SHA256 Hash File type Added Source Yara Hits
ASCII 2022-02-04 03:13:49http://13.236.74.237:8000/PowerSploit/Privesc... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2022-02-04 02:58:12http://13.236.74.237:8000/PowerSploit/CodeExe... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
C 2022-02-04 02:57:05http://13.236.74.237:8000/PowerSploit/CodeExe... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2022-02-04 02:56:58http://13.236.74.237:8000/PowerSploit/CodeExe... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
UTF-8 2022-02-04 00:16:33http://23.95.137.162:80/amsi-bypass CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2022-01-05 15:00:12User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-12-23 17:41:23User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-11-16 16:00:44User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-10-22 03:31:43http://92.222.158.49/powersploit-payload CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2021-07-24 10:00:55User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-07-13 22:00:24User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-06-29 12:00:53User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2021-06-10 14:32:32User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2020-04-08 14:57:41User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
ASCII 2019-07-17 12:11:31User Submission CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2019-05-05 01:36:27http://45.76.216.23/PowerShell/Invoke-TokenMa... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
C 2019-05-05 01:36:22http://45.76.216.23/PowerShell/Invoke-Reflect... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2019-05-04 23:51:42http://196.52.9.47/Invoke--Shellcode.ps1 CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]
ASCII 2018-11-14 17:43:51User Submission CuckooSandbox/embedded_win_api YRP/domain YRP/contentis_base64 YRP/Empire_PowerShell_Framework_Gen4 [+]
C 2018-03-07 03:53:30http://207.148.71.41/CodeExecution-dll.jpg CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:12:47http://172.104.107.30/PowerSploit/Privesc/Get... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:12:27http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:09:45http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:09:43http://172.104.107.30/PowerSploit/Exfiltratio... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:08:02http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/contentis_base64 [+]
ASCII 2018-03-07 03:07:59http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/IP [+]
C 2018-03-07 03:07:57http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]
ASCII 2018-03-07 03:07:54http://172.104.107.30/PowerSploit/CodeExecuti... CuckooSandbox/embedded_win_api YRP/powershell YRP/domain YRP/url [+]