detects a PoisonIvy MalwareVT Analysis2015-06-03 00:00:0070Florian RothAPT,EXE,FILE,MALe22c13963b1026ed0fcc8b8dea77344c
1828PoisonIvy_Sample_APT_3Detects a PoisonIvy MalwareVT Analysis2015-06-03 00:00:0070Florian RothAPT,EXE,FILE,MAL0c0a66a68a80c08a83a022b4fc46e1f6
1829PoisonIvy_Sample_APT_4Detects a PoisonIvy Sample APTVT Analysis2015-06-03 00:00:0070Florian RothAPT,EXE,FILEe4d80dd1dedeedb8ede74ae9b78eb747
1830PortRacerAuto-generated rule on file PortRacer.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLa35418145e60d16c183ece3ceba8b278
1831PortScannerAuto-generated rule on file PortScanner.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL72ce56115aee4b2f7b5ddaa5456d7607
1832PoseidonGroup_MalDoc_1Detects Poseidon Group - Malicious Word Documenthttps://securelist.com/blog/research/73673/poseidon-group-a-targeted-attack-boutique-specializing-in-global-cyber-espionage/2016-02-09 00:00:0080Florian RothFILE,OFFICE9bceecc0da91439cde483376c77087b9
1833PoseidonGroup_MalDoc_2Detects Poseidon Group - Malicious Word Documenthttps://securelist.com/blog/research/73673/poseidon-group-a-targeted-attack-boutique-specializing-in-global-cyber-espionage/2016-02-09 00:00:0070Florian RothFILE,OFFICEf886f4bd346a463de03e14c170eab16b
1834PoseidonGroup_MalwareDetects Poseidon Group Malwarehttps://securelist.com/blog/research/73673/poseidon-group-a-targeted-attack-boutique-specializing-in-global-cyber-espionage/2016-02-09 00:00:0085Florian RothEXE,FILE,MALc788eaa9dae39d1d31b7f6910e774162
1835PowerShdllDetects hack tool PowerShdllhttps://github.com/p3nt4/PowerShdll2017-08-03 00:00:0075Florian Roth5123079ea0d28aa987071c708c4e1140
1836PowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolshttps://twitter.com/danielhbohannon/status/9050961069247610882017-08-11 00:00:0070Florian RothOBFUS,SCRIPT0ea7d44eb533b104fac3b1bc8a8cd269
1837PowerShell_Emp_Eval_Jul17_A1Detects suspicious sample with PowerShell content PowerShell Empire Eval2017-07-27 00:00:0075Florian RothEXE,FILE,SCRIPT4e7880c7622c27bcf0c5e04619f15879
1838PowerShell_Emp_Eval_Jul17_A2Detects suspicious sample with PowerShell content PowerShell Empire Eval2017-07-27 00:00:0075Florian RothEXE,FILE,SCRIPT4c752c597d8c3a319901aa6ee0735bd3
1839PowerShell_ISESteroids_ObfuscationDetects PowerShell ISESteroids obfuscationhttps://twitter.com/danielhbohannon/status/8779539704378449932017-06-23 00:00:0075Florian RothOBFUS,SCRIPTe40c9648874e86136bb44852d5e4d4ec
1840PowerShell_JAB_B64Detects base464 encoded $ sign at the beginning of a stringhttps://twitter.com/ItsReallyNick/status/9809152879220408322018-04-02 00:00:0060Florian RothSCRIPTa3d7993cee55dbaed475a0ce551062ea
1841PowerShell_Mal_HackTool_GenDetects PowerShell hack tool samples - generic PE loaderInternal Research2017-11-02 00:00:0075Florian RothGEN,HKTL,SCRIPT111886d3511eeef5dff5e328bd686135
1842PowerShell_Suite_EidolonDetects PowerShell Suite Eidolon script - file Start-Eidolon.ps1https://github.com/FuzzySecurity/PowerShell-Suite2017-12-27 00:00:0075Florian RothFILE,SCRIPTa930332d686ee27e385a839cb0d23c26
1843PowerShell_Suite_Hacktools_Gen_StringsDetects strings from scripts in the PowerShell-Suite repohttps://github.com/FuzzySecurity/PowerShell-Suite2017-12-27 00:00:0075Florian RothGEN,SCRIPTc054953c2a313abed276db2f60c305a6
1844PowerShell_Susp_Parameter_ComboDetects PowerShell invocation with suspicious parametershttps://goo.gl/uAic1X2017-03-12 00:00:0060Florian RothANOMALY,SCRIPT52cdea0c983cae62e9d8ca3bf497d3d7
1845PowerShell_in_Word_DocDetects a powershell and bypass keyword in a Word documentInternal Research - ME2017-06-27 00:00:0050Florian RothFILE,OFFICE,SCRIPT54f05e36c14d39ad8b83b7bbc4bd8ce0
1846Powerkatz_DLL_GenericDetects Powerkatz - a Mimikatz version prepared to run in memory via Powershell (overlap with other Mimikatz versions is possible)PowerKatz Analysis2016-02-05 00:00:0080Florian RothEXE,FILE,GEN64da045ef05b6f27216f9710c37786fd
1847Powershell_Attack_ScriptsPowershell Attack Scripts-2016-03-09 00:00:0070Florian RothHKTL55f5f534fbdd6acef0424f11ad673371
1848Powershell_NetcatDetects a Powershell version of the Netcat network hacking tool-2014-10-10 00:00:0060Florian RothHKTL1bd48741d1e9a01f94eaebfd8d632e6a
1849Prikormka--1970-01-01 01:00:0075-EXTVAR,REQ_PRIVATE9321d3a0b7490d6d9d5ea8924093d083
1850ProPort_zip_Folder_ProPortAuto-generated rule on file ProPort.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTL4ace211713e214a904185a3cb2d98d8c
1851ProcessInjector_GenDetects a process injection utility that can be used ofr good and bad purposeshttps://github.com/cuckoosandbox/monitor/blob/master/bin/inject.c2018-04-23 00:00:0060Florian RothEXE,FILE,GEN,HKTL60cecb6e31198bb728d89e2789b36f46
1852Project1Chinese Hacktool Set - file Project1.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL2947fb47f69c98fa6746054de6a7b090
1853ProjectM_CrimsonDownloaderDetects ProjectM Malware - file dc8bd60695070152c94cbeb5f61eca6e4309b8966f1aa9fdc2dd0ab754ad3e4chttp://researchcenter.paloaltonetworks.com/2016/03/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/2016-03-26 00:00:0075Florian RothEXE,FILE,MAL28e2590553bc525851502e19a7ac4f1f
1854ProjectM_DarkComet_1Detects ProjectM Malware - file cc488690ce442e9f98bac651218f4075ca36c355d8cd83f7a9f5230970d24157http://researchcenter.paloaltonetworks.com/2016/03/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/2016-03-26 00:00:0075Florian RothEXE,FILE,MAL6d0ebbf65f5e61c6024ec9d07f93cf91
1855Pupy_BackdoorDetects Pupy backdoorhttps://github.com/n1nj4sec/pupy-binaries2017-08-11 00:00:0075Florian RothEXE,FILE,MALbab0f20bacc6d524ab474b9d34edea3a
1856PwDumpPwDump 6 variant-2014-04-24 00:00:0070Marc StroebelHKTL70a27411f65538a9b21829f41095318b
1857PwDump_BDetects a tool used by APT groups - file PwDump.exehttp://goo.gl/igxLyF2016-09-08 00:00:0075Florian RothAPT,EXE,FILE,HKTLd424c9dc593ae76f85d29ceb3ec20603
1858QQBrowserNot malware but suspicious browser - file QQBrowser.exehttps://goo.gl/4pTkGQ2017-06-02 00:00:0050Florian RothEXE,FILE3a8add557b5d4287bea9f3fc41eab8dc
1859QQ_zip_Folder_QQDisclosed hacktool set (old stuff) - file QQ.exe-2014-11-23 00:00:0060Florian RothHKTL2de77a858d518a0a9551cab2bf8cb6bb
1860QuarksPwDump_GenDetects all QuarksPWDump versions-2015-09-29 00:00:0080Florian RothGEN,HKTL361b37066f8dc0952f15d9d3f7e7becf
1861Quasar_RAT_1Detects Quasar RAThttps://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf2017-04-07 00:00:0075Florian RothEXE,FILE,MALaf44fc8c42377d91843afe7d2f35c93a
1862Quasar_RAT_2Detects Quasar RAThttps://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf2017-04-07 00:00:0075Florian RothEXE,FILE,MALd8bba788903f2f780dd1c4d39b0264ad
1863Quasar_RAT_Jan18_1Detects Quasar RAThttps://researchcenter.paloaltonetworks.com/2018/01/unit42-vermin-quasar-rat-custom-malware-used-ukraine/2018-01-29 00:00:0075Florian RothEXE,FILE,MALf2eb9597aff70686e9b2b1946dc34584
1864Query_Javascript_Decode_FunctionDetects malware mentioned in TA18-074A-1970-01-01 01:00:0075other2ab53fdf8d76be5dc4b3f6a4ef5e881f
1865Query_XML_Code_MAL_DOC_PT_2Detects malware mentioned in TA18-074A-1970-01-01 01:00:0075otherFILE67a7f44c74b9179e3ea93bfe8e9473a2
1866RAT_AARDetects AAR RAThttp://malwareconfig.com/stats/AAR2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALa306245540f7002b6ddd9e6d80712c78
1867RAT_AdzokDetects Adzok RAThttp://malwareconfig.com/stats/Adzok2015-05-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALfbd894f517e8b0d1c698a1d821ea986d
1868RAT_Ap0calypseDetects Ap0calypse RAThttp://malwareconfig.com/stats/Ap0calypse2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL9d58adf7ef08895eb7a16bf19aef3292
1869RAT_ArcomDetects Arcom RAThttp://malwareconfig.com/stats/Arcom2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALe8297bf2b043ac7141417896d49d8d5a
1870RAT_BandookDetects Bandook RAThttp://malwareconfig.com/stats/bandook2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL15a841b35410c70ec909c1b8b865e350
1871RAT_BlackNixDetects BlackNix RAThttp://malwareconfig.com/stats/BlackNix2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALec8fb07a31cde3ca070710ae4bf59ab4
1872RAT_BlackShadesDetects BlackShades RAThttp://blog.cylance.com/a-study-in-bots-blackshades-net2014-04-06 00:00:0075Brian Wallace (@botnet_hunter)MAL418d806fe9d6686646bbc433d0d46b3c
1873RAT_BlueBananaDetects BlueBanana RAThttp://malwareconfig.com/stats/BlueBanana2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALa5022d1e509327a750286d8b8074cf83
1874RAT_BozokDetects Bozok RAThttp://malwareconfig.com/stats/Bozok2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL7b127ab2a9ef34ce567b04628a8a409d
1875RAT_ClientMeshDetects ClientMesh RAThttp://malwareconfig.com/stats/ClientMesh2014-06-06 00:00:0075Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)MAL7891246ee384a40f660a7107d86d099a
1876RAT_CyberGateDetects CyberGate RAThttp://malwareconfig.com/stats/CyberGate2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL07987888abcbb0373ca55061a61ba411
1877RAT_DarkCometDetects DarkComet RAThttp://malwareconfig.com/stats/DarkComet2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL8d8233a29fd6db35be27520d5fe482aa
1878RAT_DarkRATDetects DarkRAThttp://malwareconfig.com/stats/DarkRAT2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALfbaa94978a3339be661d0298b085814a
1879RAT_GreameDetects Greame RAThttp://malwareconfig.com/stats/Greame2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL1b74932abe0b0bff2bd777a36b0f055e
1880RAT_HawkEyeDetects HawkEye RAThttp://malwareconfig.com/stats/HawkEye2015-06-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL4c252d2693fe9eb8e651c904e67bf3d9
1881RAT_ImminentDetects Imminent RAThttp://malwareconfig.com/stats/Imminent2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL99656fdf3a4552add06c1c886df3d0ab
1882RAT_InfinityDetects Infinity RAThttp://malwareconfig.com/stats/Infinity2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALfa3bbcd30e5109ed88a257955e124d62
1883RAT_JavaDropperDetects JavaDropper RAThttp://malwareconfig.com/stats/JavaDropper2015-10-06 00:00:0075Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)MALe122da42c6300e44a48a8d776d616d03
1884RAT_LostDoorDetects LostDoor RAThttp://malwareconfig.com/stats/LostDoor2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL61faa56a4c8146d1b2b9026fccdedb19
1885RAT_LuminosityLinkDetects LuminosityLink RAThttp://malwareconfig.com/stats/LuminosityLink2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALc58371c88a4b85d92909e7e0fcbccbc0
1886RAT_LuxNetDetects LuxNet RAThttp://malwareconfig.com/stats/LuxNet2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALc55487fbdf87e62099e32b5c8a1d3d8d
1887RAT_NetWireDetects NetWire RAThttp://malwareconfig.com/stats/NetWire2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net> & David CanningsMALdf9f47c7490ba357d861b5bbb9cc225f
1888RAT_PandoraDetects Pandora RAThttp://malwareconfig.com/stats/Pandora2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL835db1e550e7276ddbfa5074af1d4290
1889RAT_ParadoxDetects Paradox RAThttp://malwareconfig.com/stats/Paradox2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL46b73aafbc7eab48dcb755a053a9092b
1890RAT_PlasmaDetects Plasma RAThttp://malwareconfig.com/stats/Plasma2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL5a11d3053ced09b506516dcbfae6a890
1891RAT_PoisonIvyDetects PoisonIvy RAThttp://malwareconfig.com/stats/PoisonIvy2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALde1090753a4be8b0b219b5d776dc7dd6
1892RAT_PredatorPainDetects PredatorPain RAThttp://malwareconfig.com/stats/PredatorPain2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALf7424a8cc166234368ef10c04b7bc9bf
1893RAT_PunisherDetects Punisher RAThttp://malwareconfig.com/stats/Punisher2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALb44bd865375af51cf4c71effb8bbdf01
1894RAT_PythoRATDetects Python RAThttp://malwareconfig.com/stats/PythoRAT2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL,SCRIPT410130fdcb7364c7b5f2cedbb95ce081
1895RAT_QRatDetects QRAThttp://malwareconfig.com2015-08-06 00:00:0075Kevin Breen @KevTheHermitMALd0c1434b1d4771ddd8d0984d9ef5bf70
1896RAT_SakulaDetects Sakula v1.0 RAThttp://blog.airbuscybersecurity.com/public/YFR/sakula_v1x.yara2015-10-13 00:00:0075Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou / NCC Group David CanningsEXE,FILE,MAL2a21511dd726187c32de1faf9d457b6c
1897RAT_ShadowTechDetects ShadowTech RAThttp://malwareconfig.com/stats/ShadowTech2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALd94cb66a00839e41d8770d49d5b66c24
1898RAT_SmallNetDetects SmallNet RAThttp://malwareconfig.com/stats/SmallNet2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL3b6f5bec88bf6d117c4e420dd75bfd6b
1899RAT_SpyGateDetects SpyGate RAThttp://malwareconfig.com/stats/SpyGate2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL14fba8e488520b3f1dba1b769b9b2186
1900RAT_Sub7NationDetects Sub7Nation RAThttp://malwareconfig.com/stats/Sub7Nation2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)MAL6e6ea397a253bd1555f40d5fd5ea131e
1901RAT_VertexDetects Vertex RAThttp://malwareconfig.com/stats/Vertex2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALc0083b96ee11ff45898303ed862f93f6
1902RAT_VirusRatDetects VirusRAThttp://malwareconfig.com/stats/VirusRat2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALf99006eb88945e6177dc285386fa7c51
1903RAT_XtremeDetects Xtreme RAThttp://malwareconfig.com/stats/Xtreme2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL10687c6e5c64322c7528ed2d16a69068
1904RAT_adWindDetects Adwind RAThttp://malwareconfig.com/stats/adWind2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MALdd659802f7eb51598668a9e0bd00e87b
1905RAT_njRatDetects njRAThttp://malwareconfig.com/stats/njRat2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL00a26b95aa92d2e252a2f3bee14d39e8
1906RAT_unrecomDetects unrecom RAThttp://malwareconfig.com/stats/unrecom2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL200618ec265fef0fcde114264cbfb4bf
1907RAT_xRATDetects xRAThttp://malwareconfig.com/stats/xRat2014-04-06 00:00:0075Kevin Breen <kevin@techanarchy.net>MAL99656fdf3a4552add06c1c886df3d0ab
1908RDP_Brute_StringsDetects RDP brute forcer from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSCf5be15452c1e912628c54df68d6b8b40
1909REDLEAVES_CoreImplant_UniqueStringsStrings identifying the core REDLEAVES RAT in its deobfuscated statehttps://www.us-cert.gov/ncas/alerts/TA17-117A1970-01-01 01:00:0075USGMAL,OBFUS2723ca091b4215392abc9cf8236a24ef
1910REDLEAVES_DroppedFile_ImplantLoader_StarburnDetect the DLL responsible for loading and deobfuscating the DAT file containing shellcode and core REDLEAVES RAThttps://www.us-cert.gov/ncas/alerts/TA17-117A1970-01-01 01:00:0075USGMAL8b1b3cceada4b1497d3ef70ed8910227
1911REDLEAVES_DroppedFile_ObfuscatedShellcodeAndRAT_handkerchiefDetect obfuscated .dat file containing shellcode and core REDLEAVES RAThttps://www.us-cert.gov/ncas/alerts/TA17-117A1970-01-01 01:00:0075USGMAL,OBFUSed8268e74d315aa6836ac0d54c8f109f
1912ROKRAT_Dropper_Nov17Detects dropper for ROKRAT malwarehttp://blog.talosintelligence.com/2017/11/ROKRAT-Reloaded.html2017-11-28 00:00:0075Florian RothEXE,FILE,MAL0c0f26a803abe8b938036658a4078a24
1913ROKRAT_MalwareDetects ROKRAT Malwarehttp://blog.talosintelligence.com/2017/04/introducing-rokrat.html2017-04-03 00:00:0075Florian RothEXE,FILE,MAL71c35c3903aba57a19e211e2cf9802d3
1914ROKRAT_Nov17_1Detects ROKRAT malwareInternal Research2017-11-28 00:00:0075Florian RothEXE,FILE,MALe6ca51add94e378794045665634a8b3e
1915RUAG_Bot_Config_FileDetects a specific config file used by malware in RUAG APT casehttps://goo.gl/N5MEj01970-01-01 01:00:0060Florian RothAPT,FILEb4135aa113df1c9403c390baa3e8e1ba
1916RUAG_Cobra_Config_FileDetects a config text file used by malware Cobra in RUAG casehttps://goo.gl/N5MEj01970-01-01 01:00:0060Florian RothFILE,NK4329482e57a3cc6ac143559d5654ec5e
1917RUAG_Cobra_MalwareDetects a malware mentioned in the RUAG Case called Carbon/Cobrahttps://goo.gl/N5MEj01970-01-01 01:00:0060Florian RothEXE,FILE,MAL,NK9a30aa4c11b1ab858c016e07ccaa8310
1918RUAG_Exfil_Config_FileDetects a config text file used in data exfiltration in RUAG casehttps://goo.gl/N5MEj01970-01-01 01:00:0060Florian RothFILE718e926c8bfd7412ecb06d371ed85761
1919RUAG_Tavdig_Malformed_ExecutableDetects an embedded executable with a malformed header - known from Tavdig malwarehttps://goo.gl/N5MEj01970-01-01 01:00:0060Florian RothEXE,FILEe16cd17470718414cebd80c69b8a736c
1920Radmin_HashChinese Hacktool Set - file Radmin_Hash.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL9ae2c4f14981a318799a43538bbe7e57
1921RangeScanDisclosed hacktool set (old stuff) - file RangeScan.exe-2014-11-23 00:00:0060Florian RothHKTLcbf554061021d842c14dc6ff0aae195a
1922Ransom_LockerGoga_Mar19_1Detects LockerGoga ransomware binarieshttps://www.nrk.no/norge/skreddersydd-dobbeltangrep-mot-hydro-1.144802022019-03-19 00:00:0075Florian RothEXE,FILE,MAL,RANSOMece0483614c79b6a6895fccec2ab336f
1923ReactOS_cmd_validReactOS cmd.exe with correct file name - maybe packed with software or part of hacker toolsethttp://www.elifulkerson.com/articles/suzy-sells-cmd-shells.php2014-05-11 00:00:0030Florian RothHKTLe1d135670931d2a0ffad7ea37667c6ef
1924Reader_aspSemi-Auto-generated - file Reader.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL8c63ed354bbf0b6bf271d52ed08f35e3
1925Reaver3_Malware_Nov17_1Detects Reaver malware mentioned in PaloAltoNetworks reporthttps://researchcenter.paloaltonetworks.com/2017/11/unit42-new-malware-with-ties-to-sunorcal-discovered/2017-11-11 00:00:0075Florian RothEXE,FILE,MALfbcef4eef2ca404c6e0e1cc8afe4bed2
1926Reaver3_Malware_Nov17_2Detects Reaver malware mentioned in PaloAltoNetworks reporthttps://researchcenter.paloaltonetworks.com/2017/11/unit42-new-malware-with-ties-to-sunorcal-discovered/2017-11-11 00:00:0075Florian RothEXE,FILE,MAL575c1a0f94a4dd2f4e92cbe404a4531d
1927Reaver3_Malware_Nov17_3Detects Reaver malware mentioned in PaloAltoNetworks reporthttps://researchcenter.paloaltonetworks.com/2017/11/unit42-new-malware-with-ties-to-sunorcal-discovered/2017-11-11 00:00:0075Florian RothEXE,FILE,MAL5f2b493c3894a32b50d6156ac2ceb061
1928ReconCommands_in_FileDetects various recon commands in a single filehttps://twitter.com/haroonmeer/status/9390993798346588172017-12-11 00:00:0040Florian Roth8e3f594f562cdc4b6f167ee60bf0fc43
1929Recon_Commands_Windows_Gen1Detects a set of reconnaissance commands on Windows systemsInternal Research2017-07-10 00:00:0060Florian RothKEYWORDaf4e21bd7a8bc0843d71acc23a93ed42
1930ReflectiveLoaderDetects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommendedInternal Research1970-01-01 01:00:0060Florian Roth (auto-filled)EXE,FILE1fd7c7f6b3176d9a1035b1a1d68140d2
1931Reflective_DLL_Loader_Aug17_1Detects Reflective DLL LoaderInternal Research2017-08-20 00:00:0075Florian RothEXE,FILE9038b82b917ab5625a2a6e23808e66c2
1932Reflective_DLL_Loader_Aug17_2Detects Reflective DLL Loader - suspicious - Possible FP could be program crackInternal Research2017-08-20 00:00:0060Florian RothEXE,FILEdd8911ec43dd2ba1562ea427b01ca65b
1933Reflective_DLL_Loader_Aug17_3Detects Reflective DLL LoaderInternal Research2017-08-20 00:00:0075Florian RothEXE,FILEb2404b2c04b0abb6f06cec0151340b78
1934Reflective_DLL_Loader_Aug17_4Detects Reflective DLL LoaderInternal Research2017-08-20 00:00:0075Florian RothEXE,FILE2eb359adff2ca6ac13d54d042e1da906
1935Regin_APT_KernelDriver_Generic_AGeneric rule for Regin APT kernel driver Malware - Symantec http://t.co/qu53359Cb2-2014-11-23 00:00:0075@Malwrsignatures - included in APT Scanner THORAPT,EXE,FILE,GEN,MAL552e13461211053888703f49d4b8845a
1936Regin_APT_KernelDriver_Generic_BGeneric rule for Regin APT kernel driver Malware - Symantec http://t.co/qu53359Cb2-2014-11-23 00:00:0075@Malwrsignatures - included in APT Scanner THORAPT,EXE,FILE,GEN,MALa35c93cae83a841091c3ba66a7ed7665
1937Regin_APT_KernelDriver_Generic_CGeneric rule for Regin APT kernel driver Malware - Symantec http://t.co/qu53359Cb2-2014-11-23 00:00:0075@Malwrsignatures - included in APT Scanner THORAPT,EXE,FILE,GEN,MALb380dcf311e5e5739c6f32e10a837791
1938Regin_Related_MalwareMalware Sample - maybe Regin relatedVT Analysis2015-06-03 00:00:0070Florian RothMAL52496acb2cabc8fc2e7daef38beb0c09
1939Regin_Sample_1Auto-generated rule - file-3665415_sys-2014-11-26 00:00:0075@MalwrSignatures0eab7e5a64388a9164f5e1594de33ccb
1940Regin_Sample_2Auto-generated rule - file hiddenmod_hookdisk_and_kdbg_8949d000.bin-2014-11-26 00:00:0075@MalwrSignaturescf0116df8fdd0628a40c1db4c39f8bc8
1941Regin_Sample_3Detects Regin Backdoor sample fe1419e9dde6d479bd7cda27edd39fafdab2668d498931931a2769b370727129-2014-11-27 00:00:0075@MalwrsignaturesFILE,MAL6b13613577b7791ab5edd68115c8b599
1942Regin_Sample_Set_1Auto-generated rule - file SHF-000052 and ndisips.sys-2014-11-26 00:00:0075@MalwrSignaturesea59dd9cf4e9be722c2bedfdc57c7720
1943Regin_Sample_Set_2Detects Regin Backdoor sample-2014-11-27 00:00:0075@MalwrSignaturesMALf94231bc02aee731ed76562e583301d4
1944Regin_sig_svcsstatDetects svcstat from Regin report - file svcsstat.exe_sample-2014-11-26 00:00:0075@MalwrSignatures14b579590f609eb92d335baed2c72494
1945Rehashed_RAT_1Detects malware from Rehashed RAT incidenthttps://blog.fortinet.com/2017/09/05/rehashed-rat-used-in-apt-campaign-against-vietnamese-organizations2017-09-08 00:00:0075Florian RothEXE,FILE,MAL15526a903b3e22acae7754bf54a10d98
1946Rehashed_RAT_2Detects malware from Rehashed RAT incidenthttps://blog.fortinet.com/2017/09/05/rehashed-rat-used-in-apt-campaign-against-vietnamese-organizations2017-09-08 00:00:0075Florian RothEXE,FILE,MAL70b9fd72775c6fa868c819e580a6040e
1947Rehashed_RAT_3Detects malware from Rehashed RAT incidenthttps://blog.fortinet.com/2017/09/05/rehashed-rat-used-in-apt-campaign-against-vietnamese-organizations2017-09-08 00:00:0075Florian RothEXE,FILE,MAL6749588122377de88f6f39ad88cf96a3
1948Release_dllTestWebshells Auto-generated - file dllTest.dll-1970-01-01 01:00:0075Florian RothWEBSHELL0265bdb7f5d5fca45ee68c3a81f32cf8
1949RemCom_RemoteCommandExecutionDetects strings from RemCom toolhttps://goo.gl/tezXZt2017-12-28 00:00:0050Florian RothHKTL7d2f1910425736b7e1185a717e446133
1950RemExp_aspSemi-Auto-generated - file RemExp.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL99538f26f7158d7c4497ce7cac4d0ec1
1951Rem_View_php_phpSemi-Auto-generated - file Rem View.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLc8b71fdebb0e5e13446d7b4ab27f3c24
1952RemoteCmdDetects a remote access tool used by APT groups - file RemoteCmd.exehttp://goo.gl/igxLyF2016-09-08 00:00:0075Florian RothAPT,EXE,FILEdfa2313b7c62c2aa21e9487e1c99e54a
1953RemoteExec_ToolRemote Access Tool used in APT Terracottahttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/2015-08-04 00:00:0075Florian RothAPT,EXE,FILE5bfde6a69f576f4479d1a5ef0a7f3bad
1954Reveal_MemoryCredentialsAuto-generated rule - file Reveal-MemoryCredentials.ps1https://github.com/giMini/RWMC/2015-08-31 00:00:0075Florian Roth8e6a0dcc31eec6caae8aba5dc2efa069
1955RevengeRAT_Sep17Detects RevengeRAT malwareInternal Research2017-09-04 00:00:0075Florian RothEXE,FILE,MAL81d8787bba5a242fccd29fbf2221e518
1956RkNTLoadWebshells Auto-generated - file RkNTLoad.exe-1970-01-01 01:00:0075Florian RothWEBSHELL111db0e4417c6ff3278d24ae98589a52
1957RocketKitten_KeyloggerDetects Keylogger used in Rocket Kitten APThttps://goo.gl/SjQhlp2015-09-01 00:00:0075Florian RothAPT,EXE,FILE,HKTL,MIDDLE_EAST371e10680c2cec64629c2d671001e2f1
1958Rombertik_CarbonGrabberDetects CarbonGrabber alias Rombertik - file Copy#064046.scrhttp://blogs.cisco.com/security/talos/rombertik2015-05-05 00:00:0075Florian RothEXE,FILE9ead69ddd32e5db41809c3996151cdda
1959Rombertik_CarbonGrabber_BuilderDetects CarbonGrabber alias Rombertik Builder - file Builder.exehttp://blogs.cisco.com/security/talos/rombertik2015-05-05 00:00:0075Florian RothEXE,FILEc6535efaae6732fe098ce2cf098107ba
1960Rombertik_CarbonGrabber_Builder_ServerDetects CarbonGrabber alias Rombertik Builder Server - file Server.exehttp://blogs.cisco.com/security/talos/rombertik2015-05-05 00:00:0075Florian RothEXE,FILE58ae753ac4f58140e43888ca3e27b1c5
1961Rombertik_CarbonGrabber_PanelDetects CarbonGrabber alias Rombertik Panel - file index.phphttp://blogs.cisco.com/security/talos/rombertik2015-05-05 00:00:0075Florian Roth63ab76e8e846781141b9dfb464c10398
1962Rombertik_CarbonGrabber_Panel_InstallScriptDetects CarbonGrabber alias Rombertik panel install script - file install.phphttp://blogs.cisco.com/security/talos/rombertik2015-05-05 00:00:0075Florian Rothd4e855a0e13a6762c6bfa3b63f60d3bd
1963RottenPotato_PotatoDetects a component of privilege escalation tool Rotten Potato - file Potato.exehttps://github.com/foxglovesec/RottenPotato2017-02-07 00:00:0090Florian RothEXE,FILEbe54bbe28b6c8d7fbda4dd525f684be9
1964SAM_Hive_BackupDetects a SAM hive backup filehttps://github.com/gentilkiwi/mimikatz/wiki/module-~-lsadump2015-03-31 00:00:0060Florian RothEXTVAR,FILE6c935acbe2c1cc41f02e36c792e73c73
1965SCT_Scriptlet_in_Temp_Inet_FilesDetects a scriptlet file in the temporary Internet files (see regsvr32 AppLocker bypass)http://goo.gl/KAB8Jw2016-04-26 00:00:0075Florian RothEXTVAR,FILE422c490c2b55ea132885ff2edd79c444
1966SFXRAR_AcrotrayMost likely a malicious file acrotray in SFX RAR / CloudDuke APT 5442.1.exe, 5442.2.exehttps://www.f-secure.com/weblog/archives/00002822.html2015-07-22 00:00:0070Florian RothAPT,EXE,FILE,RUSSIA1f9afe05b73968799caf3c015a9f0f18
1967SHIFU_Banking_TrojanDetects SHIFU Banking Trojanhttp://goo.gl/52n8WE2015-10-31 00:00:0070Florian RothEXE,FILE,MAL029a7d58e425a2f08afb031b87b203e5
1968SLServer_campaign_codeSearches for the related campaign code.-2016-04-18 00:00:0075Matt Brooks, @cmatthewbrooksFILE02ade1eaea0bac9e74086fd5dbb51d44
1969SLServer_command_and_controlSearches for the C2 server.-2016-04-18 00:00:0075Matt Brooks, @cmatthewbrooksFILE4ce76481034d5ef2ac10cfd8e2f20f9e
1970SLServer_dialog_remainsSearches for related dialog remnants.-2016-04-18 00:00:0075Matt Brooks, @cmatthewbrooks / modified by Florian RothFILEb3901b72799c0dd18aae12ed54da9821
1971SLServer_mutexSearches for the mutex.-2016-04-18 00:00:0075Matt Brooks, @cmatthewbrooksFILEb6cd1d5a8d26d6f2d6d21f80f8de8cfb
1972SLServer_unknown_stringSearches for a unique string.-2016-04-18 00:00:0075Matt Brooks, @cmatthewbrooksFILEaf7fd981f96874bebda96e9d360855e3
1973SNOWGLOBE_Babar_MalwareDetects the Babar Malware used in the SNOWGLOBE attacks - file babar.exehttp://motherboard.vice.com/read/meet-babar-a-new-malware-almost-certainly-created-by-france2015-02-18 00:00:0080Florian RothEXE,FILE,MAL183c725591cbbb67a1b0b280dccffbe8
1974SQLCrackerChinese Hacktool Set - file SQLCracker.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLd72f12da7b9ac7e7aa16be5cbaccc86d
1975SQLMapThis signature detects the SQLMap SQL injection tool-2014-07-06 00:00:0060Florian RothHKTL98e627b7d61a419bf070a77bb567a129
1976SQLToolsChinese Hacktool Set - file SQLTools.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLdb6030b4038bac7431602eeceffb2811
1977STNC_php_phpSemi-Auto-generated - file STNC.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL8f8dd0097027f710c7fa991ef2432bd6
1978SUSP_Bad_PDFDetects PDF that embeds code to steal NTLM hashesInternal Research2018-05-03 00:00:0075Florian Roth, Markus NeisFILE,SUSPe31e105385471c2664b7c061aedac9cf
1979SUSP_CMD_Var_ExpansionDetects Office droppers that include a variable expansion stringhttps://twitter.com/asfakian/status/10448595256758435852018-09-26 00:00:0060Florian RothFILE,OFFICE,SUSP7c1163971a89e1921c1a486baaa5072a
1980SUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionInternal Research2018-12-12 00:00:0040Florian RothFILE,LINUX,SUSP4052342a830f55f02a949b76de1267e3
1981SUSP_ELF_Tor_ClientDetects VPNFilter malwareInternal Research2018-05-24 00:00:0075Florian RothFILE,LINUX,SUSP208d049ce35e555a893e38f8bb0ff700
1982SUSP_EnableContent_String_GenDetects suspicious string that asks to enable active content in Office DocInternal Research2019-02-12 00:00:0075Florian RothFILE,GEN,OFFICE,SUSP70c79e8178d4628e5dc5a7c76b13b1f6
1983SUSP_Imphash_PassRevealer_PY_EXEDetects an imphash used by password revealer and hack toolsInternal Research2018-04-06 00:00:0040Florian RothEXE,FILE,HKTL,SUSP29e5ad98ad6f8a1588eb37b4d2ad0238
1984SUSP_JAVA_Class_with_VBS_ContentDetects a JAVA class file with strings known from VBS fileshttps://www.menlosecurity.com/blog/a-jar-full-of-problems-for-financial-services-companies2019-01-03 00:00:0060Florian RothFILE,SCRIPT,SUSP2d8cb05f3262ed4c4b1ee1b99129f4d2
1985SUSP_Katz_PDBDetects suspicious PDB in fileInternal Research2019-02-04 00:00:0075Florian RothEXE,FILE,HKTL,SUSP4e8343e402d3ffa838b2401bec6e5b05
1986SUSP_LNK_Big_Link_FileDetects a suspiciously big LNK file - maybe with embedded contentInternal Research2018-05-15 00:00:0065Florian RothFILE,SUSP2434620a156275a9b7ede3a822bed7a4
1987SUSP_LNK_File_AppData_RoamingDetects a suspicious link file that references to AppData Roaminghttps://www.fireeye.com/blog/threat-research/2018/05/deep-dive-into-rig-exploit-kit-delivering-grobios-trojan.html2018-05-16 00:00:0050Florian RothFILE,SUSPf1e9fd4cba6619454d2e6162c84bd181
1988SUSP_LNK_File_PathTraversalDetects a suspicious link file that references a file multiple folders lower than the link itselfhttps://www.fireeye.com/blog/threat-research/2018/05/deep-dive-into-rig-exploit-kit-delivering-grobios-trojan.html2018-05-16 00:00:0040Florian RothFILE,SUSPf731f5d681534f95c3e18ca4f8879588
1989SUSP_LNK_SuspiciousCommandsDetects LNK file with suspicious content-2018-09-18 00:00:0060Florian RothFILE,SUSP27c8f30ffb31c9bb67693cf4cfc1a033
1990SUSP_LNK_lnkfileoverRFCdetect APT lnk files that run double extraction and launch routines with autoruns-2018-09-18 00:00:0075@Grotezinfosec, modified by Florian RothAPT,FILE,SUSP3715aa6f3090a5820cc72255523a6cde
1991SUSP_Macro_StarOfficeSuspicious macro in StarOfficehttps://twitter.com/JohnLaTwC/status/10932598739937320962019-02-06 00:00:0060John Lambert @JohnLaTwCFILE,OFFICE,SUSP22ee481b4dc7047678fd9fb99687b4f6
1992SUSP_Microsoft_7z_SFX_ComboDetects a suspicious file that has a Microsoft copyright and is a 7z SFXInternal Research2018-09-16 00:00:0075Florian RothANOMALY,EXE,FILE,SUSPa3a9108b18f27c38e1a8cf2c36bcf24b
1993SUSP_Microsoft_Copyright_String_Anomaly_2Detects Floxif MalwareInternal Research2018-05-11 00:00:0060Florian RothEXE,FILE,MAL,SUSP0248c1ff2608c6f314257bfee2cb2883
1994SUSP_Microsoft_RAR_SFX_ComboDetects a suspicious file that has a Microsoft copyright and is a RAR SFXInternal Research2018-09-16 00:00:0075Florian RothANOMALY,EXE,FILE,SUSPa6aa52a1aeb7cfe07781bd8fd979f1ff
1995SUSP_Modified_SystemExeFileName_in_FileDetecst a variant of a system file name often used by attackers to cloak their activityhttps://www.symantec.com/blogs/threat-intelligence/seedworm-espionage-group2018-12-11 00:00:0065Florian RothEXE,FILE,SUSP82b7ee96542c85910d615a2f83340a37
1996SUSP_Obfuscted_PowerShell_CodeDetects obfuscated PowerShell Codehttps://twitter.com/silv0123/status/10730726915848806402018-12-13 00:00:0075Florian RothOBFUS,SCRIPT,SUSP9486565bca8c5af0c51f0ad8dcc8358d
1997SUSP_Office_Dropper_StringsDetects Office droppers that include a notice to enable active contentInternal Research2018-09-13 00:00:0075Florian RothFILE,MAL,OFFICE,SUSPc16fb85c66f239c0a37d86f222f3838f
1998SUSP_PDB_Strings_Keylogger_BackdoorDetects PDB strings used in backdoors or keyloggersInternal Research2018-03-23 00:00:0065Florian RothEXE,FILE,HKTL,MAL,SUSP8d52995e69499575c48870a5e015c3bb
1999SUSP_PiratedOffice_2007Detects an Office document that was created with a pirated version of MS Office 2007https://twitter.com/pwnallthethings/status/743230570440826886?lang=en2018-12-04 00:00:0040Florian RothFILE,OFFICE,SUSP5f735a9d72877ccd134931a727082232
2000SUSP_PowerShell_IEX_Download_ComboDetects strings found in sample from CN group repo leak in October 2018https://twitter.com/JaromirHorejsi/status/10470842779204116482018-10-04 00:00:0075Florian RothANOMALY,SCRIPT,SUSPe4c7e99f1968611d133183bab2996022
2001SUSP_PowerShell_String_K32_RemProcessDetects suspicious PowerShell code that uses Kernel32, RemoteProccess handles or shellcodehttps://github.com/nccgroup/redsnarf2018-03-31 00:00:0075Florian RothFILE,SCRIPT,SUSP80e6addb6d5b52ccc4ef6ff7ee8218b2
2002SUSP_Powershell_ShellCommand_May18_1Detects a supcicious powershell commandlinehttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL,SUSPe7b7619775c90a8d973214fb149a8b1f
2003SUSP_Putty_Unnormal_SizeDetects a putty version with a size different than the one provided by Simon Tatham (could be caused by an additional signature or malware)Internal Research2019-01-07 00:00:0050Florian RothEXE,FILE,SUSP741f7d491478d22036feb4ad09919355
2004SUSP_RAR_with_PDF_Script_ObfuscationDetects RAR file with suspicious .pdf extension prefix to trick usersInternal Research2019-04-06 00:00:0075Florian RothFILE,OBFUS,SUSPd4b1823ab0ea714a6c2d166c792541ce
2005SUSP_RTF_Header_AnomalyDetects malformed RTF header often used to trick mechanisms that check for a full RTF headerhttps://twitter.com/ItsReallyNick/status/9757057596181585932019-01-20 00:00:0075Florian RothFILE,SUSP283653751850fd301eaaf090edb31f1b
2006SUSP_Renamed_Dot1XtrayDetects a legitimate renamed dot1ctray.exe, which is often used by PlugX for DLL side-loadingInternal Research2018-11-15 00:00:0075Florian RothEXE,EXTVAR,FILE,SUSP11a3af23d9945c66524cb6f60545f8f1
2007SUSP_SFX_RunProgram_WScriptDetects suspicious SFX as used by Gamaredon groupInternal Research2018-09-27 00:00:0075Florian RothEXE,FILE,SUSP7406550f49d81846af5b6eeba58ffa45
2008SUSP_Scheduled_Task_BigSizeDetects suspiciously big scheduled task XML file as seen in combination with embedded base64 encoded PowerShell codeInternal Research2018-12-06 00:00:0075Florian RothFILE,SCRIPT,SUSP7d1e4d8baeb5d9ba9a9d07c84afaaa4c
2009SUSP_Script_Obfuscation_Char_ConcatDetects strings found in sample from CN group repo leak in October 2018https://twitter.com/JaromirHorejsi/status/10470842779204116482018-10-04 00:00:0075Florian RothOBFUS,SUSPdcc29ae427be97b48072b002c9a3197d
2010SUSP_Size_of_ASUS_TuningToolDetects an ASUS tuning tool with a suspicious sizehttps://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/2018-10-17 00:00:0060Florian RothEXE,FILE,SUSP877ecec366fd74453e4622c84b1137f2
2011SUSP_Win32dll_StringDetects suspicious string in executableshttps://medium.com/@Sebdraven/apt-sidewinder-changes-theirs-ttps-to-install-their-backdoor-f92604a27392018-10-24 00:00:0075Florian RothSUSP6cbeb34cdd69c3482eaf472fa94ec97f
2012SUSP_WordDoc_VBA_Macro_StringsDetects suspicious strings in Word Doc that indcate malicious use of VBA macrosInternal Research2019-02-12 00:00:0060Florian RothFILE,OFFICE,SCRIPT,SUSP578e795fe8211e16b625a652410e4b85
2013SUSP_XMRIG_StringDetects a suspicious XMRIG crypto miner executable string in filrInternal Research2018-12-28 00:00:0075Florian RothEXE,FILE,SUSP79c20663f29d32bdaa0806d8ad45f355
2014SUSP_autocad_lsp_malwareRecognizes malicious autocad files written in LISP-2019-02-04 00:00:0075John Lambert @JohnLaTwCFILE,MAL,SUSP2eb94ea2a4c876479eecb5609d77bace
2015SUSP_certificate_payloadDetects payloads that pretend to be certificateshttps://blog.nviso.be/2018/08/02/powershell-inside-a-certificate-part-3/2018-08-02 00:00:0050Didier Stevens, Florian RothFILE,SUSPe5ec1f0dd359cc6ceb9be6d900e60958
2016SUSP_shellpop_BashDetects susupicious bash commandhttps://github.com/0x00-0x00/ShellPop2018-05-18 00:00:0075Tobias MichalskiHKTL,SUSP0f2f02f4710c4b99717c88c8c857ea31
2017SVG_LoadURLDetects a tiny SVG file that loads an URL (as seen in CryptoWall malware infections)http://goo.gl/psjCCc2015-05-24 00:00:0050Florian Roth297f927a2adf5cf789f789d3f8802876
2018S_MultiFunction_Scanners_sChinese Hacktool Set - file s.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLb0e83c4f048f21a76a79c3383cfdde8c
2019Safe0ver_Shell__Safe_Mod_Bypass_By_Evilc0der_phpSemi-Auto-generated - file Safe0ver Shell -Safe Mod Bypass By Evilc0der.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL5d4914a5634d049554b64b5f16965c94
2020Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2_phpSemi-Auto-generated - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLcbc0b6e310fefbe3cf6fc574ddf7d6d6
2021Sality_Malware_Oct16Detects an unspecififed malware - October 2016Internal Research2016-10-08 00:00:0080Florian RothEXE,FILE,MAL3d3d4e84fbc3ae5f763e7fbe0b153bbd
2022Saudi_Phish_TrojanDetects a trojan used in Saudi Aramco Phishinghttps://goo.gl/Z3JUAA2017-10-12 00:00:0075Florian RothEXE,FILE,MAL4401ceb9763de9044acecbc30ae86bcb
2023ScanBox_Malware_GenericScanbox Chinese Deep Panda APT Malware http://goo.gl/MUUfjv and http://goo.gl/WXUQcP-2015-02-28 00:00:0075Florian RothAPT,CHINA,GEN,MAL1d04717f065176c0fbdb39ce2dfd7ddd
2024Scarcruft_malware_Feb18_1Detects Scarcruft malware - February 2018https://twitter.com/craiu/status/9594771297957314582018-02-03 00:00:0090Florian rootpathEXE,FILEf35dc7716fc3dea291748271c4b13750
2025SeDLL_Javascript_DecryptorDetects SeDll - DLL is used for decrypting and executing another JavaScript backdoor such as Orzhttps://goo.gl/MZ7dRg2017-10-18 00:00:0075Florian RothEXE,FILE,MALfba106c49d4ff77baa3b6a9fb38fe6d8
2026SeaDuke_SampleSeaDuke Malware - file 3eb86b7b067c296ef53e4857a74e09f12c2b84b666fc130d1f58aec18bc74b0dhttp://goo.gl/MJ0c2M2015-07-14 00:00:0070Florian RothEXE,FILE,MAL,RUSSIAd8999772c91dd2950801b5b270f91c2d
2027SecurityXploded_Producer_StringDetects hacktools by SecurityXplodedhttp://securityxploded.com/browser-password-dump.php2017-07-13 00:00:0060Florian RothEXE,FILE,HKTL4476c6ab666e84e049501aa47fa16e59
2028ServantshellDetects Servantshell malwarehttps://tinyurl.com/jmp7nrs2017-02-02 00:00:0070Arbor Networks ASERT Nov 2015EXE,FILEe2ede7d8968d16f7fd601b30faee92a1
2029SetupBDoorWebshells Auto-generated - file SetupBDoor.exe-1970-01-01 01:00:0075Florian RothMAL,WEBSHELL9e1512124f625c40e2aa0f65fb0eddcc
2030ShadowPad_nssock2Detects malicious nssock2.dll from ShadowPad incident - file nssock2.dllhttps://securelist.com/shadowpad-in-corporate-networks/81432/2017-08-15 00:00:0075Florian RothEXE,FILE9a3d68a3ade02d3e00b5738f61c8e297
2031Shamoon2_ComCompDetects Shamoon 2.0 Communication Componentshttps://goo.gl/jKIfGB2016-12-01 00:00:0070Florian Roth (with Binar.ly)EXE,FILE,MIDDLE_EASTe751182f5c9bdb90ac0c24730c64e015
2032Shamoon2_WiperDetects Shamoon 2.0 Wiper Componenthttps://goo.gl/jKIfGB2016-12-01 00:00:0070Florian RothEXE,FILE,MIDDLE_EASTa6447177a8e7461b725a752e7a2489d8
2033Shamoon_Disttrack_DropperDetects Shamoon 2.0 Disttrack Dropperhttps://goo.gl/jKIfGB2016-12-01 00:00:0070Florian RothEXE,FILE,MAL,MIDDLE_EAST9eeac6827ac5fbedb6139d2291eeba22
2034SharpCatDetects command shell SharpCat - file SharpCat.exehttps://github.com/Cn33liz/SharpCat2016-06-10 00:00:0075Florian RothEXE,FILEcb6b28395b5d370ea4ac33c3bbd0df5f
2035SharpireAuto-generated rule - file Sharpire.exehttps://github.com/0xbadjuju/Sharpire2017-09-23 00:00:0075Florian RothEXE,FILE,HKTLaf83750796220002e169740cc58ad9c1
2036ShellCrew_StreamEx_1Auto-generated rule - file 81f411415aefa5ad7f7ed2365d9a18d0faf33738617afc19215b69c23f212c07https://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar2017-02-10 00:00:0075Florian RothEXE,FILE44059c9bb021dbf159b5c34fd0a4dfc5
2037ShellCrew_StreamEx_1_msiAuto-generated rule - file msi.dllhttps://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar2017-02-10 00:00:0075Florian RothEXE,FILE7e8c2a69aa211038a75505cd1326d478
2038ShellCrew_StreamEx_1_msi_dllAuto-generated rule - file msi.dll.enghttps://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar2017-02-10 00:00:0075Florian RothFILE68f86b69d38f8cc64468665e86ae7a11
2039Shell_AspChinese Hacktool Set Webshells - file Asp.htmlhttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL2c15b1de91807aadc28bb1cc9f5258d6
2040Shifu_Banking_TrojanDetects Shifu Banking Trojanhttps://securityintelligence.com/shifu-masterful-new-banking-trojan-is-attacking-14-japanese-banks/2015-09-01 00:00:0075Florian RothEXE,FILE,MAL7513c4a0aec0365cd29c46fe0ad7973d
2041Sig_RemoteAdmin_1Detects strings from well-known APT malwareInternal Research2017-12-03 00:00:0045Florian RothAPT,EXE,FILE,HKTL7df0125ffc867d1635ecc3f36c4e1785
2042Silence_malware_1Detects malware sample mentioned in the Silence report on Securelisthttps://securelist.com/the-silence/83009/2017-11-01 00:00:0075Florian RothEXE,FILE2fe00228c7f61644ae594898b5275219
2043Silence_malware_2Detects malware sample mentioned in the Silence report on Securelisthttps://securelist.com/the-silence/83009/2017-11-01 00:00:0075Florian RothEXE,FILEe38f1402a1263a17e0cac05cba23f1b9
2044SimAttacker___Vrsion_1_0_0___priv8_4_My_friend_phpSemi-Auto-generated - file SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL4809109057249cdf09cc40e9e8b18337
2045SimShell_1_0___Simorgh_Security_MGZ_phpSemi-Auto-generated - file SimShell 1.0 - Simorgh Security MGZ.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL3331eb9cc05889b0f918349bec9e5d09
2046Simple_PHP_BackDooRWebshells Auto-generated - file Simple_PHP_BackDooR.php-1970-01-01 01:00:0075Florian RothWEBSHELLd6ce909fa562c5987d556ebc0ad1f4bc
2047Sincap_php_phpSemi-Auto-generated - file Sincap.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLe5cc523957637149a0a094a134d2ca3e
2048Sleep_Timer_ChoiceDetects malware from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSCEXE,FILE9a74e73bfded804dc0a2c05a564b4676
2049Slingshot_APT_Malware_1Detects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE,MALc51e9ed0d1f0dc1ba03736c59655279e
2050Slingshot_APT_Malware_2Detects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE,MAL2851b18981c7241d29a82c2a7aed911f
2051Slingshot_APT_Malware_3Detects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE,MAL8e0fa34cb8b4cd39d3572f05ce7bf481
2052Slingshot_APT_Malware_4Detects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE,MALe123bb2724f6b06981f3def1a527a3fc
2053Slingshot_APT_MinislingDetects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILEfa4196dfdc7819f93abff8916a2f2370
2054Slingshot_APT_Ring0_LoaderDetects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE2000cb940b6139d1f0a7e90a4b8ad74c
2055Slingshot_APT_Spork_DownloaderDetects malware from Slingshot APThttps://securelist.com/apt-slingshot/84312/2018-03-09 00:00:0075Florian RothAPT,EXE,FILE92f0ae2e94325e6244f3012b86d425d5
2056SmartniffChinese Hacktool Set - file Smartniff.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1fff8c42d015a321564fd25d8be4bc51
2057SnakeTurla_Install_SHDetects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,RUSSIAcc7e98e02db1e1898c7f99f08e5eed16
2058SnakeTurla_Installd_SHDetects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,RUSSIA076d333c251302f0dc3b97c0ab2a75fd
2059SnakeTurla_Malware_May17_1Detects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,MAL,RUSSIAe64ab97dfe01aaa1af4aa873848ca267
2060SnakeTurla_Malware_May17_2Detects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,MAL,RUSSIA2d99c25e58be7a88478024b96a8d157b
2061SnakeTurla_Malware_May17_3Detects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,MAL,RUSSIAd11143ddb82de91d69ef8c575a1b8b35
2062SnakeTurla_Malware_May17_4Detects Snake / Turla Samplehttps://goo.gl/QaOh4V2017-05-04 00:00:0075Florian RothFILE,MAL,RUSSIA4dae54c925ce8a1b61002b9100dc0310
2063SndVol_ANOMALYAnomaly rule looking for certain strings in a system file (maybe false positive on certain systems) - file SndVol.exenot set2015-03-16 00:00:0075Florian RothANOMALY,EXTVAR,REQ_PRIVATE,SUSP9b81e915501f032dae537af5e56c8277
2064Sniffer_analyzer_SSClone_1210_full_versionChinese Hacktool Set - file Sniffer analyzer SSClone 1210 full version.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL8d6eded396110038a3bf1288d1f9fcf6
2065SoakSoak_Infected_WordpressDetects a SoakSoak infected Wordpress site http://goo.gl/1GzWUXhttp://goo.gl/1GzWUX2014-12-15 00:00:0060Florian RothOFFICE,WEBSHELLae0273466952fb5899a5eef34cf5121c
2066Sofacy_AZZY_Backdoor_HelperDLLDropped C&C helper DLL for AZZY 4.3https://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,MAL,RUSSIA9633e2bb889f3bb7ed2bb332b5981d55
2067Sofacy_AZZY_Backdoor_Implant_1AZZY Backdoor Implant 4.3 - Sample 1https://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,MAL,RUSSIA8e08f404cbc943c9b61bf55e4efaa936
2068Sofacy_Bundestag_BatchSofacy Bundestags APT Batch Scripthttp://dokumente.linksfraktion.de/inhalt/report-orig.pdf2015-06-19 00:00:0070Florian RothAPT,RUSSIA87a07da93f25cb0b1bcc4cf38963d75b
2069Sofacy_Campaign_Mal_Feb18_cdnverDetects Sofacy malwarehttps://twitter.com/ClearskySec/status/9609247553553694722018-02-07 00:00:0075Florian RothEXE,FILE,RUSSIAf33cf799f92109d2249f2adbf8912538
2070Sofacy_CollectorStealer_Gen1Generic rule to detect Sofacy Malware Collector Stealerhttps://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,GEN,MAL,RUSSIA320a8c4dd6ad40cf6a222872fb93b110
2071Sofacy_CollectorStealer_Gen2File collectors / USB stealers - Generichttps://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,GEN,RUSSIA79c69dd60ce892112bf1a6b2e6b5659d
2072Sofacy_CollectorStealer_Gen3File collectors / USB stealers - Generichttps://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,GEN,RUSSIA0747aafbcacb322a7843ea369bd1a0ad
2073Sofacy_Fybis_ELF_Backdoor_Gen1Detects Sofacy Fysbis Linux Backdoor_Naikon_APT_Sample1http://researchcenter.paloaltonetworks.com/2016/02/a-look-into-fysbis-sofacys-linux-backdoor/2016-02-13 00:00:0080Florian RothAPT,FILE,LINUX,MAL,RUSSIA1d45ed1deb42371c07abe06fbe61306b
2074Sofacy_Fysbis_ELF_Backdoor_Gen2Detects Sofacy Fysbis Linux Backdoorhttp://researchcenter.paloaltonetworks.com/2016/02/a-look-into-fysbis-sofacys-linux-backdoor/2016-02-13 00:00:0080Florian RothFILE,LINUX,MAL,RUSSIA1ebf1a2a541d126435243e64bebe5bcf
2075Sofacy_Jun16_Sample1Detects Sofacy Malware mentioned in PaloAltoNetworks APT reporthttp://goo.gl/mzAa972016-06-14 00:00:0085Florian RothAPT,EXE,FILE,MAL,RUSSIAe4369712d5cd76271664023b132d9529
2076Sofacy_Jun16_Sample2Detects Sofacy Malware mentioned in PaloAltoNetworks APT reporthttp://goo.gl/mzAa972016-06-14 00:00:0085Florian RothAPT,EXE,FILE,MAL,RUSSIA56028fb4348377290d1040278b0e6535
2077Sofacy_Jun16_Sample3Detects Sofacy Malware mentioned in PaloAltoNetworks APT reporthttp://goo.gl/mzAa972016-06-14 00:00:0085Florian RothAPT,EXE,FILE,MAL,RUSSIAd455bf85511ad1b62fce95aaf7234a9a
2078Sofacy_Mal2Sofacy Group Malware Sample 2http://dokumente.linksfraktion.de/inhalt/report-orig.pdf2015-06-19 00:00:0070Florian RothEXE,FILE,MAL,RUSSIA7c26b52c02228536c3c110686e625fff
2079Sofacy_Mal3Sofacy Group Malware Sample 3http://dokumente.linksfraktion.de/inhalt/report-orig.pdf2015-06-19 00:00:0070Florian RothEXE,FILE,MAL,RUSSIAb26495941e6e9513a488210e4827853a
2080Sofacy_Malware_AZZY_Backdoor_1AZZY Backdoor - Sample 1https://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,MAL,RUSSIAc48ef6d314d2b34d736a1c5cba5e08a5
2081Sofacy_Malware_StrangeSpacesDetetcs strange strings from Sofacy malware with many spaceshttps://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/2015-12-04 00:00:0075Florian RothEXE,FILE,MAL,RUSSIAf38dd724ab6dbd70680a55fac6b8a3d2
2082Sofacy_Oct17_1Detects Sofacy malware reported in October 2017http://blog.talosintelligence.com/2017/10/cyber-conflict-decoy-document.html2017-10-23 00:00:0075Florian RothEXE,FILE,RUSSIAe7843dbb6e25d553856ac1e727a85dba
2083Sofacy_Oct17_2Detects Sofacy malware reported in October 2017http://blog.talosintelligence.com/2017/10/cyber-conflict-decoy-document.html2017-10-23 00:00:0075Florian RothEXE,FILE,RUSSIA01fa400317774bee99273b16214bfb17
2084Sofacy_Trojan_Loader_Feb18_1Sofacy Activity Feb 2018https://www.reverse.it/sample/e3399d4802f9e6d6d539e3ae57e7ea9a54610a7c4155a6541df8e94d67af086e?environmentId=1002018-03-01 00:00:0075Florian RothEXE,FILE,MAL,RUSSIA236d4994c0251bf578f3f9e417958616
2085Sphinx_Moth_cudacrtsphinx moth threat group file cudacrt.dllwww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SAEXE,FILEd502c7f5c0852c84fa9577dd49b93c2d
2086Sphinx_Moth_h2tsphinx moth threat group file h2t.datwww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SA (modified by Florian Roth)EXE,FILE31e80a659c3e68201fb719dd233c7900
2087Sphinx_Moth_iastor32sphinx moth threat group file iastor32.exewww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SAEXE,FILEc1947154d982687ac228b7a276c9678a
2088Sphinx_Moth_kerberos32sphinx moth threat group file kerberos32.dllwww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SA (modified by Florian Roth)EXE,FILEe53e6a49d6839b3a87f6d08429e67091
2089Sphinx_Moth_kerberos64sphinx moth threat group file kerberos64.dllwww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SA (modified by Florian Roth)EXE,FILEe43e3baf39b8fb550a81f2ed90454f6a
2090Sphinx_Moth_nvcplexsphinx moth threat group file nvcplex.datwww.kudelskisecurity.com2015-08-06 00:00:0075Kudelski Security - Nagravision SAEXE,FILE0239ab675cecf319d7240ac73be9265d
2091SplitJoin_V1_3_3_rar_Folder_3Disclosed hacktool set (old stuff) - file splitjoin.exe-2014-11-23 00:00:0060Florian RothHKTLac25e8c7953de30a7887ccd55431f352
2092SqlDbx_zhsChinese Hacktool Set - file SqlDbx_zhs.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL1dbf66fc1e7be98eae5780e2c9ee0c02
2093StealthWasp_s_Basic_PortScanner_v1_2Auto-generated rule on file StealthWasp's Basic PortScanner v1.2.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLc441ed23b05b0403ddc27905656a57e2
2094StegoKatzEncoded Mimikatz in other file typeshttps://goo.gl/jWPBBY2015-09-11 00:00:0070Florian Rothfd1a1336c374b4fb3becad053c5d4470
2095StoneDrillDetects malware from StoneDrill threat reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/2017-03-07 00:00:0075Florian RothEXE,FILE,MIDDLE_EAST6c78e0292ca27cd9e6bfc83257102317
2096StoneDrill_BAT_1Rule to detect Batch file from StoneDrill reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/1970-01-01 01:00:0075Florian RothFILE,MIDDLE_EAST769284956c5e9fe219ad2f39fd49d0af
2097StoneDrill_Malware_2Detects malware from StoneDrill threat reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/2017-03-07 00:00:0075Florian RothEXE,FILE,MAL,MIDDLE_EASTc0f33936dafe4c1151d2665646ae8d0e
2098StoneDrill_Service_InstallRule to detect Batch file from StoneDrill reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/1970-01-01 01:00:0075Florian RothMIDDLE_EAST7db335ec3db5560107d7724d26d91c89
2099StoneDrill_VBS_1Detects malware from StoneDrill threat reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/2017-03-07 00:00:0075Florian RothMIDDLE_EAST,SCRIPTea4fd67066a84799d5d5c4b42f319818
2100StoneDrill_main_subRule to detect StoneDrill (decrypted) sampleshttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/1970-01-01 01:00:0075Kaspersky LabFILE,MIDDLE_EASTf8e95a1a42f2cad0ed411bb57c3f83f9
2101StoneDrill_ntssrvr32Detects malware from StoneDrill threat reporthttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/2017-03-07 00:00:0075Florian RothEXE,FILE,MIDDLE_EAST334f70d8287bd1bdf2c3a32b287e3fac
2102StreamEx_ShellCrewDetects a https://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar2017-02-09 00:00:0080Cylance37f1c675c0b219433486b191c7ac47db
2103StuxNet_Malware_1Stuxnet Sample - file malware.exeInternal Research2016-07-09 00:00:0075Florian RothMAL28e22abcfccf736aefa1c5e69c1bb9ec
2104StuxNet_dllStuxnet Sample - file dll.dllInternal Research2016-07-09 00:00:0075Florian RothEXE,FILE1fda4e52c3b2a3a18c1688ba912ec7a6
2105Stuxnet_Malware_2Stuxnet Sample - file 63e6b8136058d7a06dfff4034b4ab17a261cdf398e63868a601f77ddd1b32802Internal Research2016-07-09 00:00:0075Florian RothEXE,FILE,MAL0b85f172255e76d5d38236d5e745915d
2106Stuxnet_Malware_3Stuxnet Sample - file ~WTR4141.tmpInternal Research2016-07-09 00:00:0075Florian RothEXE,FILE,MAL71db1865eae739f98c2c96de0047000f
2107Stuxnet_Malware_4Stuxnet Sample - file 0d8c2bcb575378f6a88d17b5f6ce70e794a264cdc8556c8e812f0b5f9c709198Internal Research2016-07-09 00:00:0075Florian RothEXE,FILE,MALcd22b5c9434eeb93ac793444cc98e7de
2108Stuxnet_Shortcut_toStuxnet Sample - file Copy of Shortcut to.lnkInternal Research2016-07-09 00:00:0075Florian RothFILE7e2f91cdf7b0a55b9b77656905b684d6
2109Stuxnet_maindll_decrypted_unpackedStuxnet Sample - file maindll.decrypted.unpacked.dll_Internal Research2016-07-09 00:00:0075Florian Rothb07a6dd29358301d38c75be58835f3fd
2110Stuxnet_s7hkimdbStuxnet Sample - file s7hkimdb.dllInternal Research2016-07-09 00:00:0075Florian RothEXE,FILE74df3588963db776f733d5678a63629d
2111Suckfly_Nidiran_Gen_1Detects Suckfly Nidiran Trojanhttps://www.symantec.com/connect/blogs/suckfly-revealing-secret-life-your-code-signing-certificates2018-01-28 00:00:0075Florian RothEXE,FILE,GEN,MAL171722d7db6f3a7fa05e094a123e3f6e
2112Suckfly_Nidiran_Gen_2Detects Suckfly Nidiran Trojanhttps://www.symantec.com/connect/blogs/suckfly-revealing-secret-life-your-code-signing-certificates2018-01-28 00:00:0075Florian RothEXE,FILE,GEN,MALea0ceae36712ef05cb902b84d97d4812
2113Suckfly_Nidiran_Gen_3Detects Suckfly Nidiran Trojanhttps://www.symantec.com/connect/blogs/suckfly-revealing-secret-life-your-code-signing-certificates2018-01-28 00:00:0075Florian RothEXE,FILE,GEN,MAL664b38ad4af5129e5ba7ff1459a9a9c6
2114SunOrcal_Malware_Nov17_1Detects Reaver malware mentioned in PaloAltoNetworks reporthttps://researchcenter.paloaltonetworks.com/2017/11/unit42-new-malware-with-ties-to-sunorcal-discovered/2017-11-11 00:00:0075Florian RothEXE,FILE,MAL67205f071c60516398227ad1733a7134
2115SuperScan4Auto-generated rule on file SuperScan4.exe-1970-01-01 01:00:0075yarGen Yara Rule Generator by Florian RothHKTLa5ea5ef3952d0862d6042f32f34d25c6
2116Susp_Indicators_EXEDetects packed NullSoft Inst EXE with characteristics of NetWire RAThttps://pastebin.com/8qaiyPxs2018-01-05 00:00:0060Florian RothFILE,MALaa3013e12793b0b66febe9e587b38bb0
2117Susp_PowerShell_Sep17_1Detects suspicious PowerShell script in combo with VBS or JS Internal Research2017-09-30 00:00:0060Florian RothSCRIPTa06561bfd6d7954b20d08c962be5584c
2118Susp_PowerShell_Sep17_2Detects suspicious PowerShell script in combo with VBS or JS Internal Research2017-09-30 00:00:0075Florian RothFILE,SCRIPT9f959a750519450736bdec639faed105
2119Suspicious_AutoIt_by_MicrosoftDetects a AutoIt script with Microsoft identificationInternal Research - VT2017-12-14 00:00:0060Florian RothEXE,FILEb1ab19499a3bc25877a2c0033f156769
2120Suspicious_BAT_StringsDetects a string also used in Netwire RAT auxilliaryhttps://pastebin.com/8qaiyPxs2018-01-05 00:00:0060Florian RothMAL096288f1c59e2d39359bac6c492e8783
2121Suspicious_JS_script_contentDetects suspicious statements in JavaScript filesResearch on Leviathan https://goo.gl/MZ7dRg2017-12-02 00:00:0070Florian RothSCRIPTc4ff8b7f0a9876c0151b731812a220cc
2122Suspicious_PowerShell_Code_1Detects suspicious PowerShell codeInternal Research2017-02-22 00:00:0060Florian RothSCRIPTc7d67bd9c5e2af871beaee2f841be620
2123Suspicious_PowerShell_WebDownload_1Detects suspicious PowerShell code that downloads from web sitesInternal Research2017-02-22 00:00:0060Florian RothSCRIPT2b698db643c0d3613aa4dfd35f5b6b61
2124Suspicious_Script_Running_from_HTTPDetects a suspicious https://www.hybrid-analysis.com/sample/a112274e109c5819d54aa8de89b0e707b243f4929a83e77439e3ff01ed218a35?environmentId=1002017-08-20 00:00:0050Florian Roth9aea42700ef9b213c29a5e46d66c2707
2125Suspicious_Size_chrome_exeDetects uncommon file size of chrome.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE6c72d59dab450e4929dfc4d9f9e9de3c
2126Suspicious_Size_csrss_exeDetects uncommon file size of csrss.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILEf0a250c305180729278e5eb73dd32e4a
2127Suspicious_Size_explorer_exeDetects uncommon file size of explorer.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE95082eda1cadc052e1967d974ece09bf
2128Suspicious_Size_firefox_exeDetects uncommon file size of firefox.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILEb3a5a70652057f334fc818a110efe609
2129Suspicious_Size_iexplore_exeDetects uncommon file size of iexplore.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILEb0957b83e22c8e5561edb6b8a3e25ac5
2130Suspicious_Size_igfxhk_exeDetects uncommon file size of igfxhk.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE187e40d82d4acbf71bce459af350df38
2131Suspicious_Size_java_exeDetects uncommon file size of java.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE8dfb790413e4c8e65e5705844ce1973d
2132Suspicious_Size_lsass_exeDetects uncommon file size of lsass.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE6f52d255c6f1a702d591eacc111dffd7
2133Suspicious_Size_rundll32_exeDetects uncommon file size of rundll32.exe-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILE50f572aa9ac04739c15e48a7e2b663e6
2134Suspicious_Size_servicehost_dllDetects uncommon file size of servicehost.dll-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILEf753d55c8975223c3f57dbe21139e075
2135Suspicious_Size_smss_exeDetects uncommon file size of smss.exe-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILE9c5b6b04b8028b9a74c539bee18024e2
2136Suspicious_Size_spoolsv_exeDetects uncommon file size of spoolsv.exe-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILE2c7920d6862050fb0399aabc49a32aca
2137Suspicious_Size_svchost_exeDetects uncommon file size of svchost.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE1a3a12a2135e83b6f547d7adf0f703c9
2138Suspicious_Size_taskhost_exeDetects uncommon file size of taskhost.exe-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILE6289839a09908cf668596fda8471aa01
2139Suspicious_Size_wininit_exeDetects uncommon file size of wininit.exe-2015-12-23 00:00:0060Florian RothEXE,EXTVAR,FILE47b765ada4ccb737a431b6dd7059821b
2140Suspicious_Size_winlogon_exeDetects uncommon file size of winlogon.exe-2015-12-21 00:00:0060Florian RothEXE,EXTVAR,FILE4ca18eae8a30fc1ad6ee48545d348145
2141SwitchSnifferChinese Hacktool Set - file SwitchSniffer.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLe315b09aa94a1e4210b172db191f10a1
2142Sword1_5Chinese Hacktool Set - file Sword1.5.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL2a4fc08892f1dea781e0560ece174ebb
2143SysInterals_PipeList_NameChangedDetects NirSoft PipeListhttps://goo.gl/Mr6M2J2016-06-04 00:00:0090Florian RothEXE,EXTVAR,FILE0e6e7da59744c2deecf14acd1dae4219
2144SysInternals_Tool_AnomalySysInternals Tool Anomaly - does not contain Mark Russinovich as authorInternal Research2016-12-06 00:00:0050Florian RothEXE,FILEcddeac6cfa8f9d025ab09b0b44d0fd5b
2145TA17_293A_Hacktool_Exploit_MS16_032Auto-generated rule - file 9b97290300abb68fb48480718e6318ee2cdd4f099aa6438010fb2f44803e0b58https://www.us-cert.gov/ncas/alerts/TA17-293A2017-10-21 00:00:0075Florian RothHKTLaf8e49c50dab76951d47787644989925
2146TA17_293A_Hacktool_PS_1Auto-generated rule - file 72a28efb6e32e653b656ca32ccd44b3111145a695f6f6161965deebbdc437076https://www.us-cert.gov/ncas/alerts/TA17-293A2017-10-21 00:00:0075Florian RothHKTL30d6588fb949da248592a7e6e35ae7a5
2147TA17_293A_Hacktool_Touch_MAC_modificationAuto-generated rule - file 070d7082a5abe1112615877214ec82241fd17e5bd465e24d794a470f699af88ehttps://www.us-cert.gov/ncas/alerts/TA17-293A2017-10-21 00:00:0075Florian RothEXE,FILE,HKTL503935641379608c91828dae522a88fd
2148TA17_293A_Query_Javascript_Decode_Function-https://www.us-cert.gov/ncas/alerts/TA17-293A1970-01-01 01:00:0075other (modified by Florian Roth)2ab53fdf8d76be5dc4b3f6a4ef5e881f
2149TA17_293A_Query_XML_Code_MAL_DOC-https://www.us-cert.gov/ncas/alerts/TA17-293A1970-01-01 01:00:0075other (modified by Florian Roth)FILE4c881a7123ebbb20350f9966af923e68
2150TA17_293A_Query_XML_Code_MAL_DOC_PT_2-https://www.us-cert.gov/ncas/alerts/TA17-293A1970-01-01 01:00:0075other (modified by Florian Roth)FILE67a7f44c74b9179e3ea93bfe8e9473a2
2151TA17_293A_energetic_bear_api_hashing_toolEnergetic Bear API Hashing Tool-1970-01-01 01:00:0075CERT RE TeamEXE,FILE,RUSSIA2e53603ebc893a0e2babe154026c8656
2152TA17_293A_malware_1inveigh pen testing tools & related artifactshttps://www.us-cert.gov/ncas/alerts/TA17-293A2017-07-17 00:00:0075US-CERT Code Analysis Team (modified by Florian Roth)b0bc1690ae0009f1e4a41a7e3fa5a17a
2153TA17_318A_rc4_stack_key_fallchillHiddenCobra FallChill - rc4_stack_keyhttps://www.us-cert.gov/ncas/alerts/TA17-318B2017-11-15 00:00:0075US CERTFILE,NK6750afdec3e7d80db3ed7debf698ac37
2154TA17_318A_success_fail_codes_fallchillHiddenCobra FallChill - success_fail_codeshttps://www.us-cert.gov/ncas/alerts/TA17-318B2017-11-15 00:00:0075US CERTFILE,NKc07efde31f931d489088e5fcf3f6e331
2155TA17_318B_volgmerMalformed User Agent in Volgmer malwarehttps://www.us-cert.gov/ncas/alerts/TA17-318B2017-11-15 00:00:0075US CERTFILE707e4be5aafdcfdb2f866ca2c2afc525
2156TA18_074A_screenDetects malware mentioned in TA18-074Ahttps://www.us-cert.gov/ncas/alerts/TA18-074A2018-03-16 00:00:0075Florian RothEXE,FILE8856226c92431fc35f2f523d6fd0e8de
2157TA18_074A_scriptsDetects malware mentioned in TA18-074Ahttps://www.us-cert.gov/ncas/alerts/TA18-074A2018-03-16 00:00:0075Florian Roth15e9e3122af3d2155ccd51db2f34284b
2158TA459_Malware_May17_1Detects TA459 related malwarehttps://goo.gl/RLf9qU2017-05-31 00:00:0075Florian RothFILE,MAL1873db263183fe132c6b0dc6a4509572
2159TA459_Malware_May17_2Detects TA459 related malwarehttps://goo.gl/RLf9qU2017-05-31 00:00:0075Florian RothEXE,FILE,MALe54af08137beca67bdf30509009cb44d
2160TRITON_ICS_FRAMEWORKTRITON framework recovered during Mandiant ICS incident responsehttps://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html1970-01-01 01:00:0075nicholas.carr @itsreallynick9d8a900242d6c3aacbad519b78d10a9a
2161TSCookie_RATDetects TSCookie RAThttp://blog.jpcert.or.jp/2018/03/malware-tscooki-7aa0.html2018-03-06 00:00:0075Florian RothEXE,FILE,MAL48c004c851054e842d3c6ca5e2596262
2162TeleBots_CredRaptor_Password_StealerDetects TeleBots malware - CredRaptor Password Stealerhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothEXE,FILE,MAL7a9a731281c8b7b94f4ace05862302b6
2163TeleBots_IntercepterNGDetects TeleBots malware - IntercepterNGhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothEXE,FILEa6ae30b0672398537e60091e180d3621
2164TeleBots_KillDisk_1Detects TeleBots malware - KillDiskhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothEXE,FILE3c684760edcaed20657a8528fb09c608
2165TeleBots_KillDisk_2Detects TeleBots malware - KillDiskhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothEXE,FILE619e060c8196d5dd9df2b7f471cc393f
2166TeleBots_VBS_Backdoor_1Detects TeleBots malware - VBS Backdoorhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothFILE,MAL,SCRIPTbace9bddef25c42c1aeb80d628bbd7e5
2167TeleBots_VBS_Backdoor_2Detects TeleBots malware - VBS Backdoorhttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothFILE,MAL,SCRIPTb259c8d9a0c75a655c4dc4ff5be098bf
2168TeleBots_Win64_Spy_KeyLogger_GDetects TeleBots malware - Win64 Spy KeyLogger Ghttps://goo.gl/4if3HG2016-12-14 00:00:0075Florian RothEXE,FILE5416c337442a31256d14b5c624a4c1a5
2169TeleDoor_BackdoorDetects the TeleDoor Backdoor as used in Petya Attack in June 2017https://goo.gl/CpfJQQ2017-07-05 00:00:0075Florian RothEXE,FILE,MAL,RANSOM5c47701790d58c1a3dc110c11d0f6bc4
2170TempRacerDetects privilege escalation tool - file TempRacer.exehttp://www.darknet.org.uk/2016/03/tempracer-windows-privilege-escalation-tool/2016-03-30 00:00:0075Florian RothEXE,FILE444fc985676383a5c230ddbd371478a0
2171Test_php_phpSemi-Auto-generated - file Test.php.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL575d6621bd1ac5ce7b8265751c43e4f3
2172ThreatGroup3390_C2Threat Group 3390 APT - C2 Serverhttp://snip.ly/giNB2015-08-06 00:00:0060Florian RothAPT,EXE,FILE71a3c27eb214d148ef959c401fa7f56d
2173ThreatGroup3390_StringsThreat Group 3390 APT - Stringshttp://snip.ly/giNB2015-08-06 00:00:0060Florian RothAPT4cbfc616994285a689e1162ced8b605f
2174TidePool_MalwareDetects TidePool malware mentioned in Ke3chang report by Palo Alto Networkshttp://goo.gl/m2CXWR2016-05-24 00:00:0075Florian RothEXE,FILE,MAL83cde3c24a6049da490ead989c06d2a5
2175Tiny_Network_Tool_GenericTiny tool with suspicious function imports. (Rule based on WinEggDrop Scanner samples)-2014-08-10 00:00:0040Florian RothEXE,FILE,GEN,HKTLba73058cbb7abaf4b72d6e50d3a22a3f
2176Tofu_BackdoorDetects Tofu Trojanhttps://www.cylance.com/en_us/blog/the-deception-project-a-new-japanese-centric-threat.html2017-02-28 00:00:0075CylanceMAL8b0bc525138b76084451dd500471cd56
2177Tool_aspSemi-Auto-generated - file Tool.asp.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELLa1e577e5a60f2f83005087ccf5515009
2178Tools_2014Chinese Hacktool Set - file 2014.jsphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL2f71c74b78406e0fbb4e804e3bff1f9c
2179Tools_2015Chinese Hacktool Set - file 2015.jsphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELLe752709d4e82ba4a03537285858d1cd4
2180Tools_cmdChinese Hacktool Set - file cmd.jSphttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,HKTL,WEBSHELL27c22317a09e7438817750ace9bcea30
2181Tools_scanChinese Hacktool Set - file scan.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLeb42635c5d6161746b1fa2899e78738b
2182Tools_unknownChinese Hacktool Set - file unknown.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL174aafcdc856dc5432209095fcbe84f7
2183Tools_xportChinese Hacktool Set - file xport.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL02223614d37c280168d594f4dcd07892
2184TopHat_BATAuto-generated rule - file cgen.bathttps://researchcenter.paloaltonetworks.com/2018/01/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/#appendix2018-01-29 00:00:0075Florian Rothdeca5eb94fb296d708cfdae725ad8e34
2185TopHat_Malware_Jan18_1Detects malware from TopHat campaignhttps://researchcenter.paloaltonetworks.com/2018/01/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/#appendix2018-01-29 00:00:0075Florian RothEXE,FILE,MAL8936ebb268801ef85f9639d309d69a5e
2186TopHat_Malware_Jan18_2Auto-generated rule - file e.exehttps://researchcenter.paloaltonetworks.com/2018/01/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/#appendix2018-01-29 00:00:0075Florian RothEXE,FILE,MAL9073fce95160eb5d15212bd6910a7253
2187Triton_trilogDetects Triton APT malware - file trilog.exehttps://goo.gl/vtQoCQ2017-12-14 00:00:0075Florian RothAPT,EXE,FILE60051ea34a065dbc2e1e80f00baff4dd
2188TrojanDownloaderTrojan Downloader - Flash Exploit Feb15http://goo.gl/wJ8V1I2015-02-11 00:00:0060Florian RothMAL793ccdf9dead6254474d3ceaaec9fa58
2189Trojan_ISMRAT_genISM RAThttps://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2017/february/ism-rat/1970-01-01 01:00:0075Ahmed ZakiFILE,MAL54c9feebf896f96ef6736b6263793b02
2190Trojan_Win32_AdupibAdupib SSL Backdoor-1970-01-01 01:00:0075MicrosoftMALc7a6f308dadc7f9243ded9908f76a42f
2191Trojan_Win32_Dipsind_BDipsind Family-1970-01-01 01:00:0075MicrosoftMAL9a5156afd69076e0b12497bddaa7167a
2192Trojan_Win32_PlaKeylog_BKeylogger component-1970-01-01 01:00:0075MicrosoftHKTL,MAL18ebceaa52fb9401e72e360c4a7433c0
2193Trojan_Win32_PlaLsaLogLoader / possible incomplete LSA Password Filter-1970-01-01 01:00:0075MicrosoftMAL49c45d971d6dc0931173ef9f6aa5930b
2194Trojan_Win32_PlaSrvHotpatching Injector-1970-01-01 01:00:0075MicrosoftHKTL,MAL3ef35de6e8feb171398c9384e9a909aa
2195Trojan_Win32_PlabitInstaller component-1970-01-01 01:00:0075MicrosoftMAL66bd8613311e8bafcf8e2a9d6f62b412
2196Trojan_Win32_Placisc2Dipsind variant-1970-01-01 01:00:0075MicrosoftMAL10ad5d2c95a0fb4be9006e09a8cea1be
2197Trojan_Win32_Placisc3Dipsind variant-1970-01-01 01:00:0075MicrosoftMALb67774ec3d21094f43158eceb6fd551f
2198Trojan_Win32_Placisc4Installer for Dipsind variant-1970-01-01 01:00:0075MicrosoftMAL49bb909fd8110319a769db4f0ef423a8
2199Trojan_Win32_PlagicomInstaller component-1970-01-01 01:00:0075MicrosoftMAL0556c52a53b0c94d4066ed7fe867885a
2200Trojan_Win32_PlagonDipsind variant-1970-01-01 01:00:0075MicrosoftMALf939f978e0642336688eee82a300e84d
2201Trojan_Win32_Plainst2Zc tool-1970-01-01 01:00:0075MicrosoftMALd6df02ca867587d65a409faae650c8c2
2202Trojan_Win32_PlainstInstaller component-1970-01-01 01:00:0075MicrosoftMAL5a1fa0ad786a2adf1ec4b88be93c51d6
2203Trojan_Win32_PlakelogRaw-input based keylogger-1970-01-01 01:00:0075MicrosoftHKTL,MALab422137cac47037e998b17c8adcd752
2204Trojan_Win32_PlaklogHook-based keylogger-1970-01-01 01:00:0075MicrosoftHKTL,MALb95652fe0cd865478dfa98c9e72f2aa0
2205Trojan_Win32_PlakpeerZc tool v2-1970-01-01 01:00:0075MicrosoftMAL1b9d54792835de3b0f601cb0f4ded253
2206Trojan_Win32_PlakpersInjector / loader component-1970-01-01 01:00:0075MicrosoftHKTL,MALe7f8e092cdea19e881c413728a1f94c0
2207Trojan_Win32_PlapiioJPin backdoor-1970-01-01 01:00:0075MicrosoftMAL2180c059f25ae9741b82c9a440d004e1
2208Trojan_Win32_PlaplexVariant of the JPin backdoor-1970-01-01 01:00:0075MicrosoftMAL1dbdc9d4cb59d79821857bf323f6d1c9
2209Trojan_Win32_PlatualInstaller component-1970-01-01 01:00:0075MicrosoftMAL8296e42cd04475f02f964156d5756608
2210TurlaMosquito_Mal_1Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA727f55bfcaece96cce1b1522e761beb9
2211TurlaMosquito_Mal_2Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIAe61b480ad856a1c9faa3fbe05d4c89da
2212TurlaMosquito_Mal_3Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA1072204aa49b4b53d643bbd0e1cb53ba
2213TurlaMosquito_Mal_4Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA05eeef2b4696db27aaee7b10fd75943f
2214TurlaMosquito_Mal_5Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA363f83194e110f17a877fd70ecf582d6
2215TurlaMosquito_Mal_6Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA2cd1317774544fb2db23fd0a3b21b481
2216TurlaMosquito_Mal_7Detects malware sample from Turla Mosquito reporthttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf2018-02-22 00:00:0075Florian RothEXE,FILE,RUSSIA97c3c889e4e17cb4ef3f37b075d039ee
2217Turla_APT_Malware_Gen1Detects Turla malware (based on sample used in the RUAG APT case)https://www.govcert.admin.ch/blog/22/technical-report-about-the-ruag-espionage-case2016-06-09 00:00:0075Florian RothAPT,EXE,FILE,MAL,RUSSIA378d747a8b1d50f9e8a633ea9772dc0b
2218Turla_APT_Malware_Gen2Detects Turla malware (based on sample used in the RUAG APT case)https://www.govcert.admin.ch/blog/22/technical-report-about-the-ruag-espionage-case2016-06-09 00:00:0075Florian RothAPT,EXE,FILE,MAL,RUSSIA8d2782742892856d8c1acd6fea08365d
2219Turla_APT_Malware_Gen3Detects Turla malware (based on sample used in the RUAG APT case)https://www.govcert.admin.ch/blog/22/technical-report-about-the-ruag-espionage-case2016-06-09 00:00:0075Florian RothAPT,EXE,FILE,MAL,RUSSIA2ca12d50f35b0a3dd61f9ab225d24fcb
2220Turla_APT_srsvcDetects Turla malware (based on sample used in the RUAG APT case)https://www.govcert.admin.ch/blog/22/technical-report-about-the-ruag-espionage-case2016-06-09 00:00:0075Florian RothAPT,EXE,FILE,RUSSIA9a65217e2c2f000a82a7e970a2423316
2221Turla_KazuarRATDetects Turla Kazuar RAT described by DrunkBinaryhttps://twitter.com/DrunkBinary/status/9829698919753195532018-04-08 00:00:0075Markus Neis / Florian RothEXE,FILE,MAL,RUSSIAab3353bc76cde790d9d81e8b32e6adda
2222Turla_Mal_Script_Jan18_1Detects Turla malicious scripthttps://ghostbin.com/paste/jsph72018-01-19 00:00:0075Florian RothRUSSIAef37261925ac30cf911b149dbb71c943
2223Txt_SqlChinese Hacktool Set - Webshells - file Sql.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL8fa7274db66e2e87e18d2dca17f4c646
2224Txt_asp1Chinese Hacktool Set - Webshells - file asp1.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLc6dc0646aabb1c6f72bd7190df1f4905
2225Txt_aspChinese Hacktool Set - Webshells - file asp.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,FILE,HKTL,WEBSHELL3087ed42affc59da61074c956b9cbc4a
2226Txt_aspx1Chinese Hacktool Set - Webshells - file aspx1.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL976f3a2d1dc4386f6d690f10d576a977
2227Txt_aspxChinese Hacktool Set - Webshells - file aspx.jpghttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL8fd060db4dff085aafd95878ac8048f6
2228Txt_aspxlcxChinese Hacktool Set - Webshells - file aspxlcx.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,FILE,HKTL,WEBSHELL321475d45d8961f00040cfb59c9f8d5d
2229Txt_aspxtagChinese Hacktool Set - Webshells - file aspxtag.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLbe5197be879593e336d9eacc4cd1d39b
2230Txt_ftpChinese Hacktool Set - Webshells - file ftp.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL306be15e84b1753ac2fb84e74398f243
2231Txt_helloChinese Hacktool Set - Webshells - file hello.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL340e1aa11e31fe4cb2af1487501105af
2232Txt_jspChinese Hacktool Set - Webshells - file jsp.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLdfdab06d5cdf7a403b8ecf41eaf8c735
2233Txt_jspcmdChinese Hacktool Set - Webshells - file jspcmd.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL31e6f775d75c45c836510f95de6582ad
2234Txt_lcxChinese Hacktool Set - Webshells - file lcx.chttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLc170895cff3910d4e3bbd54a4a1ac640
2235Txt_phpChinese Hacktool Set - Webshells - file php.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL9c1647795392ad77e6c495cf932d11ae
2236Txt_php_2Chinese Hacktool Set - Webshells - file php.htmlhttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELL3a32b2ca6a06fd3383f24d4a35eab171
2237Txt_shellChinese Hacktool Set - Webshells - file shell.chttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLfc0edc8bf5396970210522da938968dd
2238Txt_xiaoChinese Hacktool Set - Webshells - file xiao.txthttp://tools.zjqhr.com/2015-06-14 00:00:0075Florian RothCHINA,HKTL,WEBSHELLe8441f74856ea3d68a3f2e39e0bd46a1
2239Typical_Malware_String_TransformsDetects typical strings in a reversed or otherwise modified formInternal Research2016-07-31 00:00:0060Florian RothEXE,FILE,MAL495b5bbeee3e6ca4a40fa9b527941cc9
2240Tzddos_DDoS_Tool_CNDisclosed hacktool set - file tzddos-2014-11-17 00:00:0060Florian RothHKTL0951f1d147e0d88ff5e5a130057de058
2241UACElevatorUACElevator bypassing UAC - file UACElevator.exehttps://github.com/MalwareTech/UACElevator2015-05-14 00:00:0075Florian RothEXE,FILEf7be5a94c923e915ba6adb5346f171a3
2242UACME_AkagiRule to detect UACMe - abusing built-in Windows AutoElevate backdoorhttps://github.com/hfiref0x/UACME2015-05-14 00:00:0060Florian RothMALf38734da4427adc7679421863eb9810f
2243UACME_Akagi_2Detects Windows User Account Control Bypass - from files Akagi32.exe, Akagi64.exehttps://github.com/hfiref0x/UACME2017-02-03 00:00:0080Florian RothEXE,FILE26b20569c1f315363b7c07b3664ff069
2244UBoatRATDetects UBoat RAT Sampleshttps://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/2017-11-29 00:00:0075Florian RothEXE,FILE,MALa2c11337ee1733789a4f7c455a5093bf
2245UBoatRAT_DropperDetects UBoatRAT Dropperhttps://researchcenter.paloaltonetworks.com/2017/11/unit42-uboatrat-navigates-east-asia/2017-11-29 00:00:0075Florian RothEXE,FILE,MALca9d065de135e2f1fee9f73c713423f0
2246URL_File_Local_EXEDetects an .url file that points to a local executablehttps://twitter.com/malwareforme/status/9153008830128701442017-10-04 00:00:0060Florian Rothcc10db7c91677347a4eb04993e6b33dc
2247UnPack_rar_Folder_InjectTDisclosed hacktool set (old stuff) - file InjectT.exe-2014-11-23 00:00:0060Florian RothHKTL9e1e1c2bb13ec00569071012dd3e3a7b
2248UnPack_rar_Folder_TBackDisclosed hacktool set (old stuff) - file TBack.DLL-2014-11-23 00:00:0060Florian RothHKTLebca59b5c623c397f400e822068ae447
2249Unauthorized_Proxy_Server_RAT-https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity1970-01-01 01:00:0075US-CERT Code Analysis TeamHKTL,MALa6199f843025912efe9434015ce1434a
2250Unidentified_Malware_TwoUnidentified Implant by APT29https://www.us-cert.gov/ncas/current-activity/2017/02/10/Enhanced-Analysis-GRIZZLY-STEPPE2017-02-10 00:00:0085US CERTAPT,MAL,RUSSIAd4f1cb1966f4e9fc388e506c978e2154
2251Unit78020_Malware_1Detects malware by Chinese APT PLA Unit 78020 - Specific Rule - msictl.exehttp://threatconnect.com/camerashy/?utm_campaign=CameraShy2015-09-24 00:00:0075Florian RothAPT,CHINA,EXE,FILE,MAL65d433751af588375650541429136607
2252Unit78020_Malware_Gen1Detects malware by Chinese APT PLA Unit 78020 - Generic Rulehttp://threatconnect.com/camerashy/?utm_campaign=CameraShy2015-09-24 00:00:0075Florian RothAPT,CHINA,EXE,FILE,GEN,MAL83728ac064469e96e2777f4cfec7f8f8
2253Unit78020_Malware_Gen2Detects malware by Chinese APT PLA Unit 78020 - Generic Rulehttp://threatconnect.com/camerashy/?utm_campaign=CameraShy2015-09-24 00:00:0075Florian RothAPT,CHINA,EXE,FILE,GEN,MAL56f9cfa9fcc5650cc824c3cac9d9ee87
2254Unit78020_Malware_Gen3Detects malware by Chinese APT PLA Unit 78020 - Generic Rule - Chonghttp://threatconnect.com/camerashy/?utm_campaign=CameraShy2015-09-24 00:00:0075Florian RothAPT,CHINA,EXE,FILE,GEN,MAL94206241e8087036f47f47591f2d4c67
2255Universal_Exploit_StringsDetects a group of strings often used in exploit codesnot set2017-12-02 00:00:0050Florian RothSCRIPT30d5be6afd352ecd58a10c4d232a55ce
2256Unknown_0f06c5d1b32f4994c3b3abf8bb76d5468f105167Detects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL9786d434fceed0b4472ec44c1bdf3c03
2257Unknown_8af033424f9590a15472a23cc3236e68070b952eDetects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL69303ba6ed5d249b9b6ad47d5eadfe7a
2258Unknown_Malware_Sample_Jul17_2Detects unknown malware sample with pastebin RAW URLhttps://goo.gl/iqH8CK2017-08-01 00:00:0075Florian RothEXE,FILE,MAL6828e5bbbc31415b3953a5d895653ddf
2259Unpack_InjecttWebshells Auto-generated - file Injectt.exe-1970-01-01 01:00:0075Florian RothHKTL,WEBSHELL9e55eca932dfedcf3f76fa20c39dfa54
2260Unpack_TBackWebshells Auto-generated - file TBack.dll-1970-01-01 01:00:0075Florian RothWEBSHELL66c8120ded1dddd71d7079603591c3e2
2261Unspecified_Malware_Jul17_1ADetects samples of an unspecified malware - July 2017Winnti HDRoot VT2017-07-07 00:00:0075Florian RothEXE,FILE,MALfe9788d0c0d535d06769cd625a8a6548
2262Unspecified_Malware_Jul17_2CUnspecified Malware - CN relationhttps://goo.gl/CX3KaY2017-07-18 00:00:0075Florian RothEXE,FILE,MAL3cb5ffb17f3800d93b233d594f536514
2263Unspecified_Malware_Oct16_ADetects an unspecififed malware - October 2016Internal Research2016-10-08 00:00:0080Florian RothEXE,FILE,MALf8e83052a02b677675403c53328332a6
2264Unspecified_Malware_Oct16_CDetects an unspecififed malware - October 2016Internal Research2016-10-08 00:00:0080Florian RothEXE,FILE,MAL2adf625019818624251c6d1dbc8cbe85
2265Unspecified_Malware_Oct16_DDetects unspecified malware - October 2016Internal Research2016-10-08 00:00:0075Florian RothEXE,FILE,MAL087fac9f775e126e18a6c2920657a8e5
2266Unspecified_Malware_Oct16_EDetects unspecified Malware - October 2016Internal Research2016-10-08 00:00:0075Florian RothEXE,FILE,MAL87ad2567a5091dabb40fb1877158b1ae
2267Unspecified_Malware_Sep1_A1Detects malware from DrqgonFly APT reporthttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group2017-09-12 00:00:0075Florian RothAPT,EXE,FILE,MAL810c6910e163417fa85235890dc32b50
2268Upatre_HazgurutDetects Upatre malware - file hazgurut.exehttps://weankor.vxstream-sandbox.com/sample/6b857ef314938d37997c178ea50687a281d8ff9925f0c4e70940754643e2c0e3?environmentId=72015-10-13 00:00:0070Florian RothEXE,FILE11ebae2755c049c35e5a1e491cc6f2bd
2269UploadShell_98038f1efa4203432349badabad76d44337319a6Detects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL36659474d392b6d55f570eec009ecefa
2270User_Function_StringDetects user function string from NCSC reporthttps://www.ncsc.gov.uk/alerts/hostile-state-actors-compromising-uk-organisations-focus-engineering-and-industrial-control2018-04-06 00:00:0075NCSC68e4e5d5ef2d24dcbd0d49a2d180d005
2271Utilman_ANOMALYAbnormal utilman.exe - typical strings not found in file-2014-01-06 00:00:0070Florian RothANOMALY,EXTVAR,REQ_PRIVATE,SUSP4cbe73bb63792729fa42aab6b643bff1
2272VBS_Obfuscated_Mal_Feb18_1Detects malicious obfuscated VBS observed in February 2018https://goo.gl/zPsn832018-02-12 00:00:0075Florian RothOBFUS,SCRIPTfbf6d1d25ee8ee07562fac5e81687dfa
2273VBS_WMIExec_Tool_Apr17_1Tools related to Operation Cloud Hopperhttps://github.com/maaaaz/impacket-examples-windows2017-04-07 00:00:0075Florian RothSCRIPT1f5e0ae048d3984556ffaa80a0e15bbb
2274VBS_dropper_script_Dec17_1Detects a supicious VBS script that drops an executableInternal Research2018-01-01 00:00:0080Florian RothSCRIPT519fa7f7c61808fce2bc2aa4e415023e
2275VBScript_Favicon_FileVBScript cloaked as Favicon file used in Leviathan incidenthttps://goo.gl/MZ7dRg2017-10-18 00:00:0075Florian RothFILE,SCRIPT548165824a2ddeb6c693174bdfc84139
2276VSSown_VBSDetects VSSown.vbs script - used to export shadow copy elements like NTDS to take away and crack elsewhere-2015-10-01 00:00:0075Florian RothHKTL,SCRIPTca9257eef68fa327b3865265928cf463
2277VUBrute_VUBrutePoS Scammer Toolbox - http://goo.gl/xiIphp - file VUBrute.exe-2014-11-22 00:00:0070Florian RothHKTLbbf4a422971cef1da4c996283a8af182
2278VUBrute_configPoS Scammer Toolbox - http://goo.gl/xiIphp - file config.inihttp://goo.gl/xiIphp2014-11-22 00:00:0070Florian RothHKTLd757bd1fda340d339a43ffb8287e6b82
2279VUL_JQuery_FileUpload_CVE_2018_9206Detects JQuery File Upload vulnerability CVE-2018-9206https://www.zdnet.com/article/zero-day-in-popular-jquery-plugin-actively-exploited-for-at-least-three-years/2018-10-19 00:00:0075Florian RothEXPLOIT28925d8af31a8138b76c7c48e4313ef7
2280Venom_RootkitVenom Linux Rootkithttps://security.web.cern.ch/security/venom.shtml2017-01-12 00:00:0075Florian RothLINUX,MALcb0709e616a18f2ab1143873246e5ed4
2281Vermin_Keylogger_Jan18_1Detects Vermin Keyloggerhttps://researchcenter.paloaltonetworks.com/2018/01/unit42-vermin-quasar-rat-custom-malware-used-ukraine/2018-01-29 00:00:0075Florian RothEXE,FILE,HKTL4723c8efae6af8af658fd0fcbc417901
2282VisualDiscovery_Lonovo_Superfish_SSL_HijackLenovo Superfish SSL Interceptor - file VisualDiscovery.exehttps://twitter.com/4nc4p/status/5683254935582720002015-02-19 00:00:0075Florian Roth / improved by kbandlaEXE,FILEf618145eeaaf2afc9d2b36fcfb24f012
2283Volgmer_MalwareDetects Volgmer malware as reported in US CERT TA17-318Bhttps://www.us-cert.gov/ncas/alerts/TA17-318B2017-11-15 00:00:0075Florian RothEXE,FILE,MAL1cf972d589090c8e8f25a6425a7d098b
2284WAF_BypassChinese Hacktool Set - file WAF-Bypass.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLfb69bb3f21d24c1e36273a950466bb73
2285WCE_Modified_1_1014Modified (packed) version of Windows Credential Editor-1970-01-01 01:00:0070Florian RothHKTL8025184cbea2802be6c716f2aa911079
2286WCE_in_memoryDetects Windows Credential Editor (WCE) in memory (and also on disk)Internal Research2016-08-28 00:00:0080Florian RothHKTL634fcb7acfe59de1147b96df09f6cee9
2287WEB_INF_webLaudanum Injector Tools - file web.xmlhttp://laudanum.inguardians.com/2015-06-22 00:00:0075Florian RothHKTL,WEBSHELL7fc1f640aa35aacf5f07e14c341921f1
2288WINNTI_KingSoft_Moz_ConfustionDetects Barium sample with Copyright confusionhttps://www.virustotal.com/en/file/070ee4a40852b26ec0cfd79e32176287a6b9d2b15e377281d8414550a83f6496/analysis/2018-04-13 00:00:0075Markus NeisEXE,FILEd99e3cbd6c04f4c0625308a5e27bf2cd
2289WMI_vbsWMI Tool - APT-2013-11-29 00:00:0070Florian RothAPT,HKTL2d511d99db6bceb2d613a8c0cf008fff
2290WMImplantAuto-generated rule - file WMImplant.ps1https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html2017-03-24 00:00:0075Florian Rothadc75bc617b696d5841da9e5defa27a6
2291WPR_Asterisk_Hook_LibraryWindows Password Recovery - file ast64.dllInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTLbde1934575725ec07bc9c4255e7fab50
2292WPR_Passscape_LoaderWindows Password Recovery - file ast.exeInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTL837c3f402e649d6c5b0f509d796ace7b
2293WPR_WindowsPasswordRecovery_EXEWindows Password Recovery - file wpr.exeInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTL2d158b363dc0e46bbd3759876da9c507
2294WPR_WindowsPasswordRecovery_EXE_64Windows Password Recovery - file ast64.exeInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTLf52f483c554297b636d73fff985e9243
2295WPR_loader_DLLWindows Password Recovery - file loader64.dllInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTL869c6eb3c630c7fe5b50d41af80dfbb2
2296WPR_loader_EXEWindows Password Recovery - file loader.exeInternal Research2017-03-15 00:00:0075Florian RothEXE,FILE,HKTL884f9f84d792713bb0e20f176475a18f
2297WSOShell_0bbebaf46f87718caba581163d4beed56ddf73a7Detects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL8bfc6e21b0cfcec87a84c4cdc543f10f
2298WScriptShell_Case_AnomalyDetects obfuscated wscript.shell commandsInternal Research2017-09-11 00:00:0060Florian RothOBFUS4d85d134f0f8cd2521b5160910a125af
2299WScript_Shell_PowerShell_ComboDetects malware from Middle Eastern campaign reported by Taloshttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html2018-02-07 00:00:0050Florian RothANOMALY,SCRIPTb8cc1daa7a53a303934ab6441df1fae8
2300WSockExpertChinese Hacktool Set - file WSockExpert.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLb06738b43d14a160009c3ebaf8dc1083
2301WannCry_BATDetects WannaCry Ransomware BATCH Filehttps://goo.gl/HG2j5T2017-05-12 00:00:0075Florian RothCRIME,FILE,MAL,RANSOM8c2743895ec9c21d4cb4ddd16be53678
2302WannCry_m_vbsDetects WannaCry Ransomware VBShttps://goo.gl/HG2j5T2017-05-12 00:00:0075Florian RothCRIME,FILE,MAL,RANSOM,SCRIPT7c9f066f546a35bd791670c63fa29f80
2303WannaCry_RansomNoteDetects WannaCry Ransomware Notehttps://goo.gl/HG2j5T2017-05-12 00:00:0075Florian RothCRIME,FILE,MAL,RANSOM533239936565763106cdb41b0df37155
2304WannaCry_RansomwareDetects WannaCry Ransomwarehttps://goo.gl/HG2j5T2017-05-12 00:00:0075Florian Roth (with the help of binar.ly)CRIME,EXE,FILE,MAL,RANSOM813683d3aa5c224ca0cbb83ec856cf77
2305WannaCry_Ransomware_GenDetects WannaCry Ransomwarehttps://www.us-cert.gov/ncas/alerts/TA17-132A2017-05-12 00:00:0075Florian Roth (based on rule by US CERT)CRIME,EXE,FILE,GEN,MAL,RANSOM350882850aa0264087686aafcabc111e
2306WaterBug_fa_malwareSymantec Waterbug Attack - FA malware varianthttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security Response3260ea5197e722bc9e4f08f81821613f
2307WaterBug_savSymantec Waterbug Attack - SAV Malwarehttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security ResponseMALc617aff48fccbe38bbb77ebf59746a9e
2308WaterBug_turla_dropperSymantec Waterbug Attack - Trojan Turla Dropperhttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security ResponseMAL,RUSSIAba0553a40c31e587b684526850f71002
2309WaterBug_wipbot_2013_coreSymantec Waterbug Attack - Trojan.Wipbot core + coregarbage appended data (PDF Exploit leftovers) + wipbot dropperfake AdobeRd32 Errorhttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security ResponseMALc1cad9cb8a92981801401c19699885ff
2310WaterBug_wipbot_2013_core_PDFSymantec Waterbug Attack - Trojan.Wipbot 2014 core PDFhttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security ResponseFILE,MALc68d0a4e4fc8c1cc7f0d6e1cc2a1f368
2311WaterBug_wipbot_2013_dllSymantec Waterbug Attack - Trojan.Wipbot 2014 Down.dll componenthttp://t.co/rF35OaAXrl2015-01-22 00:00:0075Symantec Security ResponseMALa899568a57584979d251dae3309d22c6
2312Waterbear_10_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEf02572c4f1f22fa9d537891c9487ac62
2313Waterbear_11_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEe7f5e5affa5ea61578175717212adca7
2314Waterbear_12_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEece90c9469f607af6ed978fadd8fedc6
2315Waterbear_13_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEa64ad8654c020362cf9b23e6708a2aae
2316Waterbear_14_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILE9d3a60f21dd5273b0f1112e597aa5e5a
2317Waterbear_1_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEda12e8bbdb9bff68563dc29b4f30f379
2318Waterbear_2_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILE39befe16ad2f4728465eccc6f1a2d12b
2319Waterbear_4_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEbb28036a98c272612c684e85668f5bf5
2320Waterbear_5_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothFILE33eeb76f3e9e7258d5dfc9386ad446a9
2321Waterbear_6_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEb00343474b1d8b5aef8ae573c18f0fb1
2322Waterbear_7_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEc7f8a0b016f37ee4d13e643269b7ba0b
2323Waterbear_8_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILEbcb9155330b570c1c0644cd7f6678bb2
2324Waterbear_9_Jun17Detects malware from Operation Waterbearhttps://goo.gl/L9g9eR2017-06-23 00:00:0075Florian RothEXE,FILE3224ffea601940bad27ab05940c6dfa9
2325WebCrack4_RouterPasswordCrackingChinese Hacktool Set - file WebCrack4-RouterPasswordCracking.exehttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTL9b8787adb3ffde114a5b882d54039305
2326WebShell_5786d7d9f4b0df731d79ed927fb5a124195fc901Detects a web shellhttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,WEBSHELL97e21ccd95557e830dcc1bf78395a769
2327WebShell_AK_74_Security_Team_Web_Shell_Beta_VersionPHP Webshells Github Archive - file AK-74 Security Team Web Shell Beta Version.php-1970-01-01 01:00:0075Florian RothWEBSHELL50104da4f2517412997e248744a69114
2328WebShell_Ayyildiz_Tim___AYT__Shell_v_2_1_BizPHP Webshells Github Archive - file Ayyildiz Tim -AYT- Shell v 2.1 Biz.php-1970-01-01 01:00:0075Florian RothWEBSHELL1bbf8cba3b9ff1bbf203b542a83b0c3f
2329WebShell_C99madShell_v__2_0_madnet_editionPHP Webshells Github Archive - file C99madShell v. 2.0 madnet edition.php-1970-01-01 01:00:0075Florian RothWEBSHELL63e2f195c606a27cb31ff1da03050e08
2330WebShell_CasuS_1_5PHP Webshells Github Archive - file CasuS 1.5.php-1970-01-01 01:00:0075Florian RothWEBSHELL017ebbce8936c692b5ec79e9cc007e73
2331WebShell_CmdAsp_asp_phpPHP Webshells Github Archive - file CmdAsp.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELLe362c5ce618b052d9ff426af1568f5de
2332WebShell_DTool_ProPHP Webshells Github Archive - file DTool Pro.php-1970-01-01 01:00:0075Florian RothWEBSHELL87268234792d8462caeed57ff4239ddc
2333WebShell_GFSPHP Webshells Github Archive - from files GFS web-shell ver 3.1.7 - PRiV8.php, Predator.php, GFS_web-shell_ver_3.1.7_-_PRiV8.php-1970-01-01 01:00:0075Florian RothWEBSHELL529049a1df8fd71b1a345d3ebb7ce3a2
2334WebShell_Gamma_Web_ShellPHP Webshells Github Archive - file Gamma Web Shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL3390f06d8f9fef10316ccef5b362ec94
2335WebShell_Generic_1609_AAuto-generated rulehttps://github.com/bartblaze/PHP-backdoors2016-09-10 00:00:0075Florian RothFILE,GEN,WEBSHELLede500790f055d8678cd8250d10387c8
2336WebShell_Generic_PHP_10PHP Webshells Github Archive - from files Cyber Shell.php, cybershell.php, Cyber Shell (v 1.0).php, PHPRemoteView.php-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL159ee05abd9aa04427babc56d8f6be25
2337WebShell_Generic_PHP_11PHP Webshells Github Archive - from files rootshell.php, Rootshell.v.1.0.php, s72 Shell v1.1 Coding.php, s72_Shell_v1.1_Coding.php-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL12919b32631e38b4b45edd8c508d4bb0
2338WebShell_Generic_PHP_1PHP Webshells Github Archive - from files Dive Shell 1.0-1970-01-01 01:00:0075Florian RothGEN,WEBSHELLd6783a15dddd826d3f24246296a98130
2339WebShell_Generic_PHP_2PHP Webshells Github Archive - from files CrystalShell v.1.php, load_shell.php, Loaderz WEB Shell.php, stres.php-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL032f17e52814cd4f0b44274fda1222c2
2340WebShell_Generic_PHP_3PHP Webshells Github Archive-1970-01-01 01:00:0075Florian RothGEN,WEBSHELLb692b63f01266df71db381cf551bf965
2341WebShell_Generic_PHP_4PHP Webshells Github Archive - from files CrystalShell v.1.php, load_shell.php, nshell.php, Loaderz WEB Shell.php, stres.php-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL1af35831edcffcaa60458a6173207e53
2342WebShell_Generic_PHP_6PHP Webshells Github Archive-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL16e768d3f667254bc49c6f1502f73b78
2343WebShell_Generic_PHP_7PHP Webshells Github Archive-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL3a953b96dd0ff9d07129854dc554ffb5
2344WebShell_Generic_PHP_8PHP Webshells Github Archive-1970-01-01 01:00:0075Florian RothGEN,WEBSHELL4c3f918935055c7b05068668dc6b23c2
2345WebShell_Generic_PHP_9PHP Webshells Github Archive - from files KAdot Universal Shell v0.1.6.php, KAdot_Universal_Shell_v0.1.6.php, KA_uShell 0.1.6.php-1970-01-01 01:00:0075Florian RothGEN,WEBSHELLd992f22007d1cda3b4f964bd567b9c90
2346WebShell_JexBoss_JSP_1Detects JexBoss JSPsInternal Research2018-11-08 00:00:0075Florian RothFILE,WEBSHELLbf0dff0ad831c0fe9000e96d9cd3c4e5
2347WebShell_JexBoss_WAR_1Detects JexBoss versions in WAR formInternal Research2018-11-08 00:00:0075Florian RothFILE,WEBSHELL32621519a4c08d5453423bba3e51ca59
2348WebShell_JspWebshell_1_2PHP Webshells Github Archive - file JspWebshell_1.2.php-1970-01-01 01:00:0075Florian RothWEBSHELLce4660802786bb793007dad924ea0d44
2349WebShell_JspWebshell_1_2_2PHP Webshells Github Archive - file JspWebshell 1.2.php-1970-01-01 01:00:0075Florian RothWEBSHELLccd78f40cfeed86744c5e2f821a177d5
2350WebShell_Liz0ziM_Private_Safe_Mode_Command_Execuriton_Bypass_ExploitPHP Webshells Github Archive - file Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit.php-1970-01-01 01:00:0075Florian RothWEBSHELLae0b78e3af538bcbde0b4384ebb55489
2351WebShell_Moroccan_Spamers_Ma_EditioN_By_GhOsTPHP Webshells Github Archive - file Moroccan Spamers Ma-EditioN By GhOsT.php-1970-01-01 01:00:0075Florian RothWEBSHELL6b5a190f4c9d86db1a09559aae57783f
2352WebShell_NCC_ShellPHP Webshells Github Archive - file NCC-Shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL150f197e031fb9726acce43aabce15bf
2353WebShell_NTDaddy_v1_9PHP Webshells Github Archive - file NTDaddy v1.9.php-1970-01-01 01:00:0075Florian RothWEBSHELL3d7a1eefd5b9e6c337939e00346ef134
2354WebShell_PHANTASMAPHP Webshells Github Archive - file PHANTASMA.php-1970-01-01 01:00:0075Florian RothWEBSHELLfc9ffa8f82dfebf7d68cd107f12d61ab
2355WebShell_PHP_Web_Kit_v3Detects PAS Tool PHP Web Kithttps://github.com/wordfence/grizzly2016-01-01 00:00:0075Florian RothFILEcc88ada76efa2268f305a9f588c12a51
2356WebShell_PHP_Web_Kit_v4Detects PAS Tool PHP Web Kithttps://github.com/wordfence/grizzly2016-01-01 00:00:0075Florian RothFILEa86d493242c2dfe7d87fb09bdc9c4ae3
2357WebShell_PhpSpy_Ver_2006PHP Webshells Github Archive - file PhpSpy Ver 2006.php-1970-01-01 01:00:0075Florian RothWEBSHELLdd634e5b2f407e7624642f3e97df675f
2358WebShell_RemExp_asp_phpPHP Webshells Github Archive - file RemExp.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELL9d6280c7c989612d619b1cf88a696b58
2359WebShell_STNC_WebShell_v0_8PHP Webshells Github Archive - file STNC WebShell v0.8.php-1970-01-01 01:00:0075Florian RothWEBSHELLab5472327886e9dd3e280c8e256641bb
2360WebShell_Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2PHP Webshells Github Archive - file Safe_Mode_Bypass_PHP_4.4.2_and_PHP_5.1.2.php-1970-01-01 01:00:0075Florian RothWEBSHELL421dfbf14c6815fff260fd840dc08598
2361WebShell_Safe_Mode_Bypass_PHP_4_4_2_and_PHP_5_1_2_2PHP Webshells Github Archive - file Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2.php-1970-01-01 01:00:0075Florian RothWEBSHELLf27ba76dc9ae6c9d9354f866298565e7
2362WebShell_SimAttacker___Vrsion_1_0_0___priv8_4_My_friendPHP Webshells Github Archive - file SimAttacker - Vrsion 1.0.0 - priv8 4 My friend.php-1970-01-01 01:00:0075Florian RothWEBSHELL33a59325b17453cf25c590b666f43955
2363WebShell_Simple_PHP_backdoor_by_DKPHP Webshells Github Archive - file Simple_PHP_backdoor_by_DK.php-1970-01-01 01:00:0075Florian RothMAL,WEBSHELLc1940c24c3fa0582d22ee590924611ec
2364WebShell_Sincap_1_0PHP Webshells Github Archive - file Sincap 1.0.php-1970-01-01 01:00:0075Florian RothWEBSHELL83c694f5da63c5486c202db37324f3d3
2365WebShell_UploaderPHP Webshells Github Archive - file Uploader.php-1970-01-01 01:00:0075Florian RothWEBSHELLd567d030234c75006a180c809b0e7471
2366WebShell_Web_shell__c_ShAnKaRPHP Webshells Github Archive - file Web-shell (c)ShAnKaR.php-1970-01-01 01:00:0075Florian RothWEBSHELL1be444895c6ed1492cefa380b4135441
2367WebShell_WinX_ShellPHP Webshells Github Archive - file WinX Shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL9464afb4ced119e48a540ca9b0c27d98
2368WebShell_Worse_Linux_ShellPHP Webshells Github Archive - file Worse Linux Shell.php-1970-01-01 01:00:0075Florian RothLINUX,WEBSHELL782fcabcfa49411693c1d4b706685cde
2369WebShell_ZyklonShellPHP Webshells Github Archive - file ZyklonShell.php-1970-01-01 01:00:0075Florian RothWEBSHELL19617f2e9555dc4c63a129d416bb9ee7
2370WebShell__Ajax_PHP_Command_Shell_Ajax_PHP_Command_Shell_soldierofallahPHP Webshells Github Archive - from files Ajax_PHP Command Shell.php, Ajax_PHP_Command_Shell.php, soldierofallah.php-1970-01-01 01:00:0075Florian RothWEBSHELL925a72ea67264772862696155c10be0a
2371WebShell__CrystalShell_v_1_erne_stresPHP Webshells Github Archive - from files CrystalShell v.1.php, erne.php, stres.php-1970-01-01 01:00:0075Florian RothWEBSHELL417a11e60e24a6a5cd62bfedd32d8fad
2372WebShell__CrystalShell_v_1_sosyete_stresPHP Webshells Github Archive - from files CrystalShell v.1.php, sosyete.php, stres.php-1970-01-01 01:00:0075Florian RothWEBSHELLca2c1e7d527bbc4e646c87facc46e087
2373WebShell__Cyber_Shell_cybershell_Cyber_Shell__v_1_0_PHP Webshells Github Archive - from files Cyber Shell.php, cybershell.php, Cyber Shell (v 1.0).php-1970-01-01 01:00:0075Florian RothWEBSHELL0a46120152c6af42c60ccde83aa09771
2374WebShell__PH_Vayv_PHVayv_PH_VayvPHP Webshells Github Archive - from files PH Vayv.php, PHVayv.php, PH_Vayv.php-1970-01-01 01:00:0075Florian RothWEBSHELL27a49d20dddd3c73d7769a9ad4338e0d
2375WebShell__PH_Vayv_PHVayv_PH_Vayv_klasvayv_asp_phpPHP Webshells Github Archive - from files PH Vayv.php, PHVayv.php, PH_Vayv.php, klasvayv.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELLa4be5f22d27b5d846a7f66f93d39a3f4
2376WebShell__Small_Web_Shell_by_ZaCo_small_zaco_zacosmallPHP Webshells Github Archive - from files Small Web Shell by ZaCo.php, small.php, zaco.php, zacosmall.php-1970-01-01 01:00:0075Florian RothWEBSHELL83db1a6fff21310afa749d817523db08
2377WebShell__findsock_php_findsock_shell_php_reverse_shellPHP Webshells Github Archive - from files findsock.c, php-findsock-shell.php, php-reverse-shell.php-1970-01-01 01:00:0075Florian RothWEBSHELLb5c5705c3dc1e33c9f8a12f6dcde3c14
2378WebShell_aZRaiLPhp_v1_0PHP Webshells Github Archive - file aZRaiLPhp v1.0.php-1970-01-01 01:00:0075Florian RothWEBSHELL50fe95b80de17f2fb09385ee3f090c53
2379WebShell_accept_languagePHP Webshells Github Archive - file accept_language.php-1970-01-01 01:00:0075Florian RothWEBSHELL809e525f0e08cbfd15afdf79079c6300
2380WebShell_b374k_mini_shell_php_phpPHP Webshells Github Archive - file b374k-mini-shell-php.php.php-1970-01-01 01:00:0075Florian RothWEBSHELLa2cdb2889f1ba26d1f46531ee38cd61e
2381WebShell_b374k_phpPHP Webshells Github Archive - file b374k.php.php-1970-01-01 01:00:0075Florian RothWEBSHELL38ace66cba2c59b06706f34d57ea8b62
2382WebShell_backupsqlPHP Webshells Github Archive - file backupsql.php-1970-01-01 01:00:0075Florian RothWEBSHELLb689e449e2d31a2d4aea847d5253e1d5
2383WebShell_c99_locus7sPHP Webshells Github Archive - file c99_locus7s.php-1970-01-01 01:00:0075Florian RothWEBSHELL2fb4ad77e1be74a0738112ce661bbac4
2384WebShell_c99_madnetPHP Webshells Github Archive - file c99_madnet.php-1970-01-01 01:00:0075Florian RothWEBSHELL86be7d02c6b35187fd7167d9d84f0f10
2385WebShell_cgiSemi-Auto-generated - file WebShell.cgi.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL317b67e7d08dfaee7374e6afa2a38c54
2386WebShell_cgitelnetPHP Webshells Github Archive - file cgitelnet.php-1970-01-01 01:00:0075Florian RothWEBSHELLbdbbd0abf9d6bcac2fe1c7194e1f7c1c
2387WebShell_dC3_Security_Crew_Shell_PRiVPHP Webshells Github Archive - file dC3_Security_Crew_Shell_PRiV.php-1970-01-01 01:00:0075Florian RothWEBSHELLee2b2a2e4b18f7fe5b1d1d479fa9f5b1
2388WebShell_dC3_Security_Crew_Shell_PRiV_2PHP Webshells Github Archive - file dC3 Security Crew Shell PRiV.php-1970-01-01 01:00:0075Florian RothWEBSHELLb7ef4c57f22c320da3c14bc1e74d9125
2389WebShell_ftpsearchPHP Webshells Github Archive - file ftpsearch.php-1970-01-01 01:00:0075Florian RothWEBSHELL57e0c47e9d44d6725d36f22e49eae6a0
2390WebShell_g00nshell_v1_3PHP Webshells Github Archive - file g00nshell-v1.3.php-1970-01-01 01:00:0075Florian RothWEBSHELLf66a86c6e276f855b810f867af02d514
2391WebShell_go_shellPHP Webshells Github Archive - file go-shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL25f866e6559b10c335573ea9826deaf4
2392WebShell_h4ntu_shell__powered_by_tsoi_PHP Webshells Github Archive - file h4ntu shell [powered by tsoi].php-1970-01-01 01:00:0075Florian RothWEBSHELLeb36987be4d8b57d33f1f07272c56563
2393WebShell_hiddens_shell_v1PHP Webshells Github Archive - file hiddens shell v1.php-1970-01-01 01:00:0075Florian RothWEBSHELL904ca614620ebfae9c69cf603a7315c3
2394WebShell_indexer_asp_phpPHP Webshells Github Archive - file indexer.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELL8b14c23369beb2f868ba959016dc4c01
2395WebShell_ironshellPHP Webshells Github Archive - file ironshell.php-1970-01-01 01:00:0075Florian RothWEBSHELLebcfb75330c3136c9c1121e514508a4f
2396WebShell_lamashellPHP Webshells Github Archive - file lamashell.php-1970-01-01 01:00:0075Florian RothWEBSHELLfc5b92ea89fd906ecb012e342bb0f104
2397WebShell_mysql_toolPHP Webshells Github Archive - file mysql_tool.php-1970-01-01 01:00:0075Florian RothWEBSHELL8778953a48f28f952d7cb94dcc007683
2398WebShell_php_backdoorPHP Webshells Github Archive - file php-backdoor.php-1970-01-01 01:00:0075Florian RothMAL,WEBSHELL2cf396e696ce70775f00492414263243
2399WebShell_php_include_w_shellPHP Webshells Github Archive - file php-include-w-shell.php-1970-01-01 01:00:0075Florian RothWEBSHELL6a3fc7dd69e02b6bcb18546557ba34f9
2400WebShell_php_webshells_529PHP Webshells Github Archive - file 529.php-1970-01-01 01:00:0075Florian RothWEBSHELLb0982567c9960f81c146b94db40a71ac
2401WebShell_php_webshells_MyShellPHP Webshells Github Archive - file MyShell.php-1970-01-01 01:00:0075Florian RothWEBSHELL8f3efa58eb587d80a878fff506c3c5f5
2402WebShell_php_webshells_NGHPHP Webshells Github Archive - file NGH.php-1970-01-01 01:00:0075Florian RothWEBSHELL9410d51c2483a182c062449699c06941
2403WebShell_php_webshells_READMEPHP Webshells Github Archive - file README.md-1970-01-01 01:00:0075Florian RothWEBSHELL2b3d89c532ee7cdd3c52d24c76307479
2404WebShell_php_webshells_aspydrvPHP Webshells Github Archive - file aspydrv.php-1970-01-01 01:00:0075Florian RothWEBSHELL1de71ea788ef65c400eb65f56095f019
2405WebShell_php_webshells_cpanelPHP Webshells Github Archive - file cpanel.php-1970-01-01 01:00:0075Florian RothWEBSHELL234d11715d2244da484f88ecd78fa627
2406WebShell_php_webshells_cwPHP Webshells Github Archive - file cw.php-1970-01-01 01:00:0075Florian RothWEBSHELL9891877cd463756cfd76ce0b73a857e2
2407WebShell_php_webshells_kralPHP Webshells Github Archive - file kral.php-1970-01-01 01:00:0075Florian RothWEBSHELLabeb315a64b2b589e4cac2b8f6e29e1e
2408WebShell_php_webshells_lolipopPHP Webshells Github Archive - file lolipop.php-1970-01-01 01:00:0075Florian RothWEBSHELL6cd0d1d725030ab165708b6a7b75ee02
2409WebShell_php_webshells_lostDCPHP Webshells Github Archive - file lostDC.php-1970-01-01 01:00:0075Florian RothWEBSHELLf0f35c1b6082b370b58ba9ceb1180752
2410WebShell_php_webshells_matamuPHP Webshells Github Archive - file matamu.php-1970-01-01 01:00:0075Florian RothWEBSHELLd1be64679f57d6a902b9e5c988e39cc8
2411WebShell_php_webshells_myshellPHP Webshells Github Archive - file myshell.php-1970-01-01 01:00:0075Florian RothWEBSHELL75e0996064865a8ec052a2b05bff3e11
2412WebShell_php_webshells_pHpINJPHP Webshells Github Archive - file pHpINJ.php-1970-01-01 01:00:0075Florian RothWEBSHELLb323af8124302e78b974dc47649f3c7f
2413WebShell_php_webshells_pwsPHP Webshells Github Archive - file pws.php-1970-01-01 01:00:0075Florian RothWEBSHELL7c563b9a8e521908dc06378d00913b3b
2414WebShell_php_webshells_spygrupPHP Webshells Github Archive - file spygrup.php-1970-01-01 01:00:0075Florian RothWEBSHELLea7cb42edba8bd3ca9f14307300e427b
2415WebShell_php_webshells_tryagPHP Webshells Github Archive - file tryag.php-1970-01-01 01:00:0075Florian RothWEBSHELLc9432ea060a98459c3a6fa0b024c213c
2416WebShell_qsd_php_backdoorPHP Webshells Github Archive - file qsd-php-backdoor.php-1970-01-01 01:00:0075Florian RothMAL,WEBSHELLfcfbb44a6978c6ad949e12902fb8ce3e
2417WebShell_reader_asp_phpPHP Webshells Github Archive - file reader.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELL11ef4d90b0af00029138274e54bcb0f7
2418WebShell_ru24_post_shPHP Webshells Github Archive - file ru24_post_sh.php-1970-01-01 01:00:0075Florian RothWEBSHELL1c83448f7ceb20eb5ceb4380c97899d6
2419WebShell_safe0verPHP Webshells Github Archive - file safe0ver.php-1970-01-01 01:00:0075Florian RothWEBSHELL4b2bb8798085f20c6d64cd02e70e297b
2420WebShell_simattackerPHP Webshells Github Archive - file simattacker.php-1970-01-01 01:00:0075Florian RothWEBSHELL0ad0556e77845535abe82a9e5bddcdd7
2421WebShell_simple_backdoorPHP Webshells Github Archive - file simple-backdoor.php-1970-01-01 01:00:0075Florian RothMAL,WEBSHELLe7bb8d19a080cf9bdeb599f907c5e83a
2422WebShell_simple_cmdPHP Webshells Github Archive - file simple_cmd.php-1970-01-01 01:00:0075Florian RothWEBSHELL6a1955be5f07a7f80089c9f743c2b97d
2423WebShell_toolaspshellPHP Webshells Github Archive - file toolaspshell.php-1970-01-01 01:00:0075Florian RothWEBSHELL1d0385ed447cab331a35f487514b869d
2424WebShell_webshells_zehir4Webshells Github Archive - file zehir4-1970-01-01 01:00:0055Florian RothWEBSHELL5bb1822ce4aa7123fa9578ff8dff4dd2
2425WebShell_zehir4_asp_phpPHP Webshells Github Archive - file zehir4.asp.php.txt-1970-01-01 01:00:0075Florian RothWEBSHELL1e2c75e3c69355ab6badbe3a83f551b4
2426Webshell_27_9_acid_c99_locus7sDetects Webshell - rule generated from from files 27.9.txt, acid.php, c99_locus7s.txthttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELL83ff295cb22da8538bbcde7d14ae1d95
2427Webshell_27_9_c66_c99Detects Webshell - rule generated from from files 27.9.txt, c66.php, c99-shadows-mod.php, c99.php ...https://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELL0c3be143afdee2b992461429e58f6820
2428Webshell_AcidPoisonDetects Poison Sh3ll - Webshellhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELL4c95cf63e249a0be0f90bbe2cac45e98
2429Webshell_AyyildizDetects Webshellhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELLa9368b48de4848ebf5c512cc51a7e3b2
2430Webshell_Backdoor_PHP_Agent_r57_mod_bizzz_shell_r57Detects Webshell - rule generated from from files Backdoor.PHP.Agent.php, r57.mod-bizzz.shell.txt ...https://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothMAL,WEBSHELLf23916ba63c407a61abd55a4ef5aacec
2431Webshell_Caterpillar_ASPXVolatile Cedar Webshell - from file caterpillar.aspxhttp://goo.gl/emons52015-04-03 00:00:0075Florian RothMIDDLE_EAST,WEBSHELL63bfca160217bbd4794c9d52d24f19a7
2432Webshell_FOPO_Obfuscation_APT_ON_Nov17_1Detects malware from NK APT incident DEInternal Research - ON2017-11-17 00:00:0075Florian RothAPT,FILE,OBFUS,WEBSHELLf362727b1b624a24491ed5832467914e
2433Webshell_InsomniaInsomnia Webshell - file InsomniaShell.aspxhttp://www.darknet.org.uk/2014/12/insomniashell-asp-net-reverse-shell-bind-shell/2014-12-09 00:00:0080Florian RothWEBSHELLcbace10396a58a0b2a7cc226dfbadc96
2434Webshell_Tiny_JSP_2Detects a tiny webshell - chine chopper-2015-12-05 00:00:00100Florian RothFILE,WEBSHELL0dd195a4b546fca4aa502660c4bcc4da
2435Webshell_acid_AntiSecShell_3Detects Webshell Acidhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELLcd5447c88da4b263e1db8d155496e652
2436Webshell_acid_FaTaLisTiCz_Fx_fx_p0isoN_sh3ll_x0rg_byp4ss_256Detects Webshellhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELLb8e9068c00ffac2c32bd171a1c7ecd94
2437Webshell_and_Exploit_CN_APT_HKWebshell and Exploit Code in relation with APT against Honk Kong protesters-2014-10-10 00:00:0050Florian RothAPT,WEBSHELLaa24085f67cb0949939760ef0cc2a3d0
2438Webshell_c100Detects Webshell - rule generated from from files c100 v. 777shellhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELL1b68f3d546cb543d8bd0cec31ddd5343
2439Webshell_c99_4Detects C99 Webshellhttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELL0c5e4c8fdd2b7d0feb92a9d49d34b479
2440Webshell_r57shell_2Detects Webshell R57https://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELLac3ceefafcb233a1ab99ba90867ac7c0
2441Webshell_zehirDetects Webshell - rule generated from from files elmaliseker.asp, zehir.asp, zehir.txt, zehir4.asp, zehir4.txthttps://github.com/nikicat/web-malware-collection2016-01-11 00:00:0070Florian RothWEBSHELLe5852688ee73f2d29ad5af86b3bca3f2
2442Weevely_WebshellWeevely Webshell - Generic Rule - heavily scrambled tiny web shellhttp://www.ehacking.net/2014/12/weevely-php-stealth-web-backdoor-kali.html2014-12-14 00:00:0060Florian RothFILE,GEN,WEBSHELL8990f2659ca78fa1d77339c65ded1593
2443WildNeutron_Sample_10Wild Neutron APT Sample Rule - file 1d3bdabb350ba5a821849893dabe5d6056bf7ba1ed6042d93174ceeaa5d6dad7https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE837a18a90cf3a6e82c0febaab7f136bf
2444WildNeutron_Sample_1Wild Neutron APT Sample Rule - file 2b5065a3d0e0b8252a987ef5f29d9e1935c5863f5718b83440e68dc53c21fa94https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE152c96b723a1d3025e369fb52063ce6f
2445WildNeutron_Sample_2Wild Neutron APT Sample Rule - file 8d80f9ef55324212759f4b6070cb8fce18a008ae9dd8b9598553206654d13a6fhttps://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE50b5f9f5ea47c1263db73377013de8ef
2446WildNeutron_Sample_3Wild Neutron APT Sample Rule - file c2c761cde3175f6e40ed934f2e82c76602c81e2128187bab61793ddb3bc686d0https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE008cc716c4f7504790d338c1254d6b1e
2447WildNeutron_Sample_4Wild Neutron APT Sample Rule - file b4005530193bc523d3e0193c3c53e2737ae3bf9f76d12c827c0b5cd0dcbaae45https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILEee94174890bee2674650b207cd689a80
2448WildNeutron_Sample_5Wild Neutron APT Sample Rule - file 1604e36ccef5fa221b101d7f043ad7f856b84bf1a80774aa33d91c2a9a226206https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE1251806a41c60057fc34d2da10b9d63d
2449WildNeutron_Sample_6Wild Neutron APT Sample Rule - file 4bd548fe07b19178281edb1ee81c9711525dab03dc0b6676963019c44cc75865https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE5f2f17e3406a71e8486b3cd845666ff3
2450WildNeutron_Sample_7Wild Neutron APT Sample Rule - file a14d31eb965ea8a37ebcc3b5635099f2ca08365646437c770212d534d504ff3chttps://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE7e8a9b9408ca77637aacdd8083adb770
2451WildNeutron_Sample_9Wild Neutron APT Sample Rule - file 781eb1e17349009fbae46aea5c59d8e5b68ae0b42335cb035742f6b0f4e4087ehttps://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE5f502b3bafe069724953dccaa5f3732b
2452WildNeutron_javacplWild Neutron APT Sample Rulehttps://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/2015-07-10 00:00:0060Florian RothAPT,EXE,FILE52d4d7e377e37d0716fb729b0e6322a4
2453WiltedTulip_Matryoshka_RATDetects Matryoshka RAT used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILE,MAL8d4d22d2f1bed7e55d1a8321f7f5605c
2454WiltedTulip_Netsrv_netsrvsDetects sample from Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILEf14e23cde811af2b1894fece8fb82141
2455WiltedTulip_ReflectiveLoaderDetects reflective loader (Cobalt Strike) used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILE903b49f48f3839e7e4f4160ec7f6b372
2456WiltedTulip_SilverlightMSIDetects powershell tool call Get_AD_Users_Logon_History used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian Roth5727badf7477a3e4ca17756f51890b65
2457WiltedTulip_Tools_backDetects Chrome password dumper used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILE88a6cf8324f1203b86aeb85a874056fc
2458WiltedTulip_Tools_clrlgDetects Windows eventlog cleaner used in Operation Wilted Tulip - file clrlg.bathttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian Roth299110a0dfc05c80ac9cb50a36ef7e4c
2459WiltedTulip_WindowsTaskDetects hack tool used in Operation Wilted Tulip - Windows Taskshttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian Rothe72bad7c35f15d04e31f120ff89b61ea
2460WiltedTulip_Windows_UM_TaskDetects a Windows scheduled task as used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian Roth8733677d146ca5e1bf6852bbb0d96155
2461WiltedTulip_ZppDetects hack tool used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILEb33682b2cd91fee91ea3f27b4181e9bb
2462WiltedTulip_matryoshka_InjectorDetects hack tool used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILE506d959ff30835da357a46dc423f5a0b
2463WiltedTulip_powershellDetects powershell script used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian Rothb8d51b15ffe31dff178aa64b92012424
2464WiltedTulip_tdtessDetects malicious service used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILEc27755eaf3e81b3935cd2b7cb6eefacc
2465WiltedTulip_vminstDetects malware used in Operation Wilted Tuliphttp://www.clearskysec.com/tulip2017-07-23 00:00:0075Florian RothEXE,FILE244de6fd531745d524839ae9f1ee0f96
2466Win32_Buzus_SoftpulseTrojan Buzus / Softpulse-2015-05-13 00:00:0075Florian RothEXE,FILE,MAL0a10ae34405275d82d305e6193a1e997
2467Win32_klockChinese Hacktool Set - file klock.dllhttp://tools.zjqhr.com/2015-06-13 00:00:0075Florian RothCHINA,EXE,FILE,HKTLbb5e68a60442c5facb11fa53cd6e1b9f
2468Win7Elevatev2Detects Win7Elevate - Windows UAC bypass utilityhttp://www.pretentiousname.com/misc/W7E_Source/Win7Elevate_Inject.cpp.html2015-05-14 00:00:0060Florian RothEXE,FILEe9c2b16ba4bdc3d54ccff320b20d71c5
2469WinAgent_BadPatch_1Detects samples mentioned in BadPatch reporthttps://goo.gl/RvDwwA2017-10-20 00:00:0075Florian RothEXE,FILEb3cbff0ebcf22563407abd2e2ebe69f8
2470WinAgent_BadPatch_2Detects samples mentioned in BadPatch reporthttps://goo.gl/RvDwwA2017-10-20 00:00:0075Florian RothEXE,FILEc559f8ce3011b8844b13655544dcc14f
2471WinDivert_DriverDetects WinDivert User-Mode packet capturing driverhttps://www.reqrypt.org/windivert.html2017-10-02 00:00:0040Florian RothEXE,FILE0f5a674281b5e8763ead6328591d209d
2472WinEggDropShellFinal_zip_Folder_InjectTDisclosed hacktool set (old stuff) - file InjectT.exe-2014-11-23 00:00:0060Florian RothHKTLbeb86006716b4a2811117bcc77bb5094
2473WinPayloads_PayloadDetects WinPayloads Payloadhttps://github.com/nccgroup/Winpayloads2017-07-11 00:00:0075Florian RothEXE,FILEe8b4e9185dec26768880712bf7656203
2474WinPayloads_PowerShellDetects WinPayloads PowerShell Payloadhttps://github.com/nccgroup/Winpayloads2017-07-11 00:00:0075Florian RothSCRIPT5a94c96abf12debc7daef552562f9186
2475WinRAR_SFX_AnomalyDetects WinRAR SFX content with the product name of major vendor's tools (sus)-2016-03-24 00:00:0030Florian RothEXE,FILE434b885d8d8650738ac064d4b106a33e
2476WinX_Shell_htmlSemi-Auto-generated - file WinX Shell.html.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsWEBSHELL4024a3fad1e084d6cb207be55a4b8278
2477Win_PrivEsc_ADACLScan4_3Detects a tool that can be used for privilege escalation - file ADACLScan4.3.ps1https://adaclscan.codeplex.com/2016-06-02 00:00:0060Florian Rothfb157df74f83433b8799c576fb9b93d4
2478Win_PrivEsc_folderpermDetects a tool that can be used for privilege escalation - file folderperm.ps1http://www.greyhathacker.net/?p=7382016-06-02 00:00:0080Florian Rothc6d020fdb2c341ca2319e1e610c6203e
2479Win_PrivEsc_gp3finder_v4_0Detects a tool that can be used for privilege escalation - file gp3finder_v4.0.exehttp://grimhacker.com/2015/04/10/gp3finder-group-policy-preference-password-finder/2016-06-02 00:00:0080Florian RothEXE,FILE63f3b51f6b461d3a91d62f5ada2f4fd0
2480WindosShell_s1Detects simple Windows shell - file s1.exehttps://github.com/odzhan/shells/2016-03-26 00:00:0075Florian RothEXE,FILE696bd9788bb5d9549ea26861ec08b1f8
2481WindowsCredentialEditorWindows Credential Editor-1970-01-01 01:00:0090Florian Roth (auto-filled)HKTLf56b3ce4a69a80f06dc07523a7f13ecc
2482WindowsShell_Gen2Detects simple Windows shell - from files s3.exe, s4.exehttps://github.com/odzhan/shells/2016-03-26 00:00:0075Florian RothEXE,FILE7e8ce55a412666c827f553ea51794f9a
2483WindowsShell_GenDetects simple Windows shell - from files keygen.exe, s1.exe, s2.exe, s3.exe, s4.exehttps://github.com/odzhan/shells/2016-03-26 00:00:0075Florian RothEXE,FILE,GEN016cbe8ed8958d9102f43e491a317323
2484WindowsShell_s3Detects simple Windows shell - file s3.exehttps://github.com/odzhan/shells/2016-03-26 00:00:0075Florian RothEXE,FILEcb59debe3b7fc26213e26e0e2a53322d
2485WindowsShell_s4Detects simple Windows shell - file s4.exehttps://github.com/odzhan/shells/2016-03-26 00:00:0075Florian RothEXE,FILE9fe2d575007cc0bf1cb9e157b7a03280
2486Winexe_RemoteExecutionWinexe tool used by Sofacy group several APT caseshttp://dokumente.linksfraktion.de/inhalt/report-orig.pdf2015-06-19 00:00:0070Florian RothAPT,EXE,FILE,RUSSIA27644d19608d8f49660c3ffa4ed05120
2487Winnti_NlaifSvcWinnti sample - file NlaifSvc.dllhttps://goo.gl/VbvJtL2017-01-25 00:00:0075Florian RothCHINA,EXE,FILEd907f81c64da800aa980444b8f2e2e33
2488Winnti_fonfigWinnti sample - file fonfig.exehttps://goo.gl/VbvJtL2017-01-25 00:00:0075Florian RothCHINA,EXE,FILE3e8af97d002ec3396b31754762bc508d
2489Winnti_malware_FWPKDetects a Winnti malware - FWPKCLNT.SYSVTI research2015-10-10 00:00:0075Florian RothCHINA,EXE,FILEcfb4375bfea67ded293f982e694a68d8
2490Winnti_malware_NsiproxyDetects a Winnti rootkit-2015-10-10 00:00:0075Florian RothCHINA,EXE,FILEdd12b43a7020dac3b83fb691a60510b9
2491Winnti_malware_StreamPortal_GenDetects a Winnti malware - StreamportalVTI research2015-10-10 00:00:0075Florian RothCHINA,EXE,FILE,GEN1babba12643d522ec9869c192e786a26
2492Winnti_malware_UpdateDLLDetects a Winnti malware - Update.dllVTI research2015-10-10 00:00:0075Florian RothCHINA,EXE,FILEd394a36c721f84e9049a0a401faf7a14
2493Winnti_signing_certDetects a signing certificate used by the Winnti APT grouphttps://securelist.com/analysis/publications/72275/i-am-hdroot-part-1/2015-10-10 00:00:0075Florian RothAPT,CHINA,EXE,FILE7f516b615d90fb27c00bd394bf85389d
2494WoolenGoldfish_Generic_1Detects a operation Woolen-Goldfish sample - http://goo.gl/NpJpVZhttp://goo.gl/NpJpVZ2015-03-25 00:00:0090Florian RothGEN74d1b02f71a242892c438474ca9b1889
2495WoolenGoldfish_Generic_2Detects a operation Woolen-Goldfish sample - http://goo.gl/NpJpVZhttp://goo.gl/NpJpVZ2015-03-25 00:00:0090Florian RothGENca2f74641174924e9780e0a9dbb9e472
2496WoolenGoldfish_Generic_3Detects a operation Woolen-Goldfish sample - http://goo.gl/NpJpVZhttp://goo.gl/NpJpVZ2015-03-25 00:00:0090Florian RothGEN69ddee0248af0613c2cad86c4ee57d4f
2497WoolenGoldfish_Sample_1Detects a operation Woolen-Goldfish sample - http://goo.gl/NpJpVZhttp://goo.gl/NpJpVZ2015-03-25 00:00:0060Florian Roth2e2435291d817a44efd22e532d202b8c
2498WordDoc_PowerShell_URLDownloadToFileDetects Word Document with PowerShell URLDownloadToFilehttps://www.arbornetworks.com/blog/asert/additional-insights-shamoon2/2017-02-23 00:00:0075Florian RothFILE,OFFICE,SCRIPT87d9fd8b804fb0024aa59fd9841fdfcb
2499Wordpress_Config_Webshell_PreprendWebshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of itInternal Research2017-06-25 00:00:0065Florian RothFILE,OFFICE,WEBSHELL497072fdd28e57d7884131d3bf1e52f9
2500Worse_Linux_Shell_phpSemi-Auto-generated - file Worse Linux Shell.php.txt-1970-01-01 01:00:0075Neo23x0 Yara BRG + customization by Stefan -dfate- MollsLINUX,WEBSHELL0c45de75272c42db9e783d417cace562
The file is too large to be shown. View Raw